Skip to content

Bump c2pa from 0.88.0 to 0.91.1 - #414

Merged
puhley merged 2 commits into
mainfrom
dependabot/cargo/c2pa-0.91.1
Oct 4, 2026
Merged

puhley merged 2 commits into
mainfrom
dependabot/cargo/c2pa-0.91.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps c2pa from 0.88.0 to 0.91.1.

Changelog

Sourced from c2pa's changelog.

0.91.1

26 September 2026

Added

  • Implement pdf manifest writing (backport #2666) (#2700)

Fixed

  • Ignore unreferenced claims when reconciling validation statuses (backport #2686) (#2735)
  • Validate live OCSP responder certs at current time and complete claim verification on revocation (backport #2688) (#2724)
  • Skip only the real C2PA jumb box in JPEG XL box hashing (backport #2695) (#2723)
  • CAWG identity assertion mismatch reporting (backport #2713) (#2719)
  • Reject invalid RSA public exponents in certificate profiles (CAI-13156) (backport #2712) (#2718)
  • Bump id3 to 1.17.2 to cap decompressed ID3v2 frame size (backport #2699) (#2716)
  • Check values to avoid underflow in identity flows (backport #2697) (#2711)
  • Bound cumulative TIFF IFD entry byte counts to file size (backport #2669) (#2706)
  • Reject oversized XMP instead of panicking on JPEG APP1 write (backport #2687) (#2705)
  • Harden against integer underflow attacks in XMP trailer parsing (backport #2670) (#2704)

0.91.0

21 September 2026

Breaking changes

  • c2pa-raw-crypto split (#2231) — SigningAlg, RawSigner, RawSignerError, RawSignatureValidationError, and the built-in OpenSSL / rust_native_crypto implementations have moved out of c2pa::crypto::raw_signature (now removed) into the separate c2pa-raw-crypto crate. Continue importing these types from the crate root (c2pa::SigningAlg, etc.), which still re-exports them; code that referenced c2pa::crypto::raw_signature::* directly needs updated import paths, and code that needs lower-level access to the raw-signing primitives should depend on c2pa-raw-crypto directly.
  • verify_after_sign now defaults to true (#2277) — Settings::verify.verify_after_sign previously defaulted to false in release builds. Builder-created manifests are now re-verified immediately after signing by default, adding a small amount of work per sign in exchange for catching a malformed manifest before it leaves the process. If you relied on the old default, set verify_after_sign = false explicitly.
  • Trust-list settings restructured for multiple named trust lists (#2545) — the top-level cawg_trust settings section is gone. C2PA claim-generator, CAWG, and TSA trust configuration now live together under trust.anchors, an array of { trust_uri, trust_kind, trust_anchors, trust_config, allowed_list, trusted_ica_issuers } entries distinguished by trust_kind (e.g. "manifest"), replacing the old single trust.trust_anchors / trust.trust_config / trust.user_anchors / trust.allowed_list fields. A new soft_binding.soft_binding_algorithms setting was also added. If you configure trust via Settings JSON/TOML, update it to the new trust.anchors[] shape — see https://github.com/contentauth/c2pa-rs/blob/c2pa-v0.91.1/docs/context-settings.md for the current schema.
  • CAWG X.509 identity assertions use CAWG-specific status codes (#2516) — per CAWG identity assertion spec v1.3 §8.2.2, X.509 identity signature validation now emits cawg.x509.* status codes (e.g. cawg.x509.credential.trusted, cawg.x509.signature.mismatch, cawg.x509.signature.validated) instead of reusing the C2PA claim-signature codes (signingCredential.trusted, claimSignature.mismatch, etc.). Code that inspects ValidationResults or log items for the old codes on this path needs to check for the new cawg.x509.* codes instead.
  • CAWG ICA issuers must be explicitly trusted (#2209) — the new trusted_ica_issuers list (part of trust.anchors[], see above) defaults to empty, so no CAWG claims-aggregation issuer is trusted until you list it explicitly; a previously-accepted, unlisted issuer now fails with cawg.ica.untrusted_issuer. Also, CawgValidator is no longer a unit struct: replace &CawgValidator {} with CawgValidator::new(&context) or CawgValidator::default().
  • HTTP redirects to non-public hosts are rejected by default (#2433) — fetching a remote manifest, OCSP response, timestamp, or did:web document now validates every redirect hop, not just the initial request, and rejects a hop that resolves to a non-globally-routable address (loopback, RFC1918, link-local/cloud-metadata, etc.) with HttpResolverError::RedirectTargetDisallowed. If your deployment legitimately redirects through an internal host, set core.allow_redirects = false to disable redirect-following, or adjust core.allowed_network_hosts.
  • C2PA 2.4 validation rules (#2578) — validation of soft-binding and metadata assertions is relaxed, and Cloud Data / External Reference assertions are validated without fetching, per the C2PA 2.4 spec. This mostly loosens prior rejections; if your code or test fixtures depended on the stricter 2.3-era validation failing for these assertion types, re-check them.
  • SVG handler no longer accepts generic XML (#2311) — the SVG asset handler's generic XML fallback is gone. An XML-based format now needs its own specific handler per the C2PA spec's manifest-placement rules (see the new plain-text (#2494) and experimental structured-text (#2283) handlers added in this release); a document that previously round-tripped through the generic SVG/XML path may need a different asset handler.

[!NOTE] This release also carries roughly 70 #[deprecated] items accumulated on main since the last breaking-changes train. None of them are removed in 0.91.0, but per our deprecation policy, the next breaking-changes release — planned for mid-November 2026 — will delete every API still marked deprecated at that point. If your build emits deprecation warnings from c2pa, plan to migrate before that release ships.

Added

  • Implement remote signing for CAWG X.509 identity assertions (#2635)
  • Add native plain-text asset handler (A.8) (#2494)
  • Credential-holder identity signer in the C API (#2603)
  • Clean up asset_io, rename things, share common code, and add private registry through Context (#2491)
  • Add ZIP support (+ EPUB, Office Open XML, Open Document, and OpenXPS) and Collection Data Hash assertion (#499)
  • Add related assertions field and validation to c2pa.actions (#2446)
  • Add digital source type field to ingredient (#2447)
  • Add support for general boxes hash exclusions (#2513)
  • [breaking] Update for C2PA 2.3 spec (#2545)
  • (crjson) Implement isUpdateManifest and isCompressedManifest fields (#2185)
  • Add Error::AssertionEncoding error source to error message (#2544)

... (truncated)

Commits
  • b979441 chore: release v0.91.1 (#2703)
  • 3012d72 fix: Ignore unreferenced claims when reconciling validation statuses (backpor...
  • 99d867e fix: Validate live OCSP responder certs at current time and complete claim ve...
  • d8c72fd ci: Sequence release-plz publish and PR jobs (backport #2698) (#2707)
  • 1f9cba9 build: release-plz respects release_commits (fixes #2229) (backport #2658...
  • 41ddd7f fix: Skip only the real C2PA jumb box in JPEG XL box hashing (backport #2695)...
  • 27bf4e3 fix: CAWG identity assertion mismatch reporting (backport #2713) (#2719)
  • 0df0d95 fix: Reject invalid RSA public exponents in certificate profiles (CAI-13156) ...
  • bff02c5 fix: bump id3 to 1.17.2 to cap decompressed ID3v2 frame size (backport #2699)...
  • be15a42 fix: Check values to avoid underflow in identity flows (backport #2697) (#2711)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [c2pa](https://github.com/contentauth/c2pa-rs) from 0.88.0 to 0.91.1.
- [Release notes](https://github.com/contentauth/c2pa-rs/releases)
- [Changelog](https://github.com/contentauth/c2pa-rs/blob/c2pa-v0.91.1/CHANGELOG.md)
- [Commits](contentauth/c2pa-rs@c2pa-v0.88.0...c2pa-v0.91.1)

---
updated-dependencies:
- dependency-name: c2pa
  dependency-version: 0.91.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 1, 2026
@puhley
puhley merged commit b0914c6 into main Oct 4, 2026
8 of 9 checks passed
@puhley
puhley deleted the dependabot/cargo/c2pa-0.91.1 branch October 4, 2026 20:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant