The runner reaches the FerrFleet API over TLS through rustls, and version 1.0.0 locked rustls 0.23.43. That release is affected by RUSTSEC-2026-0285: rustls accepted TLS 1.3 handshake messages sent at the wrong encryption level when they followed a key change in the same record. The handshake transcript stays authenticated, so a network attacker could not tamper with or complete a handshake, but a peer could send in the clear what should have been encrypted without the connection being refused.

Runner 1.0.1 locks rustls 0.23.45, which fixes it. The action's inputs are unchanged, and the only other differences in the image are routine patch-level dependency bumps.

uses: FerrLabs/FerrFleet-Runner@v1 and the ghcr.io/ferrlabs/ferrfleet/runner:1 image both point at 1.0.1 already, so a workflow on the moving tag picks it up on its next run. If you pin the image by digest, as the action recommends, move to the 1.0.1 digest and check its signature:

cosign verify ghcr.io/ferrlabs/ferrfleet/runner@sha256:1e80b0f7e34c6e2a0e6babb42235eae58ba5e2605bbc1679d30aa93229fbe0b2 \
  --certificate-identity-regexp '^https://github.com/FerrLabs/FerrFleet-Runner/' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

The runner's CI now runs cargo deny on every pull request and requires it to pass, so a dependency with a known advisory can no longer merge without someone deciding to accept it.