Skip to content

chore(deps): update bytes to v1.11.1 - #276

Merged
adleong merged 1 commit into
mainfrom
alex/bytes
Feb 13, 2026
Merged

adleong merged 1 commit into
mainfrom
alex/bytes

Conversation

@adleong

@adleong adleong commented Feb 12, 2026

Copy link
Copy Markdown
Contributor

To address GHSA-434x-w66g-qw3r

Signed-off-by: Alex Leong <alex@buoyant.io>

@cratelyn cratelyn left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thank you for opening this @adleong! i really appreciate all the work you've been doing.

error[unmaintained]: rustls-pemfile is unmaintained
   ┌─ /github/workspace/Cargo.lock:90:1
   │
90 │ rustls-pemfile 2.2.0 registry+https://github.com/rust-lang/crates.io-index
   │ ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ unmaintained advisory detected
   │
   ├ ID: RUSTSEC-2025-0134
   ├ Advisory: https://rustsec.org/advisories/RUSTSEC-2025-0134
   ├ The rustls-pemfile crate is no longer maintained. The repository has been archived since August
     2025, and users are encouraged to depend directly on the underlying PEM parsing code included
     in rustls-pki-types since 1.9.0. The latest version of rustls-pemfile is in fact a thin wrapper
     around the same code used in rustls-pki-types, so migrating should be straightforward.
     
     The new API is represented by the [`PemObject`][PemObject] trait, which provides methods for
     reading a single or multiple PEM objects from a file or byte slice.
     
     [PemObject]: https://docs.rs/rustls-pki-types/latest/rustls_pki_types/pem/trait.PemObject.html
   ├ Announcement: https://github.com/rustls/pemfile/issues/61
   ├ Solution: No safe upgrade is available!
   ├ rustls-pemfile v2.2.0
     └── kubert v0.25.0
         └── linkerd-extension-init v0.1.0

it looks like there is a failure in the dependency audit, unrelated to this upgrade.

we will need to solicit a new kubert release, including this pull request: olix0r/kubert#432 we could, alternatively, add an allowance for that dependency to our deny.toml. i would really prefer not to do this though.

@adleong
adleong merged commit dac98e3 into main Feb 13, 2026
7 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants