Skip to content

Bump openssl from 0.10.72 to 0.10.78 - #769

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/openssl-0.10.78
Closed

Bump openssl from 0.10.72 to 0.10.78#769
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/openssl-0.10.78

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Apr 23, 2026

Copy link
Copy Markdown
Contributor

Bumps openssl from 0.10.72 to 0.10.78.

Release notes

Sourced from openssl's releases.

openssl-v0.10.78

What's Changed

Full Changelog: rust-openssl/rust-openssl@openssl-v0.10.77...openssl-v0.10.78

openssl-v0.10.77

What's Changed

New Contributors

Full Changelog: rust-openssl/rust-openssl@openssl-v0.10.76...openssl-v0.10.77

openssl-v0.10.76

What's Changed

... (truncated)

Commits
  • a6debf5 Release openssl v0.10.78 and openssl-sys v0.9.114 (#2609)
  • 09b425e Check derive output buffer length on OpenSSL 1.1.x (#2606)
  • 826c388 Error for short out in MdCtxRef::digest_final() (#2608)
  • 1d10902 Validate callback-returned lengths in PSK and cookie trampolines (#2607)
  • 5af6895 Reject oversized length returns from password callback trampoline (#2605)
  • 718d07f fix inverted bounds assertion in AES key unwrap (#2604)
  • 53cc69d Add support for LibreSSL 4.3.x (#2603)
  • 0b41e79 Fix dangling stack pointer in custom extension add callback (#2599)
  • cbdedf8 Avoid panic for overlong OIDs (#2598)
  • 1fc51ef openssl 4 support (#2591)
  • Additional commits viewable in compare view


Note

Medium Risk
Lockfile-only change, but it updates crypto/TLS bindings (openssl/openssl-sys), which can affect security behavior and native linking across platforms.

Overview
Updates the Rust openssl dependency in Cargo.lock from 0.10.72 to 0.10.78, along with the corresponding openssl-sys bump from 0.9.107 to 0.9.114 (checksum updates only).

Reviewed by Cursor Bugbot for commit 057866e. Bugbot is set up for automated code reviews on this repo. Configure here.

@dependabot dependabot Bot added Changed Required label for PR that categorizes merge commit message as "Changed" for changelog dependencies Pull requests that update a dependency file rust Pull requests that update Rust code labels Apr 23, 2026
@coveralls-official

coveralls-official Bot commented Apr 23, 2026

Copy link
Copy Markdown

Coverage Report for CI Build 24848502304

Coverage remained the same at 87.497%

Details

  • Coverage remained the same as the base build.
  • Patch coverage: No coverable lines changed in this PR.
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 8542
Covered Lines: 7474
Line Coverage: 87.5%
Coverage Strength: 30888543.99 hits per line

💛 - Coveralls

@dependabot @github

dependabot Bot commented on behalf of github Apr 23, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot couldn't access the repository. Because of this, Dependabot cannot update this pull request.

@dependabot
dependabot Bot force-pushed the dependabot/cargo/openssl-0.10.78 branch from ca9abe5 to 4015bd5 Compare April 23, 2026 17:11
Bumps [openssl](https://github.com/rust-openssl/rust-openssl) from 0.10.72 to 0.10.78.
- [Release notes](https://github.com/rust-openssl/rust-openssl/releases)
- [Commits](rust-openssl/rust-openssl@openssl-v0.10.72...openssl-v0.10.78)

---
updated-dependencies:
- dependency-name: openssl
  dependency-version: 0.10.78
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/cargo/openssl-0.10.78 branch from 4015bd5 to 057866e Compare April 29, 2026 14:52
@emlowe

emlowe commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Apr 30, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR is already up-to-date with main! If you'd still like to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@dependabot @github

dependabot Bot commented on behalf of github May 6, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #778.

@dependabot dependabot Bot closed this May 6, 2026
@dependabot
dependabot Bot deleted the dependabot/cargo/openssl-0.10.78 branch May 6, 2026 18:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Changed Required label for PR that categorizes merge commit message as "Changed" for changelog dependencies Pull requests that update a dependency file rust Pull requests that update Rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant