Skip to content

Bump openssl from 0.10.78 to 0.10.80#230

Merged
lfarrel6 merged 1 commit into
mainfrom
dependabot/cargo/openssl-0.10.80
Jun 15, 2026
Merged

Bump openssl from 0.10.78 to 0.10.80#230
lfarrel6 merged 1 commit into
mainfrom
dependabot/cargo/openssl-0.10.80

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 28, 2026

Copy link
Copy Markdown
Contributor

Bumps openssl from 0.10.78 to 0.10.80.

Release notes

Sourced from openssl's releases.

openssl-v0.10.80

What's Changed

Full Changelog: rust-openssl/rust-openssl@openssl-v0.10.79...openssl-v0.10.80

openssl-v0.10.79

What's Changed

Full Changelog: rust-openssl/rust-openssl@openssl-v0.10.78...openssl-v0.10.79

Commits
  • 35be7ae Release openssl 0.10.80 and openssl-sys 0.9.116 (#2639)
  • 19eceb2 Fix output buffer overflow in cipher_update_inplace for AES key-wrap-with-pad...
  • b460eb3 Prefer Homebrew openssl@4 and stop looking for openssl@1.1 (#2633)
  • 649f2d9 Release openssl 0.10.79 and openssl-sys 0.9.115 (#2632)
  • 257f9b2 Fix output buffer overflow for AES key-wrap-with-padding ciphers (#2630)
  • d43e917 Reject non-UTF-8 OCSP responder URLs in X509Ref::ocsp_responders (#2631)
  • f46519c Add PkeyCtxRef::set_context_string for ML-DSA (#2629)
  • ad9ae31 Bind OSSL_PARAM_modified and use it for seed_into (#2628)
  • 4e25c9b Fix process abort when verify/PSK callbacks fire after SSL_CTX swap (#2624)
  • 3dd8f42 Add PKeyRef::seed_into for ML-DSA/ML-KEM seed extraction (#2626)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update Rust code labels May 28, 2026
Bumps [openssl](https://github.com/rust-openssl/rust-openssl) from 0.10.78 to 0.10.80.
- [Release notes](https://github.com/rust-openssl/rust-openssl/releases)
- [Commits](rust-openssl/rust-openssl@openssl-v0.10.78...openssl-v0.10.80)

---
updated-dependencies:
- dependency-name: openssl
  dependency-version: 0.10.80
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump openssl from 0.10.72 to 0.10.80 Bump openssl from 0.10.78 to 0.10.80 May 29, 2026
@dependabot dependabot Bot force-pushed the dependabot/cargo/openssl-0.10.80 branch from 3f9527d to a53ac4b Compare May 29, 2026 18:40
@lfarrel6 lfarrel6 merged commit d806a71 into main Jun 15, 2026
2 checks passed
@lfarrel6 lfarrel6 deleted the dependabot/cargo/openssl-0.10.80 branch June 15, 2026 20:39
@evervault-dependencies

Copy link
Copy Markdown
Contributor

This vulnerability has been resolved through the standard development process and is no longer reported by Vanta. Closing this PR automatically.

1 similar comment
@evervault-dependencies

Copy link
Copy Markdown
Contributor

This vulnerability has been resolved through the standard development process and is no longer reported by Vanta. Closing this PR automatically.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update Rust code

Development

Successfully merging this pull request may close these issues.

2 participants