Skip to content

Upgrade bundled OpenSSL to 3.6.3#29487

Merged
jif-oai merged 2 commits into
mainfrom
jif/upgrade-openssl-3-6-3
Jun 22, 2026
Merged

Upgrade bundled OpenSSL to 3.6.3#29487
jif-oai merged 2 commits into
mainfrom
jif/upgrade-openssl-3-6-3

Conversation

@jif-oai

@jif-oai jif-oai commented Jun 22, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • upgrade the bundled OpenSSL source from 3.5.5 to 3.6.3
  • update the Bazel openssl-sys build dependency to use the upgraded source crate
  • refresh the Bazel module lockfile

Why

OpenSSL 3.5.5 is within the affected ranges for security issues fixed in later releases. The Rust openssl-src wrapper does not currently publish OpenSSL 3.5.7, so this moves the vendored Linux musl build to the available patched 3.6.3 release.

@jif-oai jif-oai merged commit 372b5ac into main Jun 22, 2026
45 checks passed
@jif-oai jif-oai deleted the jif/upgrade-openssl-3-6-3 branch June 22, 2026 22:19
@github-actions github-actions Bot locked and limited conversation to collaborators Jun 22, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant