0.8.1

bigcapitalhq/bigcapital0.8.1Jun 4, 2026by andrewhavck

AI Summary

Security and dependency updates for Pingora HTTP server. Addresses memory exhaustion vulnerabilities and updates Rustls-related dependencies.

Key Highlights

  • Bound default HTTP/2 server limits to mitigate memory exhaustion
  • Rustls-related dev-dependencies updated for security advisories
  • Pinned tracing dependencies for Rust 1.84 compatibility

New Features

  • HTTP/2 memory exhaustion mitigation
  • Security updates for Rustls dependencies
  • Enhanced test infrastructure with cargo check

Full Release Notes

## [0.8.1](https://github.com/cloudflare/pingora/compare/0.8.0...0.8.1) - 2026-06-04


**🔒 Security**

* Bound default HTTP/2 server limits to mitigate memory exhaustion.
* Upgrade Rustls-related dev-dependencies to address `rustls-webpki` security advisories.

**⚙️ Miscellaneous Tasks**

* Pin tracing dependencies to preserve Rust 1.84 compatibility.
* Use `cargo check` for MSRV verification instead of compiling dev-dependencies during tests.
* Update the Semgrep OSS scanning workflow.
* Use valid paths in header serialization tests.
* Gate HTTP/1 CONNECT tests on patched HTTP/1 support.