This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+7 more
Affected surfaces
Summary
AI summaryUpdates π¦ Other Changes, auth, and π Documentation across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Hardens HMAC pads against AArch64 SVE division vulnerabilities. Hardens HMAC pads against AArch64 SVE division vulnerabilities. Source: llm_adapter@2026-06-13 Confidence: high |
β |
| Feature | Medium |
Adds ECDSA P-256/P-384 signing and constantβtime coverage. Adds ECDSA P-256/P-384 signing and constantβtime coverage. Source: llm_adapter@2026-06-13 Confidence: high |
β |
| Feature | Low |
Routes RSA blinding inverse through fixed scratch buffer. Routes RSA blinding inverse through fixed scratch buffer. Source: llm_adapter@2026-06-13 Confidence: high |
β |
| Feature | Low |
Adds ECDSA DudeCT diagnostics and targetβscoped constantβtime policy in CI. Adds ECDSA DudeCT diagnostics and targetβscoped constantβtime policy in CI. Source: llm_adapter@2026-06-13 Confidence: high |
β |
| Performance | Low |
Routes macOS aarch64 HKDFβSHA256 through SHA2 compression for benchmark scaling. Routes macOS aarch64 HKDFβSHA256 through SHA2 compression for benchmark scaling. Source: llm_adapter@2026-06-13 Confidence: high |
β |
| Bugfix | Low |
Disables native RISCβV Rust cache restore in CI. Disables native RISCβV Rust cache restore in CI. Source: llm_adapter@2026-06-13 Confidence: high |
β |
Full changelog
0.4.1 - 2026-06-13
π Documentation
- make public docs user-facing and add ECDSA migration guides benchmarks: refresh 2026-06-12 benchmark evidence (4a3f4e8)
π¦ Other Changes
- auth: route RSA blinding inverse through fixed scratch (a33fc67)
- auth: route macOS aarch64 HKDF-SHA256 through SHA2 compression hashes: batch Apple SHA3 Keccak absorb blocks bench: scale README perf chart axis from benchmark data benchmarks: refresh 2026-06-12 benchmark evidence (f9ab35f)
- auth: harden HMAC pads against AArch64 SVE division ci: disable native RISC-V Rust cache restore (62be628)
- auth: harden ECDSA P-256/P-384 CT backends ci: add ECDSA DudeCT diagnostics and target-scoped CT policy (82db892)
- auth: add ECDSA P-256/P-384 signing and CT coverage (f24375d)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Rscrypto
All releases βRelated context
Related tools
Beta — feedback welcome: [email protected]