Dependency and vsock-proxy maintenance release. cargo audit on this tree reports no vulnerabilities (11 in 1.5.1).
Changes:
- Move to
aws-nitro-enclaves-image-format0.8.1, which bringsaws-nitro-enclaves-cose0.6.1 and the currentaws-sdk-kms. This drops the vulnerable hyper 0.14, h2 0.3, rustls 0.21 and rustls-webpki 0.101 chain. KMS signing inbuild-enclavenow honoursHTTP_PROXY,HTTPS_PROXYandNO_PROXY; setNO_PROXY=*to keep the old behaviour. - vsock-proxy moves to
hickory-resolver0.26 (fixes RUSTSEC-2026-0119 in hickory-proto 0.24). IPv4-first lookup order is kept. - vsock-proxy DNS hardening: IP literals no longer need a working
resolv.conf; aresolv.confwithout anameserverline falls back to/etc/hostswith a warning; the start-up lookup retries three times; a failed refresh after the TTL expires keeps the last known address for 30 s instead of exiting the proxy. - Helper crates:
aws-nitro-enclaves-enclave-build2.0.0 (public API now uses image-format 0.8 types) andaws-nitro-enclaves-eif-loader1.0.1 (unused image-format dependency removed).aws-nitro-enclaves-driver-bindingsstays at 1.0.0. - Vendored dependency tarball for the RPM build refreshed.
No changes to enclave blobs, the driver or the allocator since 1.5.1.
Full Changelog: v1.5.1...v1.5.2