A security patch for the 1.4 line, which is supported for security fixes only. No functional changes.
Security
- Rebuilt against a refreshed base image, clearing an OpenSSL advisory affecting v1.4.2 (
GHSA-rwwr-5gjq-4jjm):openssl/libssl3t64/openssl-provider-legacymove from3.5.6-1~deb13u2to3.5.7-1~deb13u2. Verified in the published image rather than assumed —v1.4.2reports OpenSSL 3.5.6,v1.4.3reports 3.5.7.
Notes
The release commit is deliberately empty. The fix comes entirely from the base image, and tagging the commit v1.4.2 already pointed at would have let the pipeline skip the build and retag the existing images — publishing identical bytes under a new version while claiming a fix.
Nothing else is included. Per SECURITY.md, the previous minor receives security fixes only; the fix for private-git-module credentials (#1442) is in v1.5.4, not here.
Status
Stable — a drop-in upgrade from v1.4.2.
Full Changelog: v1.4.2...v1.4.3