Skip to content

deps: bump russh from 0.62.7 to 0.63.1 - #205

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/russh-0.62.7
Closed

deps: bump russh from 0.62.7 to 0.63.1#205
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/russh-0.62.7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 21, 2026

Copy link
Copy Markdown
Contributor

Bumps russh from 0.62.7 to 0.63.1.

Release notes

Sourced from russh's releases.

v0.63.1

Security fixes

GHSA-47hw-gvq5-r2gm - client-side Handler callbacks reachable with invalid channel IDs

A mirror of GHSA-m65r-rprj-r5rg for the client side - Handler per-channel callbacks are called even when the server supplies an invalid (never opened) channel ID. Depending on what the handler does this can lead to a vulnerability.

GHSA-p8qx-h547-fjw9 - MAC-requiring block cipher can be negotiated without MAC and panic

Two peers disagreeing on supported MACs can end up negotiating none MAC for a cipher that requires one, which leads to the session task panicking.

v0.63.0

Features

  • 09f6582: Support host certificates on the client side (#752) (@​biao29) #752

    • This changes the signature of Handler::check_server_key to take a new PublicKeyOrCertificate enum instead of &PublicKey
  • d7601ae: Support host certificates on the server side (#641) (Georg von Zengen) #641

    • Adds a Config::certificates that functions similarly to Config::keys

Fixes

  • f2354c7: improve strict kex checks (Eugene)
  • 0363fde: fixed PKCS#8 parsing panicking on incorrect contents (Eugene)
  • 46c927a: use constant-time comparison for agent unlock (Eugene)
  • 8da8967: sanitize Curve25519 params (Eugene)

Full Changelog: Eugeny/russh@v0.62.7...v0.63.0

v0.63.0-beta.1

Features

  • 09f6582: Support host certificates on the client side (#752) (@​biao29) #752
  • d7601ae: Support host certificates on the server side (#641) (Georg von Zengen) #641

Full Changelog: Eugeny/russh@v0.62.7...v0.63.0-beta.1

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Aug 21, 2026
Bumps [russh](https://github.com/warp-tech/russh) from 0.62.7 to 0.63.1.
- [Release notes](https://github.com/warp-tech/russh/releases)
- [Commits](Eugeny/russh@v0.62.7...v0.63.1)

---
updated-dependencies:
- dependency-name: russh
  dependency-version: 0.62.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title deps: bump russh from 0.62.5 to 0.62.7 deps: bump russh from 0.62.7 to 0.63.1 Aug 28, 2026
@dependabot
dependabot Bot force-pushed the dependabot/cargo/russh-0.62.7 branch from 6ea926b to d6ccaed Compare August 28, 2026 06:17
@dependabot @github

dependabot Bot commented on behalf of github Aug 28, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #211.

@dependabot dependabot Bot closed this Aug 28, 2026
@dependabot
dependabot Bot deleted the dependabot/cargo/russh-0.62.7 branch August 28, 2026 09:13
davekempe added a commit that referenced this pull request Aug 29, 2026
russh 0.63 changed the check_server_key callback to take
&PublicKeyOrCertificate; resolve it to a PublicKey via .public_key() in
both the tunnel and probe handlers, and widen the russh constraint to
0.63. Closes the retargeted dependabot PRs #204 (uuid) and #205 (russh).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants