Security Fix
fix: verify TLS handshake signatures in #172
Fixed an issue where an invalid certificate could be accepted during the TLS handshake when using a custom certificate validation callback.
We recommend updating applications that use a custom certificate validation callback.
Fixes
- Fix invalid request headers aborting native process by @mayuki in #173
- Clear buffer array when returning it to the pool by @mayuki in #175
- Keep certificate verification callback until native context disposal by @mayuki in #176
What's Changed
- Bump 1password/load-secrets-action from 3.1.0 to 3.2.1 in the dependencies group by @dependabot[bot] in #160
- Bump 1password/load-secrets-action from 3.2.1 to 4.0.0 in the dependencies group by @dependabot[bot] in #161
- ci: fix seiton detected run-env-context-direct-use by @guitarrapc in #164
- ci: github actions parser error by @guitarrapc in #165
- Bump actions-rust-lang/setup-rust-toolchain from 1.15.0 to 1.16.1 in the dependencies group across 1 directory by @dependabot[bot] in #162
- Bump actions-rust-lang/setup-rust-toolchain from 1.16.1 to 1.17.0 in the dependencies group by @dependabot[bot] in #166
- ci: add pr harness check by @guitarrapc in #167
- Bump 1password/load-secrets-action from 4.0.0 to 4.1.1 in the dependencies group by @dependabot[bot] in #168
- Bump 1password/load-secrets-action from 4.1.1 to 5.0.0 in the dependencies group by @dependabot[bot] in #169
- Bump actions-rust-lang/setup-rust-toolchain from 1.17.0 to 2.0.0 in the dependencies group by @dependabot[bot] in #170
- chore: add "Build succeeded!" when export completed. by @guitarrapc in #174
Full Changelog: 1.11.5...1.11.6