Skip to content

Bump openssl from 0.10.72 to 0.10.78#1421

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/cargo/openssl-0.10.78
Open

Bump openssl from 0.10.72 to 0.10.78#1421
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/cargo/openssl-0.10.78

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 23, 2026

Bumps openssl from 0.10.72 to 0.10.78.

Release notes

Sourced from openssl's releases.

openssl-v0.10.78

What's Changed

Full Changelog: rust-openssl/rust-openssl@openssl-v0.10.77...openssl-v0.10.78

openssl-v0.10.77

What's Changed

New Contributors

Full Changelog: rust-openssl/rust-openssl@openssl-v0.10.76...openssl-v0.10.77

openssl-v0.10.76

What's Changed

... (truncated)

Commits
  • a6debf5 Release openssl v0.10.78 and openssl-sys v0.9.114 (#2609)
  • 09b425e Check derive output buffer length on OpenSSL 1.1.x (#2606)
  • 826c388 Error for short out in MdCtxRef::digest_final() (#2608)
  • 1d10902 Validate callback-returned lengths in PSK and cookie trampolines (#2607)
  • 5af6895 Reject oversized length returns from password callback trampoline (#2605)
  • 718d07f fix inverted bounds assertion in AES key unwrap (#2604)
  • 53cc69d Add support for LibreSSL 4.3.x (#2603)
  • 0b41e79 Fix dangling stack pointer in custom extension add callback (#2599)
  • cbdedf8 Avoid panic for overlong OIDs (#2598)
  • 1fc51ef openssl 4 support (#2591)
  • Additional commits viewable in compare view


Note

Medium Risk
Updates the openssl/openssl-sys crates used for cryptographic operations; while change is limited to dependency versions, it can affect TLS/crypto behavior and native linking across platforms.

Overview
Bumps the workspace openssl dependency to 0.10.78 and updates the lockfile accordingly (including openssl-sys to 0.9.114).

No application code changes; this is a dependency refresh that pulls in upstream OpenSSL binding fixes and compatibility updates.

Reviewed by Cursor Bugbot for commit a42fc5e. Bugbot is set up for automated code reviews on this repo. Configure here.

@dependabot dependabot Bot added Changed Required label for PR that categorizes merge commit message as "Changed" for changelog dependencies Pull requests that update a dependency file rust Pull requests that update Rust code labels Apr 23, 2026
@socket-security
Copy link
Copy Markdown

socket-security Bot commented Apr 23, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedcargo/​openssl@​0.10.72 ⏵ 0.10.7880100 +4093100100

View full report

@coveralls-official
Copy link
Copy Markdown

coveralls-official Bot commented Apr 23, 2026

Coverage Report for CI Build 25210151577

Coverage remained the same at 80.674%

Details

  • Coverage remained the same as the base build.
  • Patch coverage: No coverable lines changed in this PR.
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 18374
Covered Lines: 14823
Line Coverage: 80.67%
Coverage Strength: 12264819.08 hits per line

💛 - Coveralls

@dependabot dependabot Bot force-pushed the dependabot/cargo/openssl-0.10.78 branch from 881d061 to d20846d Compare April 30, 2026 15:44
Bumps [openssl](https://github.com/rust-openssl/rust-openssl) from 0.10.72 to 0.10.78.
- [Release notes](https://github.com/rust-openssl/rust-openssl/releases)
- [Commits](rust-openssl/rust-openssl@openssl-v0.10.72...openssl-v0.10.78)

---
updated-dependencies:
- dependency-name: openssl
  dependency-version: 0.10.78
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/cargo/openssl-0.10.78 branch from d20846d to a42fc5e Compare May 1, 2026 09:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Changed Required label for PR that categorizes merge commit message as "Changed" for changelog dependencies Pull requests that update a dependency file rust Pull requests that update Rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants