Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: update to openssl 0.10.70 for CVE-2025-24898 #7435

Merged
merged 1 commit into from
Feb 3, 2025

Conversation

cfm
Copy link
Member

@cfm cfm commented Feb 3, 2025

Status

Ready for review

Description of Changes

Updates openssl to v0.10.70 for RUTSEC-2025-0004 (CVE-2025-24898), flagged in https://github.com/freedomofpress/securedrop/actions/runs/13105546611/job/36559730714#step:4:613.

Testing

CI passes.

@cfm cfm force-pushed the rustsec-2025-0004 branch from 98a14a7 to 9be6245 Compare February 3, 2025 19:43
@cfm cfm marked this pull request as ready for review February 3, 2025 19:49
@cfm cfm requested a review from a team as a code owner February 3, 2025 19:49
@legoktm legoktm self-assigned this Feb 3, 2025
Copy link
Member

@legoktm legoktm left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will wait for CI to finish before merging, but LGTM. Also nothing wrong with reviewing, but in the future Alex (who released the new crate version) is a member of the Rust project and can just be marked as trusted.

@legoktm legoktm added this pull request to the merge queue Feb 3, 2025
Merged via the queue into develop with commit 032b1af Feb 3, 2025
44 checks passed
@legoktm legoktm deleted the rustsec-2025-0004 branch February 3, 2025 20:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: Done
Development

Successfully merging this pull request may close these issues.

2 participants