Skip to content

fix: bump rustls and move the example image to Debian 13 - #27

Merged
jonasz-lasut merged 3 commits into
mainfrom
fix/rustls-and-debian13
Oct 8, 2026
Merged

jonasz-lasut merged 3 commits into
mainfrom
fix/rustls-and-debian13

Conversation

@jonasz-lasut

Copy link
Copy Markdown
Collaborator

Fixes the one advisory cargo audit reports against Cargo.lock and moves the example image off a Debian 12 base that carries two critical CVEs.

  • rustls 0.23.43 → 0.23.45 (RUSTSEC-2026-0285, GHSA-2mjx-qc3c-rqvc, medium): rustls accepted TLS 1.3 handshake messages sent at the wrong encryption level when they followed a key change in the same record. It reaches the SDK through tonic → tokio-rustls, so only Cargo.lock changes.
  • Example image on Debian 13: gcr.io/distroless/cc-debian12 is already pinned to its newest digest, which still ships libssl3 3.0.20 (critical CVE-2026-75803) and libc6 with critical CVE-2026-5450. The function uses aws-lc-rs for TLS, so the OpenSSL CVEs don't reach the binary, but image scanners still flag them. cc-debian13 scans at 0 critical / 11 high against 2 / 15 (grype, linux/amd64). The remaining highs are in the gcc runtime libraries, libc6 and zlib1g, with no fixed package yet. The build stage moves to rust:1.99-trixie so the binary links against the runtime image's glibc.
  • Renovate: a package rule groups both example/Dockerfile images into one renovate/example-function-images branch. Renovate keeps the -trixie tag suffix and the cc-debian13 image name, so moving to the next Debian release stays a manual edit of both lines.

Checked locally:

  • cargo audit reports no vulnerabilities; fmt, clippy -D warnings and tests pass.
  • The example image builds, starts with --insecure, and serves /metrics.
  • renovate-config-validator --strict passes. A --platform=local dry run against an outdated copy of the Dockerfile put the rust tag, rust digest and distroless digest updates on a single branch.

rustls 0.23.13 through 0.23.44 accepts TLS 1.3 handshake messages sent
at the wrong encryption level when they follow a key change in the same
record (RUSTSEC-2026-0285, GHSA-2mjx-qc3c-rqvc). rustls reaches the SDK
through tonic and tokio-rustls, so only the lockfile changes.

Signed-off-by: Jonasz Małecki <jonasz@upbound.io>
The newest gcr.io/distroless/cc-debian12 digest, the one already
pinned, ships libssl3 3.0.20 (critical CVE-2026-75803 plus four highs)
and libc6 with critical CVE-2026-5450. cc-debian13 scans at 0 critical
and 11 high against 2 and 15. The build stage moves to rust:1.99-trixie
so the binary links against the runtime image's glibc.

Signed-off-by: Jonasz Małecki <jonasz@upbound.io>
Renovate opened separate PRs for the rust build image and the
distroless runtime image. Group both so the two stages move together.

Renovate keeps the -trixie tag suffix and the cc-debian13 image name,
so moving to the next Debian release stays a manual edit of both lines.

Signed-off-by: Jonasz Małecki <jonasz@upbound.io>
@jonasz-lasut
jonasz-lasut marked this pull request as ready for review October 8, 2026 06:18
@jonasz-lasut
jonasz-lasut merged commit 402bcaa into main Oct 8, 2026
5 checks passed
@jonasz-lasut
jonasz-lasut deleted the fix/rustls-and-debian13 branch October 8, 2026 06:18
jonasz-lasut added a commit that referenced this pull request Oct 8, 2026
The rustls fix from #27 only changed this repo's Cargo.lock, which
projects depending on the SDK ignore. Declare rustls directly with a
0.23.45 floor so they cannot resolve a version affected by
RUSTSEC-2026-0285. default-features = false keeps the feature set that
tonic's tls-aws-lc already enables.

Signed-off-by: Jonasz Małecki <jonasz@upbound.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant