Skip to content

[BUG]: postgresql-17-dev depends on openssl-hardened-dev, breaking external dependencies #78678

@max06

Description

@max06

Package name

postgresql-17-dev

Current version in Wolfi

17.9-r4

Requested version

No response

Upstream project URL

unrelated

Problem

Your recent change in 6f1d202, switching from openssl-dev to openssl-hardened-dev breaks building external packages, for example gems like puma and eventmachine.

We knew about the deprecated features in openssl 4, but we did not expect a patch level update to set them active without any warning. Or that this change would affect completely unrelated projects.

Steps to reproduce

No response

Root cause (if known)

No response

Proposed solution

No response

Testing performed

No response

Acceptance criteria

  • The requested version is the latest stable upstream release (no pre-releases or RCs)
  • The upstream project uses an OSI-approved license
  • The change aligns with Wolfi’s packaging and security model
  • The package can be reasonably maintained over time
  • There are no known unresolved security or supply-chain concerns

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-triageapplied to all new customer/user issues. Removed after triage occurs.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions