0.8.1

spider-rs/spider0.8.1Jun 4, 2026by andrewhavck

AI Summary

Addresses security vulnerabilities in HTTP/2 server limits and Rustls dependencies, and updates miscellaneous tasks like dependency pinning and MSRV verification.

Key Highlights

  • Security: Bound default HTTP/2 server limits to mitigate memory exhaustion
  • Security: Upgraded Rustls-related dev-dependencies
  • Misc: Pin tracing dependencies for Rust 1.84 compatibility
  • Misc: Use cargo check for MSRV verification

Full Release Notes

## [0.8.1](https://github.com/cloudflare/pingora/compare/0.8.0...0.8.1) - 2026-06-04


**🔒 Security**

* Bound default HTTP/2 server limits to mitigate memory exhaustion.
* Upgrade Rustls-related dev-dependencies to address `rustls-webpki` security advisories.

**⚙️ Miscellaneous Tasks**

* Pin tracing dependencies to preserve Rust 1.84 compatibility.
* Use `cargo check` for MSRV verification instead of compiling dev-dependencies during tests.
* Update the Semgrep OSS scanning workflow.
* Use valid paths in header serialization tests.
* Gate HTTP/1 CONNECT tests on patched HTTP/1 support.