github aws/aws-nitro-enclaves-cli v1.5.2

3 hours ago

Dependency and vsock-proxy maintenance release. cargo audit on this tree reports no vulnerabilities (11 in 1.5.1).

Changes:

  • Move to aws-nitro-enclaves-image-format 0.8.1, which brings aws-nitro-enclaves-cose 0.6.1 and the current aws-sdk-kms. This drops the vulnerable hyper 0.14, h2 0.3, rustls 0.21 and rustls-webpki 0.101 chain. KMS signing in build-enclave now honours HTTP_PROXY, HTTPS_PROXY and NO_PROXY; set NO_PROXY=* to keep the old behaviour.
  • vsock-proxy moves to hickory-resolver 0.26 (fixes RUSTSEC-2026-0119 in hickory-proto 0.24). IPv4-first lookup order is kept.
  • vsock-proxy DNS hardening: IP literals no longer need a working resolv.conf; a resolv.conf without a nameserver line falls back to /etc/hosts with a warning; the start-up lookup retries three times; a failed refresh after the TTL expires keeps the last known address for 30 s instead of exiting the proxy.
  • Helper crates: aws-nitro-enclaves-enclave-build 2.0.0 (public API now uses image-format 0.8 types) and aws-nitro-enclaves-eif-loader 1.0.1 (unused image-format dependency removed). aws-nitro-enclaves-driver-bindings stays at 1.0.0.
  • Vendored dependency tarball for the RPM build refreshed.

No changes to enclave blobs, the driver or the allocator since 1.5.1.

Full Changelog: v1.5.1...v1.5.2

Don't miss a new aws-nitro-enclaves-cli release

NewReleases is sending notifications on new releases.