Skip to content

Bump rustls-platform-verifier from 0.7.0 to 0.7.1 - #380

Merged
djc merged 1 commit into
mainfrom
dependabot/cargo/rustls-platform-verifier-0.7.1
Sep 28, 2026
Merged

djc merged 1 commit into
mainfrom
dependabot/cargo/rustls-platform-verifier-0.7.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps rustls-platform-verifier from 0.7.0 to 0.7.1.

Release notes

Sourced from rustls-platform-verifier's releases.

0.7.1

About

This version contains Windows and Android bugfixes, but its headline feature is a migration to an improved distribution strategy for the Android component of the crate, which must be included by Gradle for Android application/library builds. If you don't build for Android, no need to worry these changes don't affect you. But if you do, please continue reading to understand the required migration steps and benefits. 0.7.1 requires the Android migration to be performed once manually.

Android Revocation

The biggest improvement to functionality in this release is proper support for revocation on Android. As OCSP moves to deprecation, more CAs are exclusively using CRLs to distribute revocation data. Previously this failed to work on Android without workarounds since by default the network fetches for this were blocked. As of 0.2.0 of rustls-platform-verifier-android, this works again as expected. We now bundle an Android App manifest with the library, which Android Studio merges into the main manifest of the app being built.

Android Distribution

As of this release, we have stopped bundling pre-compiled .aar artifacts and a local Maven repository inside each release of rustls-platform-verifier-android. Instead, all future (and past!) Maven artifacts are now hosted on GitHub under the maven-archive branch. The branch's structure creates a remote Maven repository that Gradle can download and synchronize with just like any other. Importantly, this now means that the Android library can be downloaded and resolved independently of cargo's own downloads.

0.2.0 of the Android component is exclusively distributed through this new mechanism, but the 0.1.0 and 0.1.1 releases were also backported to the new repository. This means that no matter what version of rustls-platform-verifier you are using, its possible to migrate your Gradle build configuration to the more modern approach. Once again we have included out-of-the-box Gradle and Kotlin script snippets to configure the repository. See our README guide for more info.

What's Changed

New Contributors

Full Changelog: rustls/rustls-platform-verifier@v/0.7.0...v/0.7.1

Commits
  • 252e251 Release 0.7.1
  • 18f5c53 Bump Maven release to 0.2.0
  • 2885f2f Bump android-release-support to 0.2.0
  • 0e76b93 Update Android documentation and release process for GitHub-published artifacts
  • c87abb8 Remove Cargo-bundled Maven repository to setup for GitHub-published artifacts
  • 7c3e664 Bundle generated CRL networkSecurityConfig into release manifest
  • f4d7c89 Update Android build tooling and associated versions
  • f48a4b9 Fix groupId in POM template
  • 027c029 Update Android network security config
  • a8aa23d Take semver-compatible dependency updates
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [rustls-platform-verifier](https://github.com/rustls/rustls-platform-verifier) from 0.7.0 to 0.7.1.
- [Release notes](https://github.com/rustls/rustls-platform-verifier/releases)
- [Changelog](https://github.com/rustls/rustls-platform-verifier/blob/main/CHANGELOG)
- [Commits](rustls/rustls-platform-verifier@v/0.7.0...v/0.7.1)

---
updated-dependencies:
- dependency-name: rustls-platform-verifier
  dependency-version: 0.7.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update Rust code labels Sep 28, 2026
@djc
djc added this pull request to the merge queue Sep 28, 2026
Merged via the queue into main with commit b195fa8 Sep 28, 2026
11 checks passed
@djc
djc deleted the dependabot/cargo/rustls-platform-verifier-0.7.1 branch September 28, 2026 20:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update Rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant