Skip to content

bump openssl 0.10.78 -> 0.10.79 in Cargo.lock#184

Merged
dblodgett-usgs merged 1 commit into
mainfrom
openssl-bump-0.10.79
May 7, 2026
Merged

bump openssl 0.10.78 -> 0.10.79 in Cargo.lock#184
dblodgett-usgs merged 1 commit into
mainfrom
openssl-bump-0.10.79

Conversation

@dblodgett-usgs
Copy link
Copy Markdown
Collaborator

@dblodgett-usgs dblodgett-usgs commented May 7, 2026

Summary

  • Bumps openssl 0.10.78 -> 0.10.79 (transitive via reqwest -> native-tls)
  • Closes Dependabot alert HTTPStore class #7: undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs (high severity)

Test plan

  • CI builds Rust crate on r-universe

Closes GHSA dependabot alert #7: undefined behavior in
X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs.
Transitive via reqwest -> native-tls.
@dblodgett-usgs dblodgett-usgs merged commit 3c8963a into main May 7, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant