fix: trust the system CA store for SMTP TLS (#11328)

* fix: trust the system CA store for SMTP TLS

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* ci: run the smtp-gated backend tests

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: depend on webpki-roots 1 directly

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: update ee-repo-ref to 48193da8cb30bc4ae82a50f944caef85d8a20b48

This commit updates the EE repository reference after PR #826 was merged in windmill-ee-private.

Previous ee-repo-ref: cd3447143b25d9f3301975feca4b202755f2508f

New ee-repo-ref: 48193da8cb30bc4ae82a50f944caef85d8a20b48

Automated by sync-ee-ref workflow.

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
This commit is contained in:
Alexander Petric
2026-09-24 15:10:28 +02:00
committed by GitHub
co-authored by Claude Opus 5.5 windmill-internal-app[bot]
parent 8525206361
commit 9375c93fd8
5 changed files with 14 additions and 3 deletions
+1 -1
View File
@@ -295,4 +295,4 @@ jobs:
# never reaches it. Pin the target dir (matching the cache step above) so
# its own tests run off this compile rather than a second bundled build.
(cd windmill-duckdb-ffi-internal && export CARGO_TARGET_DIR="$PWD/target" && ./build_dev.sh && cargo test --release -p windmill_duckdb_ffi_internal)
DENO_PATH=$(which deno) BUN_PATH=$(which bun) NODE_BIN_PATH=$(which node) GO_PATH=$(which go) UV_PATH=$(which uv) PHP_PATH=$(which php) COMPOSER_PATH=$(which composer) RUBY_PATH=$(which ruby) RUBY_BUNDLE_PATH=$(which bundle) RUBY_GEM_PATH=$(which gem) POWERSHELL_PATH=$(which pwsh) DOTNET_PATH=$(which dotnet) cargo test --features enterprise,deno_core,duckdb,license,python,rust,scoped_cache,parquet,private,private_registry_test,csharp,php,ruby,mysql,quickjs,mcp,run_inline --all -- --nocapture --test-threads=10
DENO_PATH=$(which deno) BUN_PATH=$(which bun) NODE_BIN_PATH=$(which node) GO_PATH=$(which go) UV_PATH=$(which uv) PHP_PATH=$(which php) COMPOSER_PATH=$(which composer) RUBY_PATH=$(which ruby) RUBY_BUNDLE_PATH=$(which bundle) RUBY_GEM_PATH=$(which gem) POWERSHELL_PATH=$(which pwsh) DOTNET_PATH=$(which dotnet) cargo test --features enterprise,deno_core,duckdb,license,python,rust,scoped_cache,parquet,private,private_registry_test,csharp,php,ruby,mysql,quickjs,mcp,run_inline,smtp --all -- --nocapture --test-threads=10
+5
View File
@@ -15658,11 +15658,14 @@ dependencies = [
"prometheus",
"quick_cache",
"rand 0.9.5",
"rcgen",
"regex",
"reqwest 0.13.5",
"reqwest-middleware",
"reqwest-retry",
"rsa",
"rustls 0.23.35",
"rustls-native-certs 0.8.4",
"schemars 0.8.22",
"semver 1.0.28",
"serde",
@@ -15683,6 +15686,7 @@ dependencies = [
"tikv-jemalloc-ctl",
"tokio",
"tokio-postgres",
"tokio-rustls 0.26.5",
"tokio-stream",
"tokio-util",
"tonic 0.13.1",
@@ -15693,6 +15697,7 @@ dependencies = [
"url",
"urlencoding",
"uuid",
"webpki-roots 1.0.9",
"windmill-macros",
"windmill-parser",
"windmill-parser-py",
+1
View File
@@ -757,4 +757,5 @@ hyper-http-proxy = { version = "1", default-features = false, features = ["rustl
hyper-rustls = { version = "0.27", default-features = false, features = ["http1", "http2", "ring", "tls12"] }
tokio-rustls = { version = "0.26", default-features = false, features = ["ring", "tls12"] }
rustls-native-certs = "0.8"
webpki-roots = "1"
rcgen = "0.13"
+1 -1
View File
@@ -1 +1 @@
ed5a367b4def5280c3a5e1090e7abfa099a01042
48193da8cb30bc4ae82a50f944caef85d8a20b48
+6 -1
View File
@@ -18,7 +18,7 @@ parquet = []
aws_auth = ["dep:aws-sdk-sts", "dep:aws-config"]
otel = ["dep:opentelemetry-semantic-conventions", "dep:opentelemetry-otlp", "dep:opentelemetry_sdk",
"dep:tracing-opentelemetry", "dep:opentelemetry-appender-tracing", "dep:tonic", "dep:opentelemetry"]
smtp = ["dep:mail-send"]
smtp = ["dep:mail-send", "dep:rustls", "dep:tokio-rustls", "dep:rustls-native-certs", "dep:webpki-roots"]
scoped_cache = []
cloud = []
dev_override = []
@@ -85,6 +85,10 @@ aws-sdk-rds = { workspace = true, optional = true }
indexmap.workspace = true
bytes.workspace = true
mail-send = { workspace = true, optional = true }
rustls = { workspace = true, optional = true }
tokio-rustls = { workspace = true, optional = true }
rustls-native-certs = { workspace = true, optional = true }
webpki-roots = { workspace = true, optional = true }
futures-core.workspace = true
async-stream.workspace = true
const_format.workspace = true
@@ -136,6 +140,7 @@ equivalent = "1.0.2"
[dev-dependencies]
# `test-util` is not part of tokio's `full`; it is what lets tests pause the clock.
tokio = { workspace = true, features = ["test-util"] }
rcgen.workspace = true
[target.'cfg(not(target_env = "msvc"))'.dependencies]
tikv-jemalloc-ctl = { optional = true, workspace = true }