1. d589045 Bump version for Bazel Central Registry by Xiangfei Ding · 2 days ago main 0.20260508.0
  2. a328f4f Limit PEM data to 1 GiB. by Rudolf Polzer · 4 days ago
  3. d03b459 Roll windows toolchain by Victor Hugo Vianna Silva · 3 days ago
  4. a10c7ee Fix presubmit errors in infra/config/main.star by Victor Hugo Vianna Silva · 3 days ago
  5. 5b861a0 Consistently fill in the sign bit in BN_lebin2bn and BN_bin2bn by David Benjamin · 3 days ago
  6. 0e71ca4 Disable the tests for fork detection on Linux < 4.14. by Rudolf Polzer · 3 days ago
  7. 716e655 Inherit hostflags verify params even without hosts by David Benjamin · 5 days ago
  8. 6cd81fa Clean up bssl::PEM_read_bio_inner. by Rudolf Polzer · 11 days ago
  9. fc9c1a3 Fork detection: add rfork() and similar support for FreeBSD/OpenBSD. by Rudolf Polzer · 12 days ago
  10. 6c23695 Implement libpki's HexEncode function more straightforwardly by David Benjamin · 4 days ago
  11. 9504958 Remove internal NumberToDecimalString helper by David Benjamin · 4 days ago
  12. f47fe45 Align libpki's PEM parser with crypto/pem a bit by David Benjamin · 4 days ago
  13. 44bb993 Add some tests to capture libpki's PEMTokenizer behavior by David Benjamin · 4 days ago
  14. e40836f Clear the counters for empty or warning records only on actual data. by Rudolf Polzer · 6 days ago
  15. 6474716 rust: bssl-tls: Raw Public Key credentials by Xiangfei Ding · 5 weeks ago
  16. 5ba5963 Fix integer overflow in CollapseWhitespaceASCII. by Rudolf Polzer · 4 days ago
  17. fb16e33 x509: Use explicit has_value on optionals by Xiangfei Ding · 5 days ago
  18. 854c044 TRUST_TOKEN_ISSUER: add missing `return 0` when trying to set a too small metadata key. by Rudolf Polzer · 4 days ago
  19. dc5afeb rust: bssl-tls: feature gate the sync_io module by Xiangfei Ding · 5 days ago
  20. fbca91c rust: bssl-tls: Expose bssl_sys::SSL handle from `TlsConnection` by Xiangfei Ding · 4 days ago
  21. 081c202 perlasm: Conform to the visibility convention and fix typo by Xiangfei Ding · 5 days ago
  22. c9f0d64 ssl: const-correct SSL_CREDENTIAL by Xiangfei Ding · 5 days ago
  23. 7d398e7 Implement a vectorized "double Keccak". by Rudolf Polzer · 3 weeks ago
  24. aa77bfa rust: bssl-tls: Introduce custom certificate verification by xfding · 7 weeks ago
  25. 72540d5 draft-ietf-tls-tls13-pkcs1-00 is now RFC 9963 by David Benjamin · 5 days ago
  26. 9bce21d Fix BIO_set_retry_special by David Benjamin · 5 days ago
  27. 580a524 Test non-blocking connect in connect BIOs by David Benjamin · 5 days ago
  28. b84dc60 crypto/x509: Tighten URI name constraints parsing and matching by Lily Chen · 4 weeks ago
  29. 4e17cdd Fix return value in x509_print_rsa_pss_params error path by David Benjamin · 5 days ago
  30. 9e2bf26 rust: bssl-tls: Do not depend on `tracing` yet by Xiangfei Ding · 6 days ago
  31. 1dd1981 crypto: Make X509* and EVP_PKEY* const clonable by Xiangfei Ding · 3 weeks ago
  32. 2a8e861 bssl-crypto: Stop gating ML-DSA on a Rust feature flag by David Benjamin · 6 days ago
  33. 4868e33 rust: bssl-tls: Remove TlsConnectionRef by Xiangfei Ding · 8 days ago
  34. 14e014f rust: bssl-tls: Promote CertificateCache to a full ref-counted type by Xiangfei Ding · 8 days ago
  35. e8ab7ae Use placement new to initialize the atomic into the WIPEONFORK page by David Benjamin · 12 days ago
  36. e02c288 Implement EVP_HPKE_KEY_derive by David Benjamin · 6 days ago
  37. e20b022 Use HPKE-PQ test vectors from the spec by David Benjamin · 7 days ago
  38. 65818ad rust: bssl-tls: fix MockSocket behaviour on pending read by Xiangfei Ding · 7 days ago
  39. 39f4531 rust: bssl-x509: rename our panic-catcher by Xiangfei Ding · 6 weeks ago
  40. 9c81e5c x509: Switch from implicit `bool`-conversion to `has_value` by Xiangfei Ding · 6 days ago
  41. 742a4d2 Update Wycheproof test vectors by David Benjamin · 11 days ago
  42. aef0e2d Reference-count CRYPTO_BUFFER_POOLs by David Benjamin · 10 days ago
  43. 7a441c6 rust: bssl-tls: Sessions for TLS 1.3 by Xiangfei Ding · 13 days ago
  44. 8aab304 rust: bssl-tls: Carve out tokio support into its own crate by Xiangfei Ding · 9 days ago
  45. b771573 rust: bssl-tls: I/O mocking infrastructure by Xiangfei Ding · 5 weeks ago
  46. 6935e82 rust: bssl-tls: General functional tests by Xiangfei Ding · 4 weeks ago
  47. a1c1467 rust: bssl-tls: Formatting and feature gate fix by Xiangfei Ding · 10 days ago
  48. 57b745e audit_symbols: Allowlist stdext:: weak symbols on Windows by Lily Chen · 11 days ago
  49. aedc995 Modernize crypto/x509/policy.cc a bit by David Benjamin · 2 weeks ago
  50. bb9fc5f Add helpers to match characters in CBS by Lily Chen · 3 weeks ago
  51. 7b20b3c Various IWYU fixes by David Benjamin · 11 days ago
  52. 271b64a Check for negative bit indices in ASN1_BIT_STRING_set_bit by David Benjamin · 11 days ago
  53. 75a048d Hook up X-wing to EVP_KEM by Lily Chen · 3 weeks ago
  54. 04aa32f Fix the legacy AES-GCM API's IV resizing logic by David Benjamin · 2 weeks ago
  55. ac5067e Move some code around in v3_ncons.cc by Lily Chen · 12 days ago
  56. 61e81eb Fix up v2i_NAME_CONSTRAINTS by David Benjamin · 12 days ago
  57. 929f91f Add tests for nameConstraints' ad-hoc config parser by David Benjamin · 12 days ago
  58. 1f6e731 Clear the sorted bit after sk_FOO_set by David Benjamin · 12 days ago
  59. f50cce8 rust: bssl-tls: Add MLDSA into list of signature algorithms by Xiangfei Ding · 13 days ago
  60. 0b5b5ff Tidy up ownership a bit in X509_get1_email and friends by David Benjamin · 2 weeks ago
  61. 102f5c5 Defer dedup in X509_get1_email and friends to the end by David Benjamin · 2 weeks ago
  62. 8415495 Unwind EC_FELEM hooks on EC_METHOD by David Benjamin · 2 weeks ago
  63. 06212ed Add an EVP adapter for KEM encap/decap by Lily Chen · 13 days ago
  64. b9696cb Add sk_FOO_sort_and_dedup by David Benjamin · 2 weeks ago
  65. 4d124cf Update documentation for ML-KEM by Lily Chen · 13 days ago
  66. 0d88d52 pregenerate: Compile public headers entirely as C. by Rudolf Polzer · 14 days ago
  67. 1cd0994 Reject trailing data in ClientHello and EncryptedExtensions trust_anchors by David Benjamin · 2 weeks ago
  68. cb507bd Test trailing data in OCSP staple parsing by David Benjamin · 2 weeks ago
  69. e93c8fd Test trailing data for SNI parsing by David Benjamin · 2 weeks ago
  70. c70aca7 Remove the OPENSSL_NO_ASM gate in OPENSSL_cleanse by David Benjamin · 2 weeks ago
  71. 151cf73 Add tests for X509_get1_email and friends by David Benjamin · 2 weeks ago
  72. 0d160a8 pregenerate: Collect symbols with -DBORINGSSL_NO_CXX by David Benjamin · 2 weeks ago
  73. b82b0af pregenerate: Don't process libpki headers for symbols by David Benjamin · 2 weeks ago
  74. 0f0884b EVP_PKEY: Treat pss_params as params for RSA-PSS keys by Lily Chen · 2 weeks ago
  75. 7ab7be8 Allow no-op EVP_CTRL_AEAD_SET_IVLEN calls to keep the IV set by David Benjamin · 2 weeks ago
  76. 0b42382 slhdsa: Reorder a BSSL_CHECK with its shift by David Benjamin · 2 weeks ago
  77. b9f2f76 Fix some unreachable code in curve25519_64_adx.h's fiat_addcarryx_u64 by David Benjamin · 2 weeks ago
  78. 75c449c rust: bssl-tls: Introduce basic session controls on context level by Xiangfei Ding · 7 weeks ago
  79. 6afcf8d rust: bssl-tls: More advanced controls over certificate verification by xfding · 7 weeks ago
  80. 837e6ce rust: bssl-tls: More advanced control over IO transport by xfding · 7 weeks ago
  81. c67abbf rust: bssl-tls: Introduce TLS alerts by xfding · 7 weeks ago
  82. 3d5cafd Don't skip calling the cleanup hook in EVP_PKEY_CTX when the copy hook fails by David Benjamin · 2 weeks ago
  83. 40e356a Check for invalid certificate_authorities extensions by David Benjamin · 2 weeks ago
  84. bf307da Remove p224-64.cc.inc by David Benjamin · 2 weeks ago
  85. c3ffc33 pki: Check for unused bits when verifying MTC proofs by David Benjamin · 2 weeks ago
  86. 92fc136 rust: bssl-tls: Reinstate preshared key tests by Xiangfei Ding · 3 weeks ago
  87. f02f0ee rust: bssl-x509: Stop reporting partially constructed cert chain by Xiangfei Ding · 3 weeks ago
  88. 09e53b2 rust: bssl-x509: proper serialisation of X.509 certificate serial number by Xiangfei Ding · 3 weeks ago
  89. ef5a1cc Test 0 * P + 0 * G in ec_point_mul_scalar_public by David Benjamin · 2 weeks ago
  90. 21fa3fc Cut down on test-only OPENSSL_EXPORTs by David Benjamin · 2 weeks ago
  91. d944558 rust: bssl-rustls-adapters: Mask the content type and protocol by Xiangfei Ding · 3 weeks ago
  92. 439e537 rust: bssl-tls: std and tokio transport integration by Xiangfei Ding · 5 weeks ago
  93. f3229af rust: bssl-tls: Drop Sync on BIO objects by Xiangfei Ding · 5 weeks ago
  94. acd9b96 rust: bssl-tls: Application facing I/O by Xiangfei Ding · 7 weeks ago
  95. a73b26b rust: bssl-tls: Make certificate store more ergonomic by Xiangfei Ding · 2 weeks ago
  96. ca56661 Add missing CONSTTIME_SECRET markers to ML-DSA implementation by David Benjamin · 2 weeks ago
  97. 880f5db Configure .clangd and .clang-format so that header insertion works by David Benjamin · 2 weeks ago
  98. 1cc9482 Reset IV state in legacy AES-GCM API on EVP_CTRL_AEAD_SET_IVLEN by David Benjamin · 3 weeks ago
  99. 4a3cda4 Support ML-DSA in libssl by Nick Harper · 4 weeks ago
  100. e9449d4 Require internal and external ML-KEM public key structs to match in size by Lily Chen · 2 weeks ago