Skip to content

chore(deps): bump openssl from 0.10.73 to 0.10.80 - #397

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/openssl-0.10.80
Closed

chore(deps): bump openssl from 0.10.73 to 0.10.80#397
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/openssl-0.10.80

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 20, 2026

Copy link
Copy Markdown
Contributor

Bumps openssl from 0.10.73 to 0.10.80.

Release notes

Sourced from openssl's releases.

openssl-v0.10.80

What's Changed

Full Changelog: rust-openssl/rust-openssl@openssl-v0.10.79...openssl-v0.10.80

openssl-v0.10.79

What's Changed

Full Changelog: rust-openssl/rust-openssl@openssl-v0.10.78...openssl-v0.10.79

openssl-v0.10.78

What's Changed

... (truncated)

Commits
  • 35be7ae Release openssl 0.10.80 and openssl-sys 0.9.116 (#2639)
  • 19eceb2 Fix output buffer overflow in cipher_update_inplace for AES key-wrap-with-pad...
  • b460eb3 Prefer Homebrew openssl@4 and stop looking for openssl@1.1 (#2633)
  • 649f2d9 Release openssl 0.10.79 and openssl-sys 0.9.115 (#2632)
  • 257f9b2 Fix output buffer overflow for AES key-wrap-with-padding ciphers (#2630)
  • d43e917 Reject non-UTF-8 OCSP responder URLs in X509Ref::ocsp_responders (#2631)
  • f46519c Add PkeyCtxRef::set_context_string for ML-DSA (#2629)
  • ad9ae31 Bind OSSL_PARAM_modified and use it for seed_into (#2628)
  • 4e25c9b Fix process abort when verify/PSK callbacks fire after SSL_CTX swap (#2624)
  • 3dd8f42 Add PKeyRef::seed_into for ML-DSA/ML-KEM seed extraction (#2626)
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [openssl](https://github.com/rust-openssl/rust-openssl) from 0.10.73 to 0.10.80.
- [Release notes](https://github.com/rust-openssl/rust-openssl/releases)
- [Commits](rust-openssl/rust-openssl@openssl-v0.10.73...openssl-v0.10.80)

---
updated-dependencies:
- dependency-name: openssl
  dependency-version: 0.10.80
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels May 20, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner May 20, 2026 07:19
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels May 20, 2026
@marc0olo

Copy link
Copy Markdown
Member

Superseded by #436, which bumps this further than proposed here (openssl 0.10.81, rustls-webpki 0.103.15) and clears all 12 open advisories in one change. Closing once #436 lands — leaving open until then so nothing is lost if it needs rework.

marc0olo added a commit that referenced this pull request Aug 27, 2026
Clears **all 12 open Dependabot advisories** in one change. Supersedes
#397, #380 and #409.

## Changes

| Package | Was | Now | Alerts cleared |
|---|---|---|---|
| `openssl` | 0.10.73 | **0.10.81** | 8 — 5 high, 2 medium, 1 low |
| `openssl-sys` | 0.9.109 | 0.9.117 | (transitive) |
| `rustls-webpki` | 0.103.10 | **0.103.15** | 3 — 1 high, 2 low |
| `rand` | 0.8.5 | **0.8.8** | 1 — low |

Each alert was checked against its own patched version; all 12 verify as
cleared. `openssl` and `rustls-webpki` land *newer* than the superseded
PRs proposed (0.10.80 / 0.103.13).

Three files, and the lockfile moves exactly four package versions — no
transitive churn.

## Why not `rand` 0.10.2, as #409 proposed

`rand` is the only one of the three that reaches shipped code — it is a
**runtime** dependency of the published `ic-vetkeys` crate (plus
`ic-vetkeys-test-utils`, `ic-vetkeys-manager-canister`,
`ic-vetkeys-canisters-tests`).

But the advisory
([GHSA-cq8v-f236-94qc](GHSA-cq8v-f236-94qc),
**low**) is:

```
vulnerable range:  >= 0.7.0, < 0.8.6
first patched:     0.8.6
```

0.8.6 is a **patch** release. #409 proposed `0.10.2` — two breaking
majors past the fix — which would force a `rand` 0.8 → 0.10 API
migration across four crates including the published crypto crate, plus
a lockstep `rand_chacha` 0.3 → 0.10 move. That is a large, risky change
to absorb for a low-severity advisory that a patch bump resolves. This
PR moves the manifest floor to `0.8.6` and the lock resolves `0.8.8`.

(The `rand 0.10.2` already in `Cargo.lock` is unrelated — it arrives via
`quinn-proto`, transitively under the dev-only `reqwest`, and is
untouched here.)

## Severity in context

`openssl` and `rustls-webpki` account for 11 of the 12 alerts, including
all 6 highs — but their real exposure is **CI-only**. Both reach the
tree solely via `reqwest`, which sits under `[dev-dependencies]` next to
`pocket-ic`, and the canisters compile to `wasm32-unknown-unknown` where
neither can exist. Neither appears in the published crate's dependency
list:

```
rand           req=^0.8.5    kind=normal
rand_chacha    req=^0.3.1    kind=normal
pocket-ic      req=^15.0.0   kind=dev
```

GitHub reports `scope=runtime` for all of them, but that is inferred
from `Cargo.lock`, which carries no dev/runtime split for transitive
packages. The manifests are the authority here.

## No release required

Published `ic-vetkeys@0.9.0` declares `rand = "^0.8.5"` — i.e. `>=0.8.5,
<0.9.0`. **`0.8.8` already satisfies that**, so anyone building against
0.9.0 today resolves the fixed version automatically; nobody is pinned
to the vulnerable 0.8.5 except via a stale local lockfile, which `cargo
update -p rand` fixes without any action from us.

`Cargo.lock` is not consumed by dependents of a library crate, and
dev-dependencies never propagate — so the `openssl` / `rustls-webpki`
half has zero consumer impact by construction.

The manifest floor bump to `0.8.6` only takes effect when we next
publish, and is belt-and-braces for the stale-lockfile case. **It can
ride the next release rather than triggering one.** Nothing here affects
`@icp-sdk/vetkeys` (npm) or the Motoko package.

## Verification

Ran the backend CI commands verbatim:

- `cargo build --release --target wasm32-unknown-unknown` for all four
canister crates — **pass**
- `cargo test` — **14 passed, 0 failed**, including the pocket-ic
integration tests (`key_sharing_should_work`,
`should_preserve_state_across_upgrade`,
`should_get_accessible_shared_key_ids`, …) that exercise the crypto
paths using `rand`
- `cargo test --doc` — pass (the 4 `ignored` doc-tests carry
pre-existing `ignore` annotations, unchanged here)
- `cargo clippy -- -Dwarnings` — pass
- `cargo fmt --check` — pass

`rand` 0.8.5 → 0.8.8 is a patch bump inside 0.8, so no API change was
expected; the green build and integration tests confirm it rather than
assume it.

## Superseded

- #397 — `openssl` → 0.10.80. Included here at 0.10.81.
- #380 — `rustls-webpki` → 0.103.13. Included here at 0.103.15.
- #409 — `rand` → 0.10.2. Replaced with the 0.8.x patch fix, per above.

Also closed as obsolete while triaging: #337, #316, #315 (targeted
`examples/`, removed in #377) and #406 (`vite` 7.3.5, already superseded
by `^7.3.6` from #434).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
@marc0olo marc0olo closed this Aug 27, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 27, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/cargo/openssl-0.10.80 branch August 27, 2026 09:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant