Skip to content

chore(main): release 0.2.3 - #87

Open
CodeMaster4711 wants to merge 1 commit into
mainfrom
release-please--branches--main
Open

chore(main): release 0.2.3#87
CodeMaster4711 wants to merge 1 commit into
mainfrom
release-please--branches--main

Conversation

@CodeMaster4711

@CodeMaster4711 CodeMaster4711 commented Mar 7, 2026

Copy link
Copy Markdown
Collaborator

🤖 I have created a release beep boop

0.2.3 (2026-07-28)

Features

  • add animated custom icons for all sidebar navigation items (8a331f4)
  • add auto-generated self-signed TLS to api-gateway (cdebae4)
  • add binary self-update for csf-agent and csf-updater via github releases (847dfe5)
  • add centralized log viewer with per-service tracing capture and admin retention settings (509f7a8)
  • add cidr suggestion, rg search, pinned rg cards and settings/delete actions (55b603c)
  • add container settings edit and fix compose port and status bugs (6da4250)
  • add container status detail, log streaming, and exec shell for workloads (3de5fab)
  • add container stop, restart, and performance insights UI with backend lifecycle support (1a03c1c)
  • add customizable icon, color and pinning for resource groups (fb130e6)
  • add docker compose stack deployment with service discovery and smart workload icons (4fef60f)
  • add firecracker microvm runtime alongside docker via runtime trait (91cf259)
  • add node reboot, power off, and drain actions (c606fea)
  • add patroni user, config template and entrypoint script (ec78a2e)
  • add redeploy and stack management for containers and compose stacks (ff3b1e7)
  • add resource picker with docker compose stacks and dynamic service icons (caf3acb)
  • add RG port mapping with dedicated container/RG/node port UI (e8f6ad5)
  • add rg_port dnat for resource-group-scoped port mapping (0e489f5)
  • add workload self-healing with real capacity scheduling and working failover (fbb344e)
  • addded ground setup for scheduler (2cca6f1)
  • added admin page and update page for cluster (ca13d40)
  • added agend volume mount (8549880)
  • added all frontend auth pages (3ace818)
  • added container placement in agent and scheduler (f84c304)
  • added endpoints in api gateway (c9a3563)
  • added frontend for one mono repo (924865b)
  • added gh token for image pulling without rate limiting (b62b2d1)
  • added graph with histroy (4e73dc5)
  • added ha with patroni on postgres (e6f6037)
  • added heartbeat logic to agent (a54df53)
  • added heartbeat logic to agent (04d3716)
  • added logo in header for svelte (48190b7)
  • added migrations for workloads (964c20a)
  • added mtls encryption (9692379)
  • added new alpha github run (40b7af5)
  • added new alpha github run (1ec1a76)
  • added nix config for nix os master node (8c3a866)
  • added OpenTelemetry Tracing (2d11250)
  • added own patroni image (f4b1938)
  • added pki for agent (73fd3ad)
  • added Prometheus Metrics and Rate Limiting (fbf9a48)
  • added rbac for all things (76faa2a)
  • added rbac for all things (3b1be5b)
  • added renovate (5d0b547)
  • added renovate via github actions (18de04d)
  • added ressource groups (e818f2f)
  • added ressource modell and workload specs (50aac08)
  • added sdn controller for network (59ace74)
  • added sdn controller for network (49b5ed9)
  • added update mech (0a33b2b)
  • added update stop and resume (fd01b36)
  • added user name in sidebar and added nodes page demo for testing (60f7e41)
  • added volume manager mount (f0e3313)
  • agent: log update signal when desired flake rev changes (0cfbcb6)
  • agents with mtls (bceb6e0)
  • allocate and configure guest ip for firecracker rg mesh (f891fea)
  • animated login button and fail modal (fcf45a2)
  • api-gateway: restrict system update endpoint to admin-only via RBAC (988342b)
  • attach rbd volumes to firecracker workloads via mmds (6cbbb49)
  • bring up per-resource-group wireguard mesh with persistent agent identity (72cb91f)
  • build and publish csfx-guest-init binary in release and prerelease pipelines (84fcdea)
  • build and publish csfx-guest-init binary in release pipeline (56aabd9)
  • build csf-updater locally via nix and publish alpha binaries to github releases (eb3df31)
  • build csf-updater locally via nix and publish alpha binaries to… (3d759e1)
  • build firecracker rootfs images via oci-client instead of docker (ac92280)
  • cluster-wide bootstrap tokens (b479ec6)
  • collect real cpu memory and network stats for firecracker vms (51b8c9d)
  • cp: wire csfx-updater as systemd service and rename units (5bd062e)
  • csf-updater: implement secure rust-based updater daemon with nixos integration (eb065a0)
  • csf-updater: verify image digests against GHCR before applying update (f791f42)
  • csfx-updater: add observability logs across update pipeline (fcd2495)
  • docker compose prod (d5ebd58)
  • drop jailer root privileges via uid gid allocator (0a54b98)
  • enforce resource group network isolation with per-rg bridges and nftables (7dd3533)
  • entry point for schedueler in etcd cluster (080225c)
  • etcd (5c0720a)
  • etcd: enable authentication and restrict access to csf service user (ba2a887)
  • expose agent and updater binary versions in update-status (08030a9)
  • force cgroup v2 hierarchy in guest kernel boot args (0f9ff80)
  • generate oci runtime spec config.json instead of shell entrypoint (688620b)
  • ground setup ceph storage (1ad3e67)
  • ground setup failover controler (806149f)
  • ground setup failover controler (47ea8b6)
  • ground setup registry for agents (9ed2f4a)
  • impl communcitaion and hearbeat (d51fb91)
  • implement gitops poller, git mirror, and nix build pipeline in csf-updater (d08736e)
  • implement watchdog heartbeat counter in registry and csf-updater (3024db4)
  • inject CSF_BUILD_VERSION into binaries at compile time via build.rs (8d18efb)
  • log workload output immediately and silence expected /dev EBUSY warning (4c6f71b)
  • login flow (9f18045)
  • new connection to db and refactor (063bc84)
  • new nix config (26ea9cc)
  • nix deployment for auto docker deploy (fb3c2da)
  • nix os config deploy on test server (b8b5aff)
  • pre reg agent for zero trust (85bd67a)
  • propagate agent version on every heartbeat and add live node metrics tunnel (72c46e3)
  • propagate desired_flake_rev via heartbeat response to agent update trigger (97914a6)
  • propagate post_update_heartbeats counter to agent for watchdog health check (88c0051)
  • push workload assignments to agents instead of relying on poll interval (993e29b)
  • reconcile firecracker vms from disk state on agent restart (4fe23df)
  • remove docker runtime and fix firecracker feature gaps exposed by removal (b79f429)
  • renam csf to csfx (6888431)
  • replace flake-rev API with version-based update scheduling (64dfe62)
  • resource-groups: add container deploy, volume management, and detail view (7b32db8)
  • run container workloads through libcontainer instead of hand-rolled init (b4f71d5)
  • serve frontend statically from api-gateway on port 8000 (69f0ad8)
  • setup ceph storage (a8c2dc5)
  • setup for etcd cluster (af2db8d)
  • setup ground struc agent (eeb12eb)
  • ssh: add ephemeral key-based SSH access to cluster nodes (e4940e7)
  • ui,agent,registry: add WireGuard P2S VPN, modal forms, and NodePort expose model (d8c098b)
  • use mutable binary paths for csf-agent and csf-updater to enable self-update (64e4326)
  • wire firecracker rg networking, dns and wireguard without docker (ac082cc)
  • wire real pty exec and rootfs entrypoint into guest-init (0c2d502)

Bug Fixes

  • add explicit host route to mmds address before fetching guest config (b1a5f68)
  • add patroni bootstrap script to create csf app user and database (0e07850)
  • added docker compose and fix build in docker (e24e7b9)
  • added log for testing update flow (8aaeef0)
  • added log for testing updater (2728d06)
  • added logging for testing (920e730)
  • agent (b09048e)
  • agent bootstrap error (013b2c8)
  • agent error (a6b0bbe)
  • agent: detect OS from /etc/os-release instead of sysinfo (1d86d69)
  • agent: rename state dir from csfx-daemon to csfx-agent (0ee1896)
  • agent: start docker on demand via systemd instead of at boot (86a2d7c)
  • allow mmds requests on guest network interface (3d0e59e)
  • api gateway and regisrty (68a9671)
  • api-gateway: exempt update status routes from rate limiting (fd08546)
  • api-gateway: make TLS config generation async to avoid block_on panic (ba21420)
  • append resource group search domain to vpn client dns config (cd417f7)
  • arm runner and manifest error (394f159)
  • arm runner and manifest error (a1ad641)
  • assign mmds bootstrap address before guest network fetch (44373d6)
  • attach firecracker tap devices to rg bridge and clean up stale rg networks (8591a8e)
  • auth probelm (80ef776)
  • auto-assign workloads to agents and wire up management wireguard tunnel (e1fa45a)
  • backend error (f4c6023)
  • backend error (cd69b8c)
  • backfill missing management tunnel ip for agents on heartbeat (d644977)
  • bound mmds fetch with timeout and read exact content-length (ce65500)
  • build error with updater hash (839fd28)
  • build errors and added frontend (b1cb885)
  • bump nixpkgs to 25.05 for Cargo 1.85/edition2024 support (ddb75f3)
  • cargo fmt (93ce25f)
  • cert issue (f544e36)
  • ci (ceb3486)
  • ci (2d5b689)
  • ci pipeline new setup with nix (eaffdf5)
  • clean up rootfs extract directory before and after failed layer extraction (95f9c57)
  • clean up stale jailer chroot directory before each start attempt (4c756a0)
  • coerce port fields to string before trim in resource group deploy form (49d667a)
  • compile errors (6cfe5ae)
  • correct pre-release version comparison and let forced updates bypass pause (46266c7)
  • create csfx role and database during patroni bootstrap (7d0486c)
  • create metrics fifo before configuring firecracker metrics endpoint (b412801)
  • create standard guest root directories missing after bundle layout change (cb700f2)
  • csf-updater: run as dedicated system user with docker group instead of root (22cf1e5)
  • csf-updater: validate version string from etcd before executing update (13e9fdf)
  • csfx-updater: add --no-out-link to nixos-rebuild build to avoid permission error (0b8e472)
  • dep update axum 0.7 -> 0.8 (9be3ff4)
  • deps reqwest 0.11 -> 0.13 (864c2db)
  • deps: update dependency @icons-pack/svelte-simple-icons to v7 (01dd084)
  • deps: update dependency @icons-pack/svelte-simple-icons to v7 (e5cef90)
  • deps: update rust dependencies (2fe8332)
  • deps: update rust dependencies (b2e32f0)
  • dev bootstrap (1547ee8)
  • disable firecracker seccomp filter incompatible with musl syscalls (9b63df4)
  • disable oci-client default features to remove aws-lc-sys from musl builds (e5b09c6)
  • disable rustls default aws-lc-rs feature to fix musl aarch64 link (8c61471)
  • docker access in updater error (ce45cba)
  • docker compose (8fd8be6)
  • docker container on nix (a285a18)
  • docker container on nix (2aca464)
  • docker long build (2372614)
  • docker prod build (581a20d)
  • docker start (a247b64)
  • docker updater error (d8f7457)
  • eliminate aws-lc-sys from musl build by switching to ring crypto provider across all services (4045fbb)
  • erros (15623c3)
  • etcd connection error (1a44dc1)
  • etcd: block etcd ports from external access via firewall rules in install script (34e1cd2)
  • exempt agent heartbeat/workloads/volumes routes from rate limiting (1b4d3c3)
  • filter noisy access, sql, heartbeat and performance events from log storage (a6f7510)
  • fix rg dns write sandbox failure and reconcile orphaned containers on agent restart (b6f2a5d)
  • for local dev env (5decf9b)
  • format (73ab945)
  • gateway: exempt registry routes from rate limiting (c9f30e9)
  • github pipeline (791c518)
  • github pipleine time (f88850e)
  • github pipleine time (6e8e2cd)
  • gitignore (d6c3dca)
  • ha for postgres with patroni (078de22)
  • handle 429 rate limit in agent registration with retry backoff (31d3c29)
  • image version (cd9b47c)
  • include guest-init binary version in rootfs cache key (128f562)
  • include response body in firecracker api error messages (3967e93)
  • install rustls aws-lc-rs crypto provider before TLS init (5ccb37d)
  • leader election (28871eb)
  • leader select (e5d8867)
  • load times on svg main (e37e88b)
  • load xterm dynamically to avoid SSR CJS named export error (db41761)
  • lock state when updater go into error (28c0247)
  • log full error chain for mmds route and fetch failures (84f4b54)
  • make bootstrap registration idempotent by upserting on hostname (98a935a)
  • make firecracker binary path configurable via env var (da9fa98)
  • manifest build (dd5d522)
  • master node auto-bootstrap — self-register agent via admin API on first boot (1d64a1f)
  • match firecracker cmdline after jailer execve for pid lookup (3940ee4)
  • merge errors (3d808ae)
  • metrics error agent (4ac4ce8)
  • migrate axum routes to 0.8 syntax and downgrade sysinfo to 0.32 (d29d12d)
  • migration in docker dev enviroment and auth fix frontend (8140686)
  • mtls handshake (cbe31b3)
  • mtls heart beat (93fb782)
  • mtls heart beat (869170f)
  • mtls issue (26e0cb2)
  • mulitple docker builds (9a857ca)
  • mulitple docker builds (6a55d51)
  • new structure project (5280c7e)
  • new test version (109c775)
  • nix compile error (8d6d32e)
  • nix compile error (48d2bde)
  • nix config error (6b5adf7)
  • nix config with path (1d80789)
  • nix container version (4e6da4e)
  • nix error (ebfdf55)
  • nix os config version (8ed2d60)
  • nixos test version updated (0230d7f)
  • nixos updater error (2b46867)
  • nixos version (64cfcec)
  • node deduplication and cluster telemetry (2259013)
  • nodes offline check (353f803)
  • parse firecracker api response by content-length instead of eof (9c4d0b4)
  • path error in updater (e10e08f)
  • patroni bootstrap error (5895235)
  • patroni internal error from bootstrap (d52bc00)
  • pin rust 1.88.0 via rust-overlay for edition2024/time crate support (2b6bc89)
  • pipeline (d01b1ee)
  • pipeline (25a9442)
  • pipeline (4f38260)
  • pipeline (3f6b004)
  • pipeline build error (ddbfc81)
  • pipeline docker build (c7d94c1)
  • pipeline docker build (909cc1a)
  • pipeline docker image (5f91789)
  • pipeline docker image (c5743de)
  • pipeline time (20e929c)
  • pipeline time (a642161)
  • pipleine (bcdc605)
  • pipleine (885eadd)
  • point resource group Corefile at actual zone file directory (8f9c4a6)
  • provide complete workspace structure to cargo-chef (d1c2022)
  • provide complete workspace structure to cargo-chef (5bef937)
  • proxy api requests to https gateway with insecure flag for dev (d65b24c)
  • rate limit by authenticated user instead of shared ip bucket (4f166c3)
  • rate-limit agents by API key hash instead of shared IP bucket (d4ab5ff)
  • recreate resource group dns container when stale instead of skipping (b9949e5)
  • recreate stale dns containers, drop loopback proxy shortcut, fix stats history query, and handle 401 in frontend (282e8cb)
  • registry: make AgentStatus::from_str case-insensitive (e80d89b)
  • registry: migrate route params from :param to {param} syntax (af9e2ec)
  • remove dead ready-signal wait blocking guest-init boot (491570b)
  • remove NoNewPrivileges to allow sudo systemctl for binary restart (ddc22b8)
  • remove ssh console button from node detail sheet (5bc2905)
  • remove unsupported allow_mmds_requests field from network-interface config (6d12a37)
  • removed old scripts (dc19cb5)
  • renovate (1b87f10)
  • repair jailer chroot cleanup and resource group dns for firecracker workloads (182aa70)
  • replace aws-lc-rs with ring for musl aarch64 (7fdc686)
  • replace rustls-tls feature with rustls for reqwest 0.13 compat (bf6d095)
  • repo (fa07190)
  • request mmds root path instead of latest/meta-data in guest-init (eef9357)
  • resolve musl build failure for csf-updater binary (50a89e8)
  • restrict binary dir permissions and verify sha256 checksum on download (2b3260f)
  • retry metrics forwarding to gateway and log permanent failures as errors (62f9224)
  • reverse proxy on registry routet through api gateway (6e2ce4f)
  • rm enity folder in every project (dbd5178)
  • rollback on failed update flow (a1109d2)
  • route agent proxy calls via loopback when target is the local WireGuard tunnel IP (be9d879)
  • run jailer as agent uid/gid so socket permissions match (83fe2e7)
  • securtity issue fix sha-1 to sha-256 (4252495)
  • securtiy issues on agent registration (228a81f)
  • seed vsock cid counter from host state and clean up jailer on boot failure (82cea21)
  • set tap device owner and named systemd unit for privileged chroot cleanup (43949f9)
  • set TLS_ENABLED=false in docker-compose and accept self-signed certs in agent (a14e75d)
  • set working directory to /tmp for nixos-rebuild to avoid symlink permission error (74b7bd1)
  • shared folder (bc7ce08)
  • shared folder (752f4df)
  • shorten jailer chroot path to fit unix socket SUN_LEN limit (fb1b2da)
  • sign gateway tls cert from internal ca and persist container state across reboot (1a6180b)
  • single-node patroni+etcd, remove haproxy (45952da)
  • small change for testing updater (1f5509f)
  • spawn jailer as root via systemd-run and fix chroot base dir nesting (90329e4)
  • ssh error for dev (a6a4fc9)
  • stage kernel, rootfs, and volume devices inside firecracker jailer chroot (270ff86)
  • stop forwarding raw agent status codes as gateway response codes (f286562)
  • strip digest newlines to prevent invalid image reference in manifest (fdd4d7e)
  • strip trailing semicolon from parsed nix version strings (346e5f4)
  • structure porject fix (8d40d6a)
  • structure project (d2d83f1)
  • swagger ui (54113f4)
  • swagger ui (033f790)
  • switch rustls provider from aws-lc-rs to ring for musl compat (7c6c62b)
  • sync missing permissions to existing Admin role on startup (bf050ae)
  • sync workload status on stop/restart and auto-detect gateway TLS SAN (7be20b8)
  • token route for dev (97d0776)
  • unblock agent log streaming and auto-allocate node ports (56a09fc)
  • unblock manual updates, auto-allocate agent tunnel IP, fix ceph rbd config (a4ef5f8)
  • update bollard, rand, sysinfo, axum FromRequestParts for dep updates (588d22b)
  • updater (e1b45c8)
  • updater (a637575)
  • updater error with images and pull (bbb8694)
  • updater flow (3d9b26c)
  • updater flow with api-gateway (1de5b80)
  • updater flow with api-gateway (5bf29ab)
  • updater test file (8a277df)
  • updater test file (5008a78)
  • updater: correct GitHub refs API path and treat 304 as no-op (e11c40e)
  • updater: set explicit nixosConfigurations attr in flake URL to match csfx-node (bdaa676)
  • updater: surface version resolution failures to etcd (9ad7152)
  • use docker icon for compose stack row instead of generic layers icon (7ca06ad)
  • use jail-relative metrics path so firecracker can create it in chroot (e651b36)
  • use native byte order when packing ipv4 sockaddr for ioctl calls (6d926cc)
  • use portable c_char type for interface name buffer on arm64 musl (ea88be5)
  • use relative API URLs for same-origin deployment (16495a4)
  • verify agent stream tls against internal ca and pull missing coredns image (69d4910)
  • version docker image (8768620)
  • wait for auth token before loading data on nodes, resource-groups and logs pages (9ff3735)
  • wait for auth token before loading resource group on mount (b67e6f1)
  • wait for ca file and order gateway after registry to avoid self-signed race (b1f256f)
  • wire TLS through dev environment for gateway, agents, and registry (8028bae)
  • workflow (c71c60f)

This PR was generated with Release Please. See documentation.

@CodeMaster4711
CodeMaster4711 force-pushed the release-please--branches--main branch from 1eb9ce6 to f5d7705 Compare March 7, 2026 21:46
@CodeMaster4711
CodeMaster4711 force-pushed the release-please--branches--main branch 18 times, most recently from 800235c to e4d452c Compare March 11, 2026 20:06
@CodeMaster4711
CodeMaster4711 force-pushed the release-please--branches--main branch from e4d452c to 7c453e3 Compare March 17, 2026 19:33
@CodeMaster4711
CodeMaster4711 force-pushed the release-please--branches--main branch from 7c453e3 to 3c5aef6 Compare April 22, 2026 12:01
@CodeMaster4711
CodeMaster4711 force-pushed the release-please--branches--main branch from 3c5aef6 to 80a8e5b Compare May 16, 2026 19:25
@CodeMaster4711
CodeMaster4711 force-pushed the release-please--branches--main branch 5 times, most recently from 18b80a5 to 1bc718b Compare June 17, 2026 18:13
@CodeMaster4711
CodeMaster4711 force-pushed the release-please--branches--main branch from 1bc718b to d6ca385 Compare June 17, 2026 18:22
@CodeMaster4711
CodeMaster4711 force-pushed the release-please--branches--main branch from ea778d6 to c1a26bb Compare July 25, 2026 18:28
@github-actions

Copy link
Copy Markdown
Contributor

cargo audit found vulnerabilities:

  • RUSTSEC-2026-0204 crossbeam-epoch@0.9.18: Invalid pointer dereference in fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid
  • RUSTSEC-2023-0071 rsa@0.9.10: Marvin Attack: potential key recovery through timing sidechannels

@CodeMaster4711
CodeMaster4711 force-pushed the release-please--branches--main branch from c1a26bb to a6876ae Compare July 25, 2026 19:13
@github-actions

Copy link
Copy Markdown
Contributor

cargo audit found vulnerabilities:

  • RUSTSEC-2026-0204 crossbeam-epoch@0.9.18: Invalid pointer dereference in fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid
  • RUSTSEC-2023-0071 rsa@0.9.10: Marvin Attack: potential key recovery through timing sidechannels

@CodeMaster4711
CodeMaster4711 force-pushed the release-please--branches--main branch from a6876ae to f5a2fbc Compare July 26, 2026 11:35
@github-actions

Copy link
Copy Markdown
Contributor

cargo audit found vulnerabilities:

  • RUSTSEC-2026-0204 crossbeam-epoch@0.9.18: Invalid pointer dereference in fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid
  • RUSTSEC-2023-0071 rsa@0.9.10: Marvin Attack: potential key recovery through timing sidechannels

@CodeMaster4711
CodeMaster4711 force-pushed the release-please--branches--main branch from f5a2fbc to da457f5 Compare July 26, 2026 12:26
@github-actions

Copy link
Copy Markdown
Contributor

cargo audit found vulnerabilities:

  • RUSTSEC-2026-0204 crossbeam-epoch@0.9.18: Invalid pointer dereference in fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid
  • RUSTSEC-2023-0071 rsa@0.9.10: Marvin Attack: potential key recovery through timing sidechannels

@CodeMaster4711
CodeMaster4711 force-pushed the release-please--branches--main branch from da457f5 to 3efdc74 Compare July 26, 2026 13:16
@github-actions

Copy link
Copy Markdown
Contributor

cargo audit found vulnerabilities:

  • RUSTSEC-2026-0204 crossbeam-epoch@0.9.18: Invalid pointer dereference in fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid
  • RUSTSEC-2023-0071 rsa@0.9.10: Marvin Attack: potential key recovery through timing sidechannels

@CodeMaster4711
CodeMaster4711 force-pushed the release-please--branches--main branch from 3efdc74 to 0165a10 Compare July 26, 2026 18:08
@github-actions

Copy link
Copy Markdown
Contributor

cargo audit found vulnerabilities:

  • RUSTSEC-2026-0204 crossbeam-epoch@0.9.18: Invalid pointer dereference in fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid
  • RUSTSEC-2023-0071 rsa@0.9.10: Marvin Attack: potential key recovery through timing sidechannels

@CodeMaster4711
CodeMaster4711 force-pushed the release-please--branches--main branch from 0165a10 to c65c4c1 Compare July 26, 2026 18:31
@github-actions

Copy link
Copy Markdown
Contributor

cargo audit found vulnerabilities:

  • RUSTSEC-2026-0204 crossbeam-epoch@0.9.18: Invalid pointer dereference in fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid
  • RUSTSEC-2023-0071 rsa@0.9.10: Marvin Attack: potential key recovery through timing sidechannels

@CodeMaster4711
CodeMaster4711 force-pushed the release-please--branches--main branch from c65c4c1 to b3443d8 Compare July 26, 2026 18:47
@github-actions

Copy link
Copy Markdown
Contributor

cargo audit found vulnerabilities:

  • RUSTSEC-2026-0204 crossbeam-epoch@0.9.18: Invalid pointer dereference in fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid
  • RUSTSEC-2023-0071 rsa@0.9.10: Marvin Attack: potential key recovery through timing sidechannels

@CodeMaster4711
CodeMaster4711 force-pushed the release-please--branches--main branch from b3443d8 to 2d8d9ec Compare July 26, 2026 19:05
@github-actions

Copy link
Copy Markdown
Contributor

cargo audit found vulnerabilities:

  • RUSTSEC-2026-0204 crossbeam-epoch@0.9.18: Invalid pointer dereference in fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid
  • RUSTSEC-2023-0071 rsa@0.9.10: Marvin Attack: potential key recovery through timing sidechannels

10 similar comments
@github-actions

Copy link
Copy Markdown
Contributor

cargo audit found vulnerabilities:

  • RUSTSEC-2026-0204 crossbeam-epoch@0.9.18: Invalid pointer dereference in fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid
  • RUSTSEC-2023-0071 rsa@0.9.10: Marvin Attack: potential key recovery through timing sidechannels

@github-actions

Copy link
Copy Markdown
Contributor

cargo audit found vulnerabilities:

  • RUSTSEC-2026-0204 crossbeam-epoch@0.9.18: Invalid pointer dereference in fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid
  • RUSTSEC-2023-0071 rsa@0.9.10: Marvin Attack: potential key recovery through timing sidechannels

@github-actions

Copy link
Copy Markdown
Contributor

cargo audit found vulnerabilities:

  • RUSTSEC-2026-0204 crossbeam-epoch@0.9.18: Invalid pointer dereference in fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid
  • RUSTSEC-2023-0071 rsa@0.9.10: Marvin Attack: potential key recovery through timing sidechannels

@github-actions

Copy link
Copy Markdown
Contributor

cargo audit found vulnerabilities:

  • RUSTSEC-2026-0204 crossbeam-epoch@0.9.18: Invalid pointer dereference in fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid
  • RUSTSEC-2023-0071 rsa@0.9.10: Marvin Attack: potential key recovery through timing sidechannels

@github-actions

Copy link
Copy Markdown
Contributor

cargo audit found vulnerabilities:

  • RUSTSEC-2026-0204 crossbeam-epoch@0.9.18: Invalid pointer dereference in fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid
  • RUSTSEC-2023-0071 rsa@0.9.10: Marvin Attack: potential key recovery through timing sidechannels

@github-actions

Copy link
Copy Markdown
Contributor

cargo audit found vulnerabilities:

  • RUSTSEC-2026-0204 crossbeam-epoch@0.9.18: Invalid pointer dereference in fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid
  • RUSTSEC-2023-0071 rsa@0.9.10: Marvin Attack: potential key recovery through timing sidechannels

@github-actions

Copy link
Copy Markdown
Contributor

cargo audit found vulnerabilities:

  • RUSTSEC-2026-0204 crossbeam-epoch@0.9.18: Invalid pointer dereference in fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid
  • RUSTSEC-2023-0071 rsa@0.9.10: Marvin Attack: potential key recovery through timing sidechannels

@github-actions

Copy link
Copy Markdown
Contributor

cargo audit found vulnerabilities:

  • RUSTSEC-2026-0204 crossbeam-epoch@0.9.18: Invalid pointer dereference in fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid
  • RUSTSEC-2023-0071 rsa@0.9.10: Marvin Attack: potential key recovery through timing sidechannels

@github-actions

Copy link
Copy Markdown
Contributor

cargo audit found vulnerabilities:

  • RUSTSEC-2026-0204 crossbeam-epoch@0.9.18: Invalid pointer dereference in fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid
  • RUSTSEC-2023-0071 rsa@0.9.10: Marvin Attack: potential key recovery through timing sidechannels

@github-actions

Copy link
Copy Markdown
Contributor

cargo audit found vulnerabilities:

  • RUSTSEC-2026-0204 crossbeam-epoch@0.9.18: Invalid pointer dereference in fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid
  • RUSTSEC-2023-0071 rsa@0.9.10: Marvin Attack: potential key recovery through timing sidechannels

@github-actions

Copy link
Copy Markdown
Contributor

cargo audit found vulnerabilities:

  • RUSTSEC-2026-0204 crossbeam-epoch@0.9.18: Invalid pointer dereference in fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid
  • RUSTSEC-2023-0071 rsa@0.9.10: Marvin Attack: potential key recovery through timing sidechannels

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant