From 2953e636acb938baf561a2b43bcf153a2e32a460 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ralph=20K=C3=BCpper?= Date: Tue, 22 Sep 2026 19:44:19 +0200 Subject: [PATCH] ci: drop the rustls 0.23.45 security exception now that it has soaked The exception let rustls 0.23.45 (RUSTSEC-2026-0285) in before its seven-day publish soak finished and expired on 2026-09-21. soak.py fails on any expired exception, so every CI run since then has failed the dependencies job, including main's next run. The version has now soaked, so the exception is no longer needed: soak.py passes with 0 exceptions against the same lockfile. --- scripts/ci/policy.toml | 8 -------- 1 file changed, 8 deletions(-) diff --git a/scripts/ci/policy.toml b/scripts/ci/policy.toml index 774d587..25341a5 100644 --- a/scripts/ci/policy.toml +++ b/scripts/ci/policy.toml @@ -13,11 +13,3 @@ banned = [ "async-executor", "async-global-executor", "futures-executor", "futures-runtime", "http-body", "http-body-util", ] - -# Remove as soon as the exact registry timestamp has completed its seven-day soak. -[[security-exceptions]] -crate = "rustls" -version = "0.23.45" -advisory = "RUSTSEC-2026-0285" -reason = "Fix TLS 1.3 handshake messages accepted across encryption-level boundaries" -expires = 2026-09-21