Skip to content

Bump openssl from 0.10.72 to 0.10.78#769

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/cargo/openssl-0.10.78
Open

Bump openssl from 0.10.72 to 0.10.78#769
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/cargo/openssl-0.10.78

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 23, 2026

Bumps openssl from 0.10.72 to 0.10.78.

Release notes

Sourced from openssl's releases.

openssl-v0.10.78

What's Changed

Full Changelog: rust-openssl/rust-openssl@openssl-v0.10.77...openssl-v0.10.78

openssl-v0.10.77

What's Changed

New Contributors

Full Changelog: rust-openssl/rust-openssl@openssl-v0.10.76...openssl-v0.10.77

openssl-v0.10.76

What's Changed

... (truncated)

Commits
  • a6debf5 Release openssl v0.10.78 and openssl-sys v0.9.114 (#2609)
  • 09b425e Check derive output buffer length on OpenSSL 1.1.x (#2606)
  • 826c388 Error for short out in MdCtxRef::digest_final() (#2608)
  • 1d10902 Validate callback-returned lengths in PSK and cookie trampolines (#2607)
  • 5af6895 Reject oversized length returns from password callback trampoline (#2605)
  • 718d07f fix inverted bounds assertion in AES key unwrap (#2604)
  • 53cc69d Add support for LibreSSL 4.3.x (#2603)
  • 0b41e79 Fix dangling stack pointer in custom extension add callback (#2599)
  • cbdedf8 Avoid panic for overlong OIDs (#2598)
  • 1fc51ef openssl 4 support (#2591)
  • Additional commits viewable in compare view


Note

Medium Risk
Lockfile-only change, but it updates crypto/TLS bindings (openssl/openssl-sys), which can affect security behavior and native linking across platforms.

Overview
Updates the Rust openssl dependency in Cargo.lock from 0.10.72 to 0.10.78, along with the corresponding openssl-sys bump from 0.9.107 to 0.9.114 (checksum updates only).

Reviewed by Cursor Bugbot for commit 057866e. Bugbot is set up for automated code reviews on this repo. Configure here.

@dependabot dependabot Bot added Changed Required label for PR that categorizes merge commit message as "Changed" for changelog dependencies Pull requests that update a dependency file rust Pull requests that update Rust code labels Apr 23, 2026
@coveralls-official
Copy link
Copy Markdown

coveralls-official Bot commented Apr 23, 2026

Coverage Report for CI Build 24848502304

Coverage remained the same at 87.497%

Details

  • Coverage remained the same as the base build.
  • Patch coverage: No coverable lines changed in this PR.
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 8542
Covered Lines: 7474
Line Coverage: 87.5%
Coverage Strength: 30888543.99 hits per line

💛 - Coveralls

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 23, 2026

Dependabot couldn't access the repository. Because of this, Dependabot cannot update this pull request.

@dependabot dependabot Bot force-pushed the dependabot/cargo/openssl-0.10.78 branch from ca9abe5 to 4015bd5 Compare April 23, 2026 17:11
Bumps [openssl](https://github.com/rust-openssl/rust-openssl) from 0.10.72 to 0.10.78.
- [Release notes](https://github.com/rust-openssl/rust-openssl/releases)
- [Commits](rust-openssl/rust-openssl@openssl-v0.10.72...openssl-v0.10.78)

---
updated-dependencies:
- dependency-name: openssl
  dependency-version: 0.10.78
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/cargo/openssl-0.10.78 branch from 4015bd5 to 057866e Compare April 29, 2026 14:52
@emlowe
Copy link
Copy Markdown
Contributor

emlowe commented Apr 30, 2026

@dependabot rebase

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 30, 2026

Looks like this PR is already up-to-date with main! If you'd still like to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Changed Required label for PR that categorizes merge commit message as "Changed" for changelog dependencies Pull requests that update a dependency file rust Pull requests that update Rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant