Patch release that addresses a security vulnerability in ZSTD:
- fix heap buffer overflow in ZSTD deep scanline decoding
Also, the v3.5.0 release incorrectly identified the OPENEXR_VERSION_RELEASE_TYPE and associated OPENEXR_PACKAGE_NAME as -dev.
See CHANGES.md for more details.
