Skip to content

fix(deps): upgrade lettre to 0.11.22 (RUSTSEC-2026-0141)#1208

Open
Hypn0sis wants to merge 1 commit into
RightNow-AI:mainfrom
Hypn0sis:pr/fix-lettre-security
Open

fix(deps): upgrade lettre to 0.11.22 (RUSTSEC-2026-0141)#1208
Hypn0sis wants to merge 1 commit into
RightNow-AI:mainfrom
Hypn0sis:pr/fix-lettre-security

Conversation

@Hypn0sis
Copy link
Copy Markdown
Contributor

Summary

  • Upgrades lettre from 0.11.21 to 0.11.22 in Cargo.lock
  • Fixes RUSTSEC-2026-0141: TLS hostname verification disabled when using Boring TLS backend (severity 9.1 critical, advisory date 2026-05-14)
  • Cargo.toml workspace constraint is already version = "0.11" - only Cargo.lock needed updating
  • No API changes between 0.11.21 and 0.11.22 - pure security patch release

Closes #1208

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant