https://github.com/python/cpython/commit/115c297fdcc7d0fab41ed0e5c08f1b9cbec35976
commit: 115c297fdcc7d0fab41ed0e5c08f1b9cbec35976
branch: main
author: Zachary Ware <[email protected]>
committer: zware <[email protected]>
date: 2026-09-29T16:23:46Z
summary:

gh-158010: Update Windows builds to use OpenSSL 3.5.9 (GH-158432)

files:
A Misc/NEWS.d/next/Windows/2026-09-29-09-56-14.gh-issue-158010.MPQX4w.rst
D Misc/NEWS.d/next/Windows/2026-06-09-11-40-48.gh-issue-151159.JKVfme.rst
D Misc/NEWS.d/next/Windows/2026-08-28-10-51-35.gh-issue-156369.MPcRL5.rst
M Misc/externals.spdx.json
M PCbuild/get_externals.bat
M PCbuild/python.props

diff --git 
a/Misc/NEWS.d/next/Windows/2026-06-09-11-40-48.gh-issue-151159.JKVfme.rst 
b/Misc/NEWS.d/next/Windows/2026-06-09-11-40-48.gh-issue-151159.JKVfme.rst
deleted file mode 100644
index ad1be115db5ce8f..000000000000000
--- a/Misc/NEWS.d/next/Windows/2026-06-09-11-40-48.gh-issue-151159.JKVfme.rst
+++ /dev/null
@@ -1 +0,0 @@
-Updated bundled version of OpenSSL to 3.5.7.
diff --git 
a/Misc/NEWS.d/next/Windows/2026-08-28-10-51-35.gh-issue-156369.MPcRL5.rst 
b/Misc/NEWS.d/next/Windows/2026-08-28-10-51-35.gh-issue-156369.MPcRL5.rst
deleted file mode 100644
index 33c02132cfdaaef..000000000000000
--- a/Misc/NEWS.d/next/Windows/2026-08-28-10-51-35.gh-issue-156369.MPcRL5.rst
+++ /dev/null
@@ -1 +0,0 @@
-Updated Windows builds to use OpenSSL 3.5.8.
diff --git 
a/Misc/NEWS.d/next/Windows/2026-09-29-09-56-14.gh-issue-158010.MPQX4w.rst 
b/Misc/NEWS.d/next/Windows/2026-09-29-09-56-14.gh-issue-158010.MPQX4w.rst
new file mode 100644
index 000000000000000..827173387f8e8af
--- /dev/null
+++ b/Misc/NEWS.d/next/Windows/2026-09-29-09-56-14.gh-issue-158010.MPQX4w.rst
@@ -0,0 +1 @@
+Updated Windows builds to use OpenSSL 3.5.9.
diff --git a/Misc/externals.spdx.json b/Misc/externals.spdx.json
index 1b658b7d4b7929a..0800347e34016db 100644
--- a/Misc/externals.spdx.json
+++ b/Misc/externals.spdx.json
@@ -70,21 +70,21 @@
       "checksums": [
         {
           "algorithm": "SHA256",
-          "checksumValue": 
"36af13403a6f34251c875946d1d524c228cbf7b82fd54dd13d9019fbc37da87e"
+          "checksumValue": 
"d6cf0d9a651f25fe506f6b3dc133a80b9b79a0bc565f570dcf8fdbd597551485"
         }
       ],
-      "downloadLocation": 
"https://github.com/python/cpython-source-deps/archive/refs/tags/openssl-3.5.8.tar.gz";,
+      "downloadLocation": 
"https://github.com/python/cpython-source-deps/archive/refs/tags/openssl-3.5.9.tar.gz";,
       "externalRefs": [
         {
           "referenceCategory": "SECURITY",
-          "referenceLocator": "cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*",
+          "referenceLocator": "cpe:2.3:a:openssl:openssl:3.5.9:*:*:*:*:*:*:*",
           "referenceType": "cpe23Type"
         }
       ],
       "licenseConcluded": "NOASSERTION",
       "name": "openssl",
       "primaryPackagePurpose": "SOURCE",
-      "versionInfo": "3.5.8"
+      "versionInfo": "3.5.9"
     },
     {
       "SPDXID": "SPDXRef-PACKAGE-sqlite",
diff --git a/PCbuild/get_externals.bat b/PCbuild/get_externals.bat
index 812949dc8370db9..b5f070ca2d858d3 100644
--- a/PCbuild/get_externals.bat
+++ b/PCbuild/get_externals.bat
@@ -54,7 +54,7 @@ echo.Fetching external libraries...
 set libraries=
 set libraries=%libraries%                                       bzip2-1.0.8
 if NOT "%IncludeLibffiSrc%"=="false" set libraries=%libraries%  libffi-3.4.4
-if NOT "%IncludeSSLSrc%"=="false" set libraries=%libraries%     openssl-3.5.8
+if NOT "%IncludeSSLSrc%"=="false" set libraries=%libraries%     openssl-3.5.9
 set libraries=%libraries%                                       mpdecimal-4.0.0
 set libraries=%libraries%                                       sqlite-3.53.4.0
 if NOT "%IncludeTkinterSrc%"=="false" set libraries=%libraries% tcl-9.0.4.0
@@ -79,7 +79,7 @@ echo.Fetching external binaries...
 
 set binaries=
 if NOT "%IncludeLibffi%"=="false"  set binaries=%binaries% libffi-3.4.4
-if NOT "%IncludeSSL%"=="false"     set binaries=%binaries% openssl-bin-3.5.8
+if NOT "%IncludeSSL%"=="false"     set binaries=%binaries% openssl-bin-3.5.9
 if NOT "%IncludeTkinter%"=="false" set binaries=%binaries% tcltk-9.0.4.0
 if NOT "%IncludeSSLSrc%"=="false"  set binaries=%binaries% nasm-2.11.06
 if NOT "%IncludeLLVM%"=="false"    set binaries=%binaries% llvm-21.1.4.0
diff --git a/PCbuild/python.props b/PCbuild/python.props
index 97f04456505cd5a..4c49decd7490d1b 100644
--- a/PCbuild/python.props
+++ b/PCbuild/python.props
@@ -105,8 +105,8 @@
     <libffiOutDir Condition="$(libffiOutDir) == 
''">$(libffiDir)$(ArchName)\</libffiOutDir>
     <libffiIncludeDir Condition="$(libffiIncludeDir) == 
''">$(libffiOutDir)include</libffiIncludeDir>
     <mpdecimalDir Condition="$(mpdecimalDir) == 
''">$(ExternalsDir)\mpdecimal-4.0.0\</mpdecimalDir>
-    <opensslDir Condition="$(opensslDir) == 
''">$(ExternalsDir)openssl-3.5.8\</opensslDir>
-    <opensslOutDir Condition="$(opensslOutDir) == 
''">$(ExternalsDir)openssl-bin-3.5.8\$(ArchName)\</opensslOutDir>
+    <opensslDir Condition="$(opensslDir) == 
''">$(ExternalsDir)openssl-3.5.9\</opensslDir>
+    <opensslOutDir Condition="$(opensslOutDir) == 
''">$(ExternalsDir)openssl-bin-3.5.9\$(ArchName)\</opensslOutDir>
     <opensslIncludeDir Condition="$(opensslIncludeDir) == 
''">$(opensslOutDir)include</opensslIncludeDir>
     <nasmDir Condition="$(nasmDir) == 
''">$(ExternalsDir)\nasm-2.11.06\</nasmDir>
     <zlibDir Condition="$(zlibDir) == ''">$(ExternalsDir)\zlib-1.3.1\</zlibDir>

_______________________________________________
Python-checkins mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://mail.python.org/mailman3//lists/python-checkins.python.org
Member address: [email protected]

Reply via email to