Skip to content

fix(deps): drop legacy hyper 0.14/h2 0.3 stack from aws-sdk-iotdataplane - #140

Merged
MathiasKoch merged 2 commits into
masterfrom
fix/drop-legacy-hyper-stack
Aug 20, 2026
Merged

MathiasKoch merged 2 commits into
masterfrom
fix/drop-legacy-hyper-stack

Conversation

@MathiasKoch

@MathiasKoch MathiasKoch commented Aug 20, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Declare aws-sdk-iotdataplane with default-features = false and explicit default-https-client + rt-tokio features.
  • The SDK's default rustls feature enables aws-smithy-runtime/tls-rustls, which pulls the legacy hyper 0.14 client and h2 0.3. h2 0.3.27 is flagged by RUSTSEC-2026-0258 and has no patched 0.3.x release, so downstream consumers running cargo-deny (factbird-edge-applications) fail as long as rustot enables it via feature unification.
  • default-https-client (hyper 1 based) is available since the declared minimum aws-sdk-iotdataplane 1.72.0, so no version floor change is needed. Verified cargo tree -e normal -i h2@0.3.27 --features shadows_multi now resolves to nothing and cargo check --features shadows_multi,mqtt_rumqttc passes.

The SDK crate's default `rustls` feature enables
aws-smithy-runtime/tls-rustls, which pulls the legacy hyper 0.14 client
and h2 0.3. h2 0.3.27 is flagged by RUSTSEC-2026-0258 with no patched
0.3.x release. Disabling default features and enabling
default-https-client (hyper 1) + rt-tokio removes the legacy stack for
downstream consumers.
@MathiasKoch
MathiasKoch force-pushed the fix/drop-legacy-hyper-stack branch from 7fdb042 to 79543cf Compare August 20, 2026 09:01
@MathiasKoch
MathiasKoch merged commit 4a7f3df into master Aug 20, 2026
5 checks passed
@MathiasKoch
MathiasKoch deleted the fix/drop-legacy-hyper-stack branch August 20, 2026 09:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant