Skip to content

Prepare 0.15.2 release#637

Merged
cpu merged 2 commits intorustls:mainfrom
cpu:ci/cpu-0.15.2
Apr 15, 2026
Merged

Prepare 0.15.2 release#637
cpu merged 2 commits intorustls:mainfrom
cpu:ci/cpu-0.15.2

Conversation

@cpu
Copy link
Copy Markdown
Member

@cpu cpu commented Apr 15, 2026

This is a minor release with two security fixes. It also updates rustls to 0.23.38.

This update addresses RUSTSEC-2026-0098 and RUSTSEC-2026-0099; two security issues affecting name constraint checking with the webpki certificate verifiers. Both issues are reachable only after signature verification and require misissuance to exploit.

cpu added 2 commits April 15, 2026 09:14
Notably this updates rustls-webpki to address RUSTSEC-2026-0099 and
RUSTSEC-2026-0098.
@cpu cpu self-assigned this Apr 15, 2026
Copy link
Copy Markdown
Member

@djc djc left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for taking care of this.

Why do we retain a CHANGELOG.md file here instead of GitHub Releases, as opposed to all the other projects?

@cpu
Copy link
Copy Markdown
Member Author

cpu commented Apr 15, 2026

Why do we retain a CHANGELOG.md file here instead of GitHub Releases, as opposed to all the other projects?

I think largely just continuing with the precedent that jsha started. I'm OK with removing the CHANGELOG.md and just continuing to curate release notes in the GH releases to match the other repos. Maybe also worth backfilling some missing releases before that.

@cpu cpu merged commit ff0e9d3 into rustls:main Apr 15, 2026
46 checks passed
@cpu cpu deleted the ci/cpu-0.15.2 branch April 15, 2026 13:40
@cpu
Copy link
Copy Markdown
Member Author

cpu commented Apr 15, 2026

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants