Skip to content

Conversation

@ameba23
Copy link
Collaborator

@ameba23 ameba23 commented Dec 12, 2025

This bumps dcap-qvl to 0.3.10 as the version we were using had a vulnerability. See https://github.com/flashbots/attested-tls-proxy/security/dependabot/2

Worth noting, 0.3.5 introduced a feature which allows you to set a root of trust for PCK ceriticates, as well as trait implementations for encoding quotes. This means you can create mock quotes with (your own PCK root of trust), which is useful for testing verification logic and would help with #11

@ameba23 ameba23 marked this pull request as draft December 12, 2025 18:19
* main: (52 commits)
  Use helper fn for updating http headers
  Set x-forwarded-for header
  Set host only in the header - dont touch the URI
  Dont set host in header as well as URI
  Add additional logging to debug issue with URI setting
  Fix URI in request headers to match target service
  Azure attestation tdx-quote must be based on td_report with input data
  Accept hostnames as target server for proxy server
  Normalize non-PKCS8 private keys
  Rm unneeded configuration in Makefile build environment following review
  Run on a github runner rather than WarpBuild
  Rm unwraps
  Improve Cargo.toml
  Improve doccomments
  Update following merging main
  Tidy, allow config to be passed in
  Gate behind feature flag
  Error handling
  Simple attested websocket server/client
  Force single test thread in CI
  ...
@ameba23 ameba23 marked this pull request as ready for review January 27, 2026 08:58
@ameba23 ameba23 merged commit 0a12763 into main Jan 27, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant