)]}'
{
  "commit": "c3c540b9a4d066476e8be372e0c5059979c8578e",
  "tree": "e336b467d726c877752bf98058c80d10c838cfbc",
  "parents": [
    "2042972e8458833714bce23386931b1c79978439"
  ],
  "author": {
    "name": "David Benjamin",
    "email": "davidben@google.com",
    "time": "Wed Dec 08 15:12:51 2021 -0500"
  },
  "committer": {
    "name": "Adam Langley",
    "email": "agl@google.com",
    "time": "Mon Dec 13 22:08:59 2021 +0000"
  },
  "message": "Remove non-standard X.509 DNS wildcard matching.\n\nAlways enable X509_CHECK_FLAG_NO_PARTIAL_WILDCARDS and never enable\nX509_CHECK_FLAG_MULTI_LABEL_WILDCARDS.\n\nUpdate-Note: BoringSSL will no longer accept wildcard patterns like\n*www.example.com or www*.example.com. (It already did not accept\nww*w.example.com.) X509_CHECK_FLAG_MULTI_LABEL_WILDCARDS will also be\nignored and can no longer be used to allow foo.bar.example.com to match\n*.example.com.\n\nFixes: 462\nChange-Id: I004e087bf70f4c3f249235cd864d9e19cc9a5102\nReviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/50705\nReviewed-by: Adam Langley \u003cagl@google.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "5d91aede7bcf2a037999c0e4e822168657bac2a0",
      "old_mode": 33188,
      "old_path": "crypto/x509v3/v3_utl.c",
      "new_id": "7e7c54966602ca62f22a779c0d7e336d863c1945",
      "new_mode": 33188,
      "new_path": "crypto/x509v3/v3_utl.c"
    },
    {
      "type": "modify",
      "old_id": "acff637f79f0c7b3e82ba1f609314cbd60109e50",
      "old_mode": 33188,
      "old_path": "include/openssl/x509v3.h",
      "new_id": "3e8cf1b4664aa35e0d9adb619c0763ebbefc661d",
      "new_mode": 33188,
      "new_path": "include/openssl/x509v3.h"
    },
    {
      "type": "modify",
      "old_id": "6ef80cbf164e509c69b6c41ad0accda0941839c7",
      "old_mode": 33188,
      "old_path": "ssl/ssl_test.cc",
      "new_id": "d0bd680e19e6a220f361e3380d185281a09f40a0",
      "new_mode": 33188,
      "new_path": "ssl/ssl_test.cc"
    }
  ]
}
