1.2.1 is over two years old, 1.2.2 was released this week. I'm not entirely sure yet whether the introduced patch to get X509_OBJECT_get0_X509() and X509_STORE_get0_objects() working is the way to go, maybe someone more knowledgable about OpenSSL internals can comment/fix this?
Other than that a trivial version bump suffices, test still passes and mbsync works as expected. Comments? Feedback?