-
-
Notifications
You must be signed in to change notification settings - Fork 36.3k
Update OpenSSL (September 2026) #158010
Copy link
Copy link
Open
Labels
3.13bugs and security fixesbugs and security fixes3.14bugs and security fixesbugs and security fixes3.15pre-release feature fixes, bugs and security fixespre-release feature fixes, bugs and security fixes3.16new features, bugs and security fixesnew features, bugs and security fixesOS-androidOS-iosOS-macOS-windowsdependenciesPull requests that update a dependency filePull requests that update a dependency fileinfraCI, GitHub Actions, buildbots, Dependabot, etc.CI, GitHub Actions, buildbots, Dependabot, etc.release-blockertopic-SSLtype-featureA feature request or enhancementA feature request or enhancement
Description
Activity
Metadata
Metadata
Assignees
Labels
3.13bugs and security fixesbugs and security fixes3.14bugs and security fixesbugs and security fixes3.15pre-release feature fixes, bugs and security fixespre-release feature fixes, bugs and security fixes3.16new features, bugs and security fixesnew features, bugs and security fixesOS-androidOS-iosOS-macOS-windowsdependenciesPull requests that update a dependency filePull requests that update a dependency fileinfraCI, GitHub Actions, buildbots, Dependabot, etc.CI, GitHub Actions, buildbots, Dependabot, etc.release-blockertopic-SSLtype-featureA feature request or enhancementA feature request or enhancement
Projects
- StatusShow more project fieldsTodo
Feature or enhancement
Proposal:
OpenSSL will have updated releases, including 3.5.9 and (not publicly available) 3.0.23. The highest vulnerability level in this set is "high" and it is not yet known if we will be directly impacted, but we should update before the next round of our releases anyway.
OpenSSL 3.0 (still used by 3.13) is now EOL, so we will need to update 3.13 binaries to 3.5 as well, with RM @Yhg1s's understandably begrudging agreement obtained on Discord. I'll be going ahead with that update (to 3.5.8) before the new releases are available to give us as much time as possible to work out any issues arising from that and to make backporting the 3.5.8->3.5.9 update as smooth as possible.
Has this already been discussed elsewhere?
This is a minor feature, which does not need previous discussion elsewhere
Links to previous discussion of this feature:
See gh-156369, gh-151159, gh-149254 for previous rounds.
Linked PRs