Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion .github/workflows/dependency-check.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -64,7 +64,8 @@ jobs:
# reading https://github.com/rustsec/advisory-db/issues/288, this is a false
# positive for clap and based on our dependency tree, we only use `yaml-rust` in `clap`.
# * RUSTSEC-2026-0258: The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit.
# We're stuck with it for the moment until we upgrade hyper (bug 2067851).
# The only remaining hyper 0.14 path is viaduct-hyper, which is being moved to reqwest in
# bug 2067851 (PR #7596); this ignore can go away once that lands.
# viaduct-hyper is only used for connecting to remote-settings, a server unser Mozilla's control
# and thus not running into the issue.
cargo audit --ignore RUSTSEC-2018-0006 --ignore RUSTSEC-2026-0258
Expand Down
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,10 @@
### Glean
- Updated to v70.0.0 ([#7598](https://github.com/mozilla/application-services/pull/7598))

### Nimbus

- `nimbus-cli`'s `start-server` now runs on `axum` 0.8 (and so `hyper` 1.x) instead of `axum` 0.6 / `hyper` 0.14, which removes the `h2` 0.3 flagged by RUSTSEC-2026-0258 from its own dependencies. No change to the server's behaviour or its URLs. ([bug 2071060](https://bugzilla.mozilla.org/show_bug.cgi?id=2071060))

# v157.0 (_2026-09-10_)

## ✨ What's Changed ✨
Expand Down
Loading
Loading