fix(deps): update rust crate rusty_paseto to 0.10.0 #196

Open
darkkirb wants to merge 1 commit from renovate/rusty_paseto-0.x into main
Owner

This PR contains the following updates:

Package Type Update Change
rusty_paseto dependencies minor 0.7.2 → 0.10.0

⚠️ Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

rrrodzilla/rusty_paseto (rusty_paseto)

v0.10.0

Compare Source

This release is a focused security pass driven by a full internal audit of the
crate against the PASETO specification and current advisory database.

Security
  • Ed25519 verification is now strict (RFC 8032). Paseto::<V2, Public> and
    Paseto::<V4, Public> now call ed25519_dalek::VerifyingKey::verify_strict
    instead of the lenient verify. The strict path rejects signatures with
    torsion components and non-canonical R encodings, eliminating ed25519
    signature malleability. All 56 default tests and the official PASETO v2/v4
    public test vectors continue to pass.
  • Default parser now rejects tokens missing the exp claim. A second-look
    audit highlighted an asymmetry: the builder required an explicit
    set_no_expiration_danger_acknowledged() to mint non-expiring tokens, but
    the parser silently accepted them. The parser is now symmetric — an absent,
    null, or non-string exp returns PasetoClaimError::Missing("exp"). Use
    the new PasetoParser::set_no_expiration_danger_acknowledged() to opt in
    when you genuinely want to accept non-expiring tokens.
  • Token and footer size limits. New constants Paseto::MAX_TOKEN_SIZE
    (64 KiB) and Paseto::MAX_FOOTER_SIZE (1024 bytes, per PASETO spec
    recommendation) are enforced in both parse_raw_token and
    UntrustedToken::try_parse before any base64 decoding or PAE construction.
    Bounds the work an attacker can force on inputs that would have failed MAC
    verification. New error variants Error::TokenTooLarge and
    Error::FooterTooLarge.
  • Derived encryption and authentication keys now zeroize on drop.
    EncryptionKey, AuthenticationKey, and HkdfKey derive
    Zeroize + ZeroizeOnDrop. The root PasetoSymmetricKey (Key<N>) was
    already zeroized; this closes the gap for per-message Ek/Ak material derived
    via HKDF (v1/v3) and BLAKE2b (v4).
  • Eliminated two public-API panic-on-bad-input paths.
    Key::<N>::from(&[u8]) and PasetoAsymmetricPrivateKey::<V2|V4, Public>::from(&[u8])
    previously called copy_from_slice into fixed-size buffers, panicking the
    thread on size mismatch. Both now use TryFrom<&[u8]> returning
    PasetoError::InvalidKey. The infallible array-typed From impls remain
    for callers that already have a correctly-sized array.
Dependencies
  • time 0.3 → 0.3.47 to resolve RUSTSEC-2026-0009 (DoS via stack
    exhaustion in claim parsing).
  • zeroize 1.4 → 1.8 for current derive macros and bug fixes.
Fixed
  • nbf claim boundary. A token with nbf == now is now accepted, per
    RFC 7519 §4.1.5. Previously the strict <= check rejected tokens for one
    instant at the boundary.
Breaking changes
  • PasetoParser::default() now rejects tokens missing exp by default;
    callers that want non-expiring tokens must add
    .set_no_expiration_danger_acknowledged() on the parser (mirroring the
    existing builder method).
  • Key::<N>::from(&[u8]) removed. Callers using Key::<N>::from(slice)
    with a slice (rather than an array) must switch to
    Key::<N>::try_from(slice)?. The array-typed From<[u8; N]> and
    From<&[u8; N]> impls are unchanged.
  • PasetoAsymmetricPrivateKey::<V2|V4, Public>::from(&[u8]) is now
    TryFrom<&[u8]>. Callers using from(slice) must switch to
    try_from(slice)?. V1 (RSA, arbitrary-length) and V3 (Key<48>-typed)
    are unaffected.
Spec compliance
  • PAE le64 now masks the high bit (n &= 0x7FFF_FFFF_FFFF_FFFF) for
    byte-exact compatibility with the reference implementation. In Rust this is
    structurally redundant — slice/Vec lengths are bounded by isize::MAX — but
    the masking matches the spec pseudocode.
Documentation
  • Corrected v1_public_insecure rationale. Previous docs cited
    RUSTSEC-2023-0071 (Marvin Attack), which targets the rsa crate. This crate
    uses ring's RSA-PSS, which is constant-time blinded and not affected by
    that advisory. The _insecure suffix and #[deprecated] attributes remain
    — V1 is the legacy PASETO version (2048-bit RSA-PSS-SHA384) and the spec
    recommends V4 — but the justification now reflects reality.
  • SECURITY.md rewritten with private disclosure channels (GitHub
    Security Advisory plus rrrodzilla@proton.me), supported-versions table,
    SLA expectations, and hardening guidance for users.
  • actix_identity example hardened. Replaced hardcoded keys with env
    vars (PASETO_KEY, COOKIE_KEY as 32-byte hex; random fallback per
    process start), removed .expect()/.unwrap() from request handlers,
    and added a leading module doc explaining what to fix before adapting it
    to production.
Meta
  • MSRV declared as 1.85, the minimum supported by the dependency tree
    (transitive time-core 0.1.8 requires edition2024).
Notes
  • cargo audit against the library's runtime dependency tree is clean.
    Two rand warnings (RUSTSEC-2026-0097, "unsound with a custom logger")
    remain in the dev-dependency tree, reachable only through proptest
    and the actix-web-based actix_identity example. They do not affect
    consumers of rusty_paseto itself.

v0.9.0

Compare Source

See CHANGELOG for details.

v0.8.0

Compare Source

Added
  • Automated release creation on version tags (#​72)
  • Untrusted footer parsing for key rotation (#​67)
  • Compile-time checks for incompatible feature combinations (#​56)
Changed
  • Update dependencies to latest versions (#​57)
    • Update primes dev dependency to 0.4
    • Update thiserror to 2.0
    • Update rand_core from 0.6 to 0.9
    • Update aes dependency from 0.7 to 0.8 (#​55)
Fixed
  • Remove unnecessary ed25519-dalek dependency in v1_public (#​71)
  • Relax lifetime bound in PasetoParser::check_claim (#​68)
  • Resolve clippy lints and update dependencies (#​65)
Refactored
  • Simplify wrap_value by removing redundant empty map check (#​66)
Documentation
  • Clarify expiration validation behavior in PasetoParser (#​69)
CI/CD
  • Improve test execution and lint coverage (#​64)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [rusty_paseto](https://github.com/rrrodzilla/rusty_paseto) | dependencies | minor | `0.7.2` → `0.10.0` | --- > ⚠️ **Warning** > > Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/2) for more information. --- ### Release Notes <details> <summary>rrrodzilla/rusty_paseto (rusty_paseto)</summary> ### [`v0.10.0`](https://github.com/rrrodzilla/rusty_paseto/blob/HEAD/CHANGELOG.md#0100---2026-05-10) [Compare Source](https://github.com/rrrodzilla/rusty_paseto/compare/v0.9.0...v0.10.0) This release is a focused security pass driven by a full internal audit of the crate against the PASETO specification and current advisory database. ##### Security - **[`Ed25519`](https://github.com/rrrodzilla/rusty_paseto/commit/Ed25519) verification is now strict (RFC 8032).** `Paseto::<V2, Public>` and `Paseto::<V4, Public>` now call `ed25519_dalek::VerifyingKey::verify_strict` instead of the lenient `verify`. The strict path rejects signatures with torsion components and non-canonical R encodings, eliminating [`ed25519`](https://github.com/rrrodzilla/rusty_paseto/commit/ed25519) signature malleability. All 56 default tests and the official PASETO v2/v4 public test vectors continue to pass. - **Default parser now rejects tokens missing the `exp` claim.** A second-look audit highlighted an asymmetry: the builder required an explicit `set_no_expiration_danger_acknowledged()` to mint non-expiring tokens, but the parser silently accepted them. The parser is now symmetric — an absent, null, or non-string `exp` returns `PasetoClaimError::Missing("exp")`. Use the new `PasetoParser::set_no_expiration_danger_acknowledged()` to opt in when you genuinely want to accept non-expiring tokens. - **Token and footer size limits.** New constants `Paseto::MAX_TOKEN_SIZE` (64 KiB) and `Paseto::MAX_FOOTER_SIZE` (1024 bytes, per PASETO spec recommendation) are enforced in both `parse_raw_token` and `UntrustedToken::try_parse` before any base64 decoding or PAE construction. Bounds the work an attacker can force on inputs that would have failed MAC verification. New error variants `Error::TokenTooLarge` and `Error::FooterTooLarge`. - **Derived encryption and authentication keys now zeroize on drop.** `EncryptionKey`, `AuthenticationKey`, and `HkdfKey` derive `Zeroize` + `ZeroizeOnDrop`. The root `PasetoSymmetricKey` (`Key<N>`) was already zeroized; this closes the gap for per-message Ek/Ak material derived via HKDF (v1/v3) and BLAKE2b (v4). - **Eliminated two public-API panic-on-bad-input paths.** `Key::<N>::from(&[u8])` and `PasetoAsymmetricPrivateKey::<V2|V4, Public>::from(&[u8])` previously called `copy_from_slice` into fixed-size buffers, panicking the thread on size mismatch. Both now use `TryFrom<&[u8]>` returning `PasetoError::InvalidKey`. The infallible array-typed `From` impls remain for callers that already have a correctly-sized array. ##### Dependencies - **`time` 0.3 → 0.3.47** to resolve RUSTSEC-2026-0009 (DoS via stack exhaustion in claim parsing). - **`zeroize` 1.4 → 1.8** for current derive macros and bug fixes. ##### Fixed - **`nbf` claim boundary.** A token with `nbf == now` is now accepted, per RFC 7519 §4.1.5. Previously the strict `<=` check rejected tokens for one instant at the boundary. ##### Breaking changes - `PasetoParser::default()` now rejects tokens missing `exp` by default; callers that want non-expiring tokens must add `.set_no_expiration_danger_acknowledged()` on the parser (mirroring the existing builder method). - `Key::<N>::from(&[u8])` removed. Callers using `Key::<N>::from(slice)` with a slice (rather than an array) must switch to `Key::<N>::try_from(slice)?`. The array-typed `From<[u8; N]>` and `From<&[u8; N]>` impls are unchanged. - `PasetoAsymmetricPrivateKey::<V2|V4, Public>::from(&[u8])` is now `TryFrom<&[u8]>`. Callers using `from(slice)` must switch to `try_from(slice)?`. V1 (RSA, arbitrary-length) and V3 (Key<48>-typed) are unaffected. ##### Spec compliance - **PAE `le64`** now masks the high bit (`n &= 0x7FFF_FFFF_FFFF_FFFF`) for byte-exact compatibility with the reference implementation. In Rust this is structurally redundant — slice/Vec lengths are bounded by `isize::MAX` — but the masking matches the spec pseudocode. ##### Documentation - **Corrected `v1_public_insecure` rationale.** Previous docs cited RUSTSEC-2023-0071 (Marvin Attack), which targets the `rsa` crate. This crate uses `ring`'s RSA-PSS, which is constant-time blinded and not affected by that advisory. The `_insecure` suffix and `#[deprecated]` attributes remain — V1 is the legacy PASETO version (2048-bit RSA-PSS-SHA384) and the spec recommends V4 — but the justification now reflects reality. - **`SECURITY.md`** rewritten with private disclosure channels (GitHub Security Advisory plus `rrrodzilla@proton.me`), supported-versions table, SLA expectations, and hardening guidance for users. - **`actix_identity` example hardened.** Replaced hardcoded keys with env vars (`PASETO_KEY`, `COOKIE_KEY` as 32-byte hex; random fallback per process start), removed `.expect()`/`.unwrap()` from request handlers, and added a leading module doc explaining what to fix before adapting it to production. ##### Meta - **MSRV declared as 1.85**, the minimum supported by the dependency tree (transitive `time-core 0.1.8` requires `edition2024`). ##### Notes - `cargo audit` against the library's runtime dependency tree is clean. Two `rand` warnings (`RUSTSEC-2026-0097`, "unsound with a custom logger") remain in the dev-dependency tree, reachable only through `proptest` and the actix-web-based `actix_identity` example. They do not affect consumers of `rusty_paseto` itself. ### [`v0.9.0`](https://github.com/rrrodzilla/rusty_paseto/releases/tag/v0.9.0) [Compare Source](https://github.com/rrrodzilla/rusty_paseto/compare/v0.8.0...v0.9.0) See [CHANGELOG](https://github.com/rrrodzilla/rusty_paseto/blob/main/CHANGELOG.md) for details. ### [`v0.8.0`](https://github.com/rrrodzilla/rusty_paseto/blob/HEAD/CHANGELOG.md#080---2025-10-05) [Compare Source](https://github.com/rrrodzilla/rusty_paseto/compare/v0.7.2...v0.8.0) ##### Added - Automated release creation on version tags ([#&#8203;72](https://github.com/rrrodzilla/rusty_paseto/issues/72)) - Untrusted footer parsing for key rotation ([#&#8203;67](https://github.com/rrrodzilla/rusty_paseto/issues/67)) - Compile-time checks for incompatible feature combinations ([#&#8203;56](https://github.com/rrrodzilla/rusty_paseto/issues/56)) ##### Changed - Update dependencies to latest versions ([#&#8203;57](https://github.com/rrrodzilla/rusty_paseto/issues/57)) - Update primes dev dependency to 0.4 - Update thiserror to 2.0 - Update rand\_core from 0.6 to 0.9 - Update aes dependency from 0.7 to 0.8 ([#&#8203;55](https://github.com/rrrodzilla/rusty_paseto/issues/55)) ##### Fixed - Remove unnecessary [`ed25519`](https://github.com/rrrodzilla/rusty_paseto/commit/ed25519)-dalek dependency in v1\_public ([#&#8203;71](https://github.com/rrrodzilla/rusty_paseto/issues/71)) - Relax lifetime bound in PasetoParser::check\_claim ([#&#8203;68](https://github.com/rrrodzilla/rusty_paseto/issues/68)) - Resolve clippy lints and update dependencies ([#&#8203;65](https://github.com/rrrodzilla/rusty_paseto/issues/65)) ##### Refactored - Simplify wrap\_value by removing redundant empty map check ([#&#8203;66](https://github.com/rrrodzilla/rusty_paseto/issues/66)) ##### Documentation - Clarify expiration validation behavior in PasetoParser ([#&#8203;69](https://github.com/rrrodzilla/rusty_paseto/issues/69)) ##### CI/CD - Improve test execution and lint coverage ([#&#8203;64](https://github.com/rrrodzilla/rusty_paseto/issues/64)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS44MS4wIiwidXBkYXRlZEluVmVyIjoiNDQuMTMuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
darkkirb scheduled this pull request to auto merge when all checks succeed 2025-10-06 03:14:42 +00:00
Author
Owner

⚠️ Artifact update problem

Renovate failed to update artifacts related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: Cargo.lock
Command failed: cargo update --config net.git-fetch-with-cli=true --manifest-path crates/chir-rs/Cargo.toml --workspace
    Updating crates.io index
    Updating `chir-rs` index
error: no matching package named `chir-rs-utils` found
location searched: `chir-rs` index
required by package `chir-rs v0.1.0 (/var/lib/private/renovate/repos/gitea/darkkirb/chir.rs/crates/chir-rs)`

File name: crates/chir-rs/Cargo.toml
Post-upgrade command 'cargo2nix -o' has not been added to the allowed list in allowedCommands
File name: crates/chir-rs/Cargo.toml
Post-upgrade command '(cd web; yarn2nix > yarn.nix)' has not been added to the allowed list in allowedCommands
File name: crates/chir-rs/Cargo.toml
Command failed: treefmt
ERRO formatter | nix: failed to apply with options '[]': exit status 1

yarn.nix:1:1:
  |
1 | <empty line>
  | ^
unexpected end of input
expecting expression


traversed 121 files
emitted 50 files for processing
formatted 0 files (0 changed) in 875ms
Error: failed to finalise formatting: formatting failures detected

### ⚠️ Artifact update problem Renovate failed to update artifacts related to this branch. You probably do not want to merge this PR as-is. ♻ Renovate will retry this branch, including artifacts, only when one of the following happens: - any of the package files in this branch needs updating, or - the branch becomes conflicted, or - you click the rebase/retry checkbox if found above, or - you rename this PR's title to start with "rebase!" to trigger it manually The artifact failure details are included below: ##### File name: Cargo.lock ``` Command failed: cargo update --config net.git-fetch-with-cli=true --manifest-path crates/chir-rs/Cargo.toml --workspace Updating crates.io index Updating `chir-rs` index error: no matching package named `chir-rs-utils` found location searched: `chir-rs` index required by package `chir-rs v0.1.0 (/var/lib/private/renovate/repos/gitea/darkkirb/chir.rs/crates/chir-rs)` ``` ##### File name: crates/chir-rs/Cargo.toml ``` Post-upgrade command 'cargo2nix -o' has not been added to the allowed list in allowedCommands ``` ##### File name: crates/chir-rs/Cargo.toml ``` Post-upgrade command '(cd web; yarn2nix > yarn.nix)' has not been added to the allowed list in allowedCommands ``` ##### File name: crates/chir-rs/Cargo.toml ``` Command failed: treefmt ERRO formatter | nix: failed to apply with options '[]': exit status 1 yarn.nix:1:1: | 1 | <empty line> | ^ unexpected end of input expecting expression traversed 121 files emitted 50 files for processing formatted 0 files (0 changed) in 875ms Error: failed to finalise formatting: formatting failures detected ```
darkkirb force-pushed renovate/rusty_paseto-0.x from 51a7ff1862
Some checks failed
renovate/artifacts Artifact file update failure
to 2f2b776981
Some checks failed
renovate/artifacts Artifact file update failure
2025-12-09 13:00:53 +00:00
Compare
darkkirb changed title from fix(deps): update rust crate rusty_paseto to 0.8.0 to fix(deps): update rust crate rusty_paseto to 0.9.0 2025-12-09 13:00:54 +00:00
darkkirb force-pushed renovate/rusty_paseto-0.x from 2f2b776981
Some checks failed
renovate/artifacts Artifact file update failure
to 71fbda3f5f
Some checks failed
renovate/artifacts Artifact file update failure
2026-05-10 21:02:01 +00:00
Compare
darkkirb changed title from fix(deps): update rust crate rusty_paseto to 0.9.0 to fix(deps): update rust crate rusty_paseto to 0.10.0 2026-05-10 21:02:02 +00:00
Some checks are pending
renovate/artifacts Artifact file update failure
Hydra aarch64-linux.checks.chir-rs
Required
Hydra aarch64-linux.checks.chir-rs-client
Required
Hydra aarch64-linux.checks.chir-rs-common
Required
Hydra aarch64-linux.checks.chir-rs-fe
Required
Hydra aarch64-linux.packages.chir-rs
Required
Hydra aarch64-linux.packages.chir-rs-client
Required
Hydra aarch64-linux.packages.chir-rs-common
Required
Hydra aarch64-linux.packages.chir-rs-fe
Required
Hydra x86_64-linux.checks.chir-rs
Required
Hydra x86_64-linux.checks.chir-rs-client
Required
Hydra x86_64-linux.checks.chir-rs-common
Required
Hydra x86_64-linux.checks.chir-rs-fe
Required
Hydra x86_64-linux.packages.chir-rs
Required
Hydra x86_64-linux.packages.chir-rs-client
Required
Hydra x86_64-linux.packages.chir-rs-common
Required
Hydra x86_64-linux.packages.chir-rs-fe
Required
Some required checks are missing.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/rusty_paseto-0.x:renovate/rusty_paseto-0.x
git switch renovate/rusty_paseto-0.x
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
darkkirb/chir.rs!196
No description provided.