Repository navigation
fix: bump rustls and move the example image to Debian 13 - #27
Merged
Merged
Conversation
rustls 0.23.13 through 0.23.44 accepts TLS 1.3 handshake messages sent at the wrong encryption level when they follow a key change in the same record (RUSTSEC-2026-0285, GHSA-2mjx-qc3c-rqvc). rustls reaches the SDK through tonic and tokio-rustls, so only the lockfile changes. Signed-off-by: Jonasz Małecki <jonasz@upbound.io>
The newest gcr.io/distroless/cc-debian12 digest, the one already pinned, ships libssl3 3.0.20 (critical CVE-2026-75803 plus four highs) and libc6 with critical CVE-2026-5450. cc-debian13 scans at 0 critical and 11 high against 2 and 15. The build stage moves to rust:1.99-trixie so the binary links against the runtime image's glibc. Signed-off-by: Jonasz Małecki <jonasz@upbound.io>
Renovate opened separate PRs for the rust build image and the distroless runtime image. Group both so the two stages move together. Renovate keeps the -trixie tag suffix and the cc-debian13 image name, so moving to the next Debian release stays a manual edit of both lines. Signed-off-by: Jonasz Małecki <jonasz@upbound.io>
jonasz-lasut
marked this pull request as ready for review
October 8, 2026 06:18
jonasz-lasut
added a commit
that referenced
this pull request
Oct 8, 2026
The rustls fix from #27 only changed this repo's Cargo.lock, which projects depending on the SDK ignore. Declare rustls directly with a 0.23.45 floor so they cannot resolve a version affected by RUSTSEC-2026-0285. default-features = false keeps the feature set that tonic's tls-aws-lc already enables. Signed-off-by: Jonasz Małecki <jonasz@upbound.io>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the one advisory
cargo auditreports againstCargo.lockand moves the example image off a Debian 12 base that carries two critical CVEs.tonic→tokio-rustls, so onlyCargo.lockchanges.gcr.io/distroless/cc-debian12is already pinned to its newest digest, which still shipslibssl33.0.20 (critical CVE-2026-75803) andlibc6with critical CVE-2026-5450. The function uses aws-lc-rs for TLS, so the OpenSSL CVEs don't reach the binary, but image scanners still flag them.cc-debian13scans at 0 critical / 11 high against 2 / 15 (grype, linux/amd64). The remaining highs are in the gcc runtime libraries,libc6andzlib1g, with no fixed package yet. The build stage moves torust:1.99-trixieso the binary links against the runtime image's glibc.example/Dockerfileimages into onerenovate/example-function-imagesbranch. Renovate keeps the-trixietag suffix and thecc-debian13image name, so moving to the next Debian release stays a manual edit of both lines.Checked locally:
cargo auditreports no vulnerabilities; fmt, clippy-D warningsand tests pass.--insecure, and serves/metrics.renovate-config-validator --strictpasses. A--platform=localdry run against an outdated copy of the Dockerfile put the rust tag, rust digest and distroless digest updates on a single branch.