Commit e07bfac
committed
chore(deps): upgrade h2 to 0.4.19 (RUSTSEC-2026-0258)
Upgrade the transitive h2 dependency from 0.4.15 to the latest patched 0.4.x release. This closes RUSTSEC-2026-0258, which allows unbounded empty DATA frames to cause memory exhaustion or a panic, and includes follow-up fixes that avoid rejecting legitimate small-frame traffic.
Only the locked version and checksum change; the dependency graph and application sources are unchanged.
Test: cargo check --locked -p bitfun-core; cargo tree --locked -i h2 --depth 1
AI: lightly tested1 parent 3adf7be commit e07bfac
1 file changed
Lines changed: 2 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments