This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+7 more
Affected surfaces
ReleasePort's take
Light signalThe v0.5.0 release fixes RSA-2048 leakage in the auth fixture policy and hardens secret handling across crypto components.
Why it matters: Addresses a highβseverity (90) security flaw leaking RSA keys; operators should upgrade immediately to prevent credential exposure.
Summary
AI summaryUpdates π¦ Other Changes, π Documentation, and 0.5.0 - 2026-06-14 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes RSA-2048 leakage in auth fixture policy. Fixes RSA-2048 leakage in auth fixture policy. Source: llm_adapter@2026-06-14 Confidence: high |
β |
| Performance | Low |
Refreshes crypto benchmarks for typed APIs. Refreshes crypto benchmarks for typed APIs. Source: llm_adapter@2026-06-14 Confidence: high |
β |
| Bugfix | Medium |
Hardens secret handling and CT validation paths in crypto. Hardens secret handling and CT validation paths in crypto. Source: llm_adapter@2026-06-14 Confidence: low |
β |
| Bugfix | Low |
Scopes CT evidence to required primitives and repairs macOS RSA fixtures. Scopes CT evidence to required primitives and repairs macOS RSA fixtures. Source: llm_adapter@2026-06-14 Confidence: high |
β |
| Refactor | Low |
Aligns migration guidance with hardened verification defaults in docs. Aligns migration guidance with hardened verification defaults in docs. Source: llm_adapter@2026-06-14 Confidence: high |
β |
| Refactor | Low |
Clarifies CRC64 reference constants in checksum module. Clarifies CRC64 reference constants in checksum module. Source: llm_adapter@2026-06-14 Confidence: high |
β |
| Refactor | Low |
Aligns feature metadata and lockfiles for CT tooling in workspace. Aligns feature metadata and lockfiles for CT tooling in workspace. Source: llm_adapter@2026-06-14 Confidence: high |
β |
Full changelog
0.5.0 - 2026-06-14
π Documentation
- prepare public docs for v0.5.0 release (1ba0795)
π¦ Other Changes
- auth: fix RSA-2048 leakage fixture policy (c8f6886)
- crypto: harden secret handling and CT validation paths ci: scope CT evidence to required primitives and repair macOS RSA fixtures docs: align migration guidance with hardened verification defaults bench: refresh crypto benches for typed APIs checksum: clarify CRC64 reference constants workspace: align feature metadata and lockfiles for CT tooling (30ddfb6)
Security Fixes
- auth: fixed RSA-2048 leakage fixture policy
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Rscrypto
All releases βRelated context
Related tools
Beta — feedback welcome: [email protected]