diff --git a/CHANGELOG.md b/CHANGELOG.md index 0e4281c..37d219d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -10,6 +10,18 @@ breaking is [written down in CONTRIBUTING.md](CONTRIBUTING.md#compatibility) — command names, flags, the two output modes and the exit codes are promises; the Mapbox APIs' own response bodies are not. +## Unreleased + +### Security + +- `rustls` moved to 0.23.45 in `Cargo.lock`, fixing + [RUSTSEC-2026-0285](https://rustsec.org/advisories/RUSTSEC-2026-0285) — + "TLS 1.3 handshake messages incorrectly accepted across encryption level + boundaries", medium severity, published 2026-09-14. `rustls` is reached + through `reqwest`, so every HTTPS request this CLI makes used the affected + version; nothing in this crate had to change. Lockfile only, and the one + crate. + ## 0.1.8 - 2026-09-14 Initial beta release. The next release is `0.2.0`. diff --git a/Cargo.lock b/Cargo.lock index fbe5901..6ca418b 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -1110,9 +1110,9 @@ checksum = "6b1e7f9a428571be2dc5bc0505c13fb6bf936822b894ec87abf8a08a4e51742d" [[package]] name = "rustls" -version = "0.23.44" +version = "0.23.45" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "6725596c3f2c3a0aef021139e145d4eafe314a6623e4680ca83852b2c67ab2ba" +checksum = "0d41d731c7d2f962d1ccc364cec258de3c0e93b38c2fb3ba97ac74513048d634" dependencies = [ "once_cell", "ring",