From d1f9d1ac953568b9bfa5c90932c923c45cd4a09f Mon Sep 17 00:00:00 2001 From: Mikhail Zabaluev Date: Thu, 28 Sep 2023 21:51:25 +0300 Subject: [PATCH] Changelog entries for #1362 --- .../unreleased/breaking-changes/1362-rpc-by-reqwest.md | 10 ++++++++++ .changelog/unreleased/security/1342-rpc-by-reqwest.md | 3 +++ 2 files changed, 13 insertions(+) create mode 100644 .changelog/unreleased/breaking-changes/1362-rpc-by-reqwest.md create mode 100644 .changelog/unreleased/security/1342-rpc-by-reqwest.md diff --git a/.changelog/unreleased/breaking-changes/1362-rpc-by-reqwest.md b/.changelog/unreleased/breaking-changes/1362-rpc-by-reqwest.md new file mode 100644 index 000000000..f9920f46b --- /dev/null +++ b/.changelog/unreleased/breaking-changes/1362-rpc-by-reqwest.md @@ -0,0 +1,10 @@ +- `[tendermint-rpc]` Changed `ErrorDetail` variants + ([\#1362](https://github.com/informalsystems/tendermint-rs/pull/1362)): + * Removed the `Hyper` and `InvalidUri` variants. + * The `Http` variant now has `Error` from `reqwest` as the source. + * Added the `InvalidProxy` variant. + * The `tungstenite` dependency exposed through its `Error` type in + WebSocket-related variants has been updated to version 0.20.x. +- `[tendermint-rpc]` Removed a `TryFrom` conversion for + `hyper::Uri` as hyper is no longer a direct dependency + ([\#1362](https://github.com/informalsystems/tendermint-rs/pull/1362)). diff --git a/.changelog/unreleased/security/1342-rpc-by-reqwest.md b/.changelog/unreleased/security/1342-rpc-by-reqwest.md new file mode 100644 index 000000000..9826cde33 --- /dev/null +++ b/.changelog/unreleased/security/1342-rpc-by-reqwest.md @@ -0,0 +1,3 @@ +- `[tendermint-rpc]` remove RUSTSEC-2023-0052 vulnerability by dropping + dependency on `hyper-proxy` and changing the HTTP client to use `reqwest` + ([\#1342](https://github.com/informalsystems/tendermint-rs/issues/1342)).