From aeb175d548856c355a7c298f84d632f2b711687e Mon Sep 17 00:00:00 2001 From: David Blodgett Date: Wed, 6 May 2026 19:22:45 -0500 Subject: [PATCH] bump openssl 0.10.78 -> 0.10.79 in Cargo.lock Closes GHSA dependabot alert #7: undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs. Transitive via reqwest -> native-tls. --- src/rust/Cargo.lock | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/src/rust/Cargo.lock b/src/rust/Cargo.lock index a9454d8..dc6279b 100644 --- a/src/rust/Cargo.lock +++ b/src/rust/Cargo.lock @@ -1412,15 +1412,14 @@ checksum = "9f7c3e4beb33f85d45ae3e3a1792185706c8e16d043238c593331cc7cd313b50" [[package]] name = "openssl" -version = "0.10.78" +version = "0.10.79" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "f38c4372413cdaaf3cc79dd92d29d7d9f5ab09b51b10dded508fb90bb70b9222" +checksum = "bf0b434746ee2832f4f0baf10137e1cabb18cbe6912c69e2e33263c45250f542" dependencies = [ "bitflags", "cfg-if", "foreign-types", "libc", - "once_cell", "openssl-macros", "openssl-sys", ] @@ -1444,9 +1443,9 @@ checksum = "7c87def4c32ab89d880effc9e097653c8da5d6ef28e6b539d313baaacfbafcbe" [[package]] name = "openssl-sys" -version = "0.9.114" +version = "0.9.115" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "13ce1245cd07fcc4cfdb438f7507b0c7e4f3849a69fd84d52374c66d83741bb6" +checksum = "158fe5b292746440aa6e7a7e690e55aeb72d41505e2804c23c6973ad0e9c9781" dependencies = [ "cc", "libc",