Skip to content

prepare for release 5.9.2#10757

Open
philljj wants to merge 1 commit into
wolfSSL:masterfrom
philljj:release
Open

prepare for release 5.9.2#10757
philljj wants to merge 1 commit into
wolfSSL:masterfrom
philljj:release

Conversation

@philljj

@philljj philljj commented Jun 23, 2026

Copy link
Copy Markdown
Contributor

No description provided.

@philljj philljj self-assigned this Jun 23, 2026
Copilot AI review requested due to automatic review settings June 23, 2026 01:35

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Prepares the wolfSSL codebase for the 5.9.2 release by updating the library version metadata across headers/build systems and refreshing the bundled release notes/changelog.

Changes:

  • Bump wolfSSL version to 5.9.2 in headers and build tooling (Autotools + CMake).
  • Update shared library ABI version numbers (SOVERSION/libtool version components).
  • Refresh release notes/changelog text for the 5.9.2 release and update Windows resource version fields.

Reviewed changes

Copilot reviewed 8 out of 9 changed files in this pull request and generated 6 comments.

Show a summary per file
File Description
wolfssl/version.h Updates LIBWOLFSSL_VERSION_STRING and LIBWOLFSSL_VERSION_HEX to 5.9.2.
README.md Updates Markdown release notes content for 5.9.2.
README Updates plain-text release notes content for 5.9.2.
IDE/WIN10/wolfssl-fips.rc Updates Windows DLL resource version fields to 5.9.2.0.
IDE/WIN-SRTP-KDF-140-3/wolfssl-fips.rc Updates Windows DLL resource version fields to 5.9.2.0.
configure.ac Updates Autotools package version and shared library version components.
CMakeLists.txt Updates CMake project version and shared library version components.
ChangeLog.md Updates changelog content for the 5.9.2 release.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread README.md
* **BREAKING (RFC 6960 4.2.2.2)**: OCSP responder authorization is now strictly enforced. Removes the non-compliant `CheckOcspResponderChain()` fallback, which authorized any OCSP responder cert issued by an ancestor of the target's issuer; RFC 6960 4.2.2.2 requires direct issuance by the CA identified in the request. Also removes the now-unused `WOLFSSL_NO_OCSP_ISSUER_CHAIN_CHECK` macro and the `vp` parameter from `CheckOcspResponder()`.

PR stands for Pull Request, and PR <NUMBER> references a GitHub pull request number where the code change was added.
PR stands for Pull Request, and PR (NUMBER) references a GitHub pull request number where the code change was added.
Comment thread README.md
Comment on lines +151 to +152
* [Med] CVE-2026-6731
X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN violates an issuing CA's DNS name constraints could be accepted. Thanks to d0sf3t (Aradex) for the report. Fixed in PR 10223.
Comment thread ChangeLog.md
* liboqs integrations for ML-KEM, ML-DSA, and SLH-DSA (SPHINCS+) have been removed in favor of the native implementations; the deprecated liblms and libxmss integrations have also been removed.
* **BREAKING (RFC 6960 4.2.2.2)**: OCSP responder authorization is now strictly enforced. Removes the non-compliant `CheckOcspResponderChain()` fallback, which authorized any OCSP responder cert issued by an ancestor of the target's issuer; RFC 6960 4.2.2.2 requires direct issuance by the CA identified in the request. Also removes the now-unused `WOLFSSL_NO_OCSP_ISSUER_CHAIN_CHECK` macro and the `vp` parameter from `CheckOcspResponder()`.

PR stands for Pull Request, and PR (NUMBER) references a GitHub pull request number where the code change was added.
Comment thread ChangeLog.md
Comment on lines +43 to +44
* [Med] CVE-2026-6731
X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN violates an issuing CA's DNS name constraints could be accepted. Thanks to d0sf3t (Aradex) for the report. Fixed in PR 10223.
Comment thread README
* **BREAKING (RFC 6960 4.2.2.2)**: OCSP responder authorization is now strictly enforced. Removes the non-compliant `CheckOcspResponderChain()` fallback, which authorized any OCSP responder cert issued by an ancestor of the target's issuer; RFC 6960 4.2.2.2 requires direct issuance by the CA identified in the request. Also removes the now-unused `WOLFSSL_NO_OCSP_ISSUER_CHAIN_CHECK` macro and the `vp` parameter from `CheckOcspResponder()`.

PR stands for Pull Request, and PR <NUMBER> references a GitHub pull request number where the code change was added.
PR stands for Pull Request, and PR (NUMBER) references a GitHub pull request number where the code change was added.
Comment thread README
Comment on lines +121 to +122
* [Med] CVE-2026-6731
X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN violates an issuing CA's DNS name constraints could be accepted. Thanks to d0sf3t (Aradex) for the report. Fixed in PR 10223.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants