0.8.1

cortezaproject/corteza0.8.1Jun 4, 2026by andrewhavck

AI Summary

This release addresses security vulnerabilities related to HTTP/2 server limits and Rustls dependencies, alongside maintenance improvements for Rust 1.84 compatibility and test verification processes.

Key Highlights

  • Bound default HTTP/2 server limits to mitigate memory exhaustion
  • Upgraded Rustls-related dev-dependencies to address security advisories
  • Pinned tracing dependencies to preserve Rust 1.84 compatibility
  • Switched to `cargo check` for MSRV verification to optimize testing

Full Release Notes

## [0.8.1](https://github.com/cloudflare/pingora/compare/0.8.0...0.8.1) - 2026-06-04


**🔒 Security**

* Bound default HTTP/2 server limits to mitigate memory exhaustion.
* Upgrade Rustls-related dev-dependencies to address `rustls-webpki` security advisories.

**⚙️ Miscellaneous Tasks**

* Pin tracing dependencies to preserve Rust 1.84 compatibility.
* Use `cargo check` for MSRV verification instead of compiling dev-dependencies during tests.
* Update the Semgrep OSS scanning workflow.
* Use valid paths in header serialization tests.
* Gate HTTP/1 CONNECT tests on patched HTTP/1 support.