Skip to content

Update OpenSSL (August 2026) #156369

Description

@zware

Feature or enhancement

Proposal:

OpenSSL has updated releases, including 3.6.4, 3.5.8, 3.0.22. The highest vulnerability level in this set is "moderate" and it is not obvious that we are directly impacted by any of them, but we should still update before our next round of scheduled releases anyway so I'm adding the 'release-blocker' label here.

We should update the CI, release artifacts, and so on.

Has this already been discussed elsewhere?

This is a minor feature, which does not need previous discussion elsewhere

Links to previous discussion of this feature:

See gh-151159, gh-149254 for previous rounds.

Linked PRs

Metadata

Metadata

Assignees

Labels

3.13bugs and security fixes3.14bugs and security fixes3.15pre-release feature fixes, bugs and security fixes3.16new features, bugs and security fixesOS-androidOS-iosOS-macOS-windowsdependenciesPull requests that update a dependency fileinfraCI, GitHub Actions, buildbots, Dependabot, etc.release-blockertopic-SSLtype-featureA feature request or enhancement

Projects

Status
Todo

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions