Bump x509-parser from 0.14.0 to 0.18.1 - #197
Conversation
Bumps [x509-parser](https://github.com/rusticata/x509-parser) from 0.14.0 to 0.18.1. - [Changelog](https://github.com/rusticata/x509-parser/blob/master/CHANGELOG.md) - [Commits](https://github.com/rusticata/x509-parser/commits) --- updated-dependencies: - dependency-name: x509-parser dependency-version: 0.18.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
There was a problem hiding this comment.
Dependabot review: x509-parser 0.14.0 → 0.18.1 — safe to merge ✅
Audited every use of x509-parser in the workspace against the API changes across 0.15–0.18. The library and wasm bindings build, and the full test suite (including the time-sensitive tests that validate real attestation docs) passes locally, matching the PR's green CI.
Scope of the bump
Only the local workspace crate attestation-doc-validation (v0.10.1) — and therefore wasm-attestation-bindings, which uses the path dependency — actually picks up 0.18.1. The node/python/swift/kotlin bindings depend on the published crates (0.9.0 / 0.10.0) which stay on x509-parser 0.14.0, so they're unaffected. Transitive bumps: asn1-rs 0.5→0.7, der-parser 8→10, oid-registry 0.6→0.8, and thiserror 1→2 scoped inside the x509-parser subtree.
API usage — all still valid
X509Certificate,parse_x509_certificate,pem::parse_x509_pem,error::PEMError— unchanged.get_extension_unique/parsed_extension/ParsedExtension::SubjectAlternativeName { general_names }— unchanged.GeneralName::DNSName(&str)— unchanged. 0.18 adds a newGeneralName::Invalidvariant; the code matches non-exhaustively (let … else/filter_map), so it compiles and behaves correctly. Behavioural note: an invalid SAN entry no longer aborts parsing of the whole SAN list (it becomesInvalidand is skipped) — harmless here since we only pick the longestDNSName.x509::SubjectPublicKeyInfo { subject_public_key: BitString, raw: &[u8] }— unchanged between 0.14 and 0.18.oid_registry::asn1_rs::BitString<'a>— identical between asn1-rs 0.5.2 and 0.7.2 (same fields, lifetime, andAsRef<[u8]>impl), sonsm/pkey.rsis unaffected.oid_registry::Oid::from_str— unchanged.
Security / performance
No concerns. Default features are still default = [] in both versions (the verify/ring crypto backend remains optional and is not enabled here), so the wasm target still builds without pulling ring. The bumped deps (thiserror 2, asn1-rs 0.7, der-parser 10) are maintained releases. I also verified the unusual-looking syn 3.0.3 and thiserror-impl 2.0.20 → syn ^3 lockfile entries against the live crates.io sparse index — checksums match; not a tampered lockfile.
Verification performed
cargo build/cargo check— OK (only pre-existing lint warnings).cargo testincl.time_sensitive_beta(FAKETIME=1674054914) andtime_sensitive_ga(FAKETIME=1695050165) — all pass (real cert parse, SAN extraction, trust-chain validation, COSE signature verification).cargo clippy -- -W clippy::pedanticandcargo fmt --check— clean.wasm-attestation-bindingsbuilt forwasm32-unknown-unknown— OK.
No source changes were needed.
Bumps x509-parser from 0.14.0 to 0.18.1.
Changelog
Sourced from x509-parser's changelog.
... (truncated)
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)