github fabriziosalmi/certmate v2.3.5
v2.3.5 — security: picomatch CVEs + pyopenssl bump

latest releases: v2.3.7, v2.3.6
5 hours ago

v2.3.5 (Patch — security)

  • Security: bump build-time dependency picomatch from 2.3.1 to 2.3.2 (#94) to address CVE-2026-33671 and CVE-2026-33672. The dependency is dev-only (transitive of tailwindcss, used at CSS build time) — runtime image and end-user installations are not exposed, but the bump keeps SCA scanners and CI clean.
  • Security: bump runtime dependency pyopenssl from 25.3.0 to 26.0.0 (#86). Routine maintenance — no known CVEs at the previous pin, but the new version closes a moderate-severity advisory in upstream OpenSSL bindings and is what fresh installs get by default.

Don't miss a new certmate release

NewReleases is sending notifications on new releases.