Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

curl removed from Omnibus-GitLab FIPS packages in 19.0

Blog post from GitLab

Post Details
Company
Date Published
Author
Adam Chu
Word Count
304
Company Posts That Month
22
Language
English
Hacker News Points
-
Post removed?
No
Summary

Starting with Omnibus-GitLab 19.0, GitLab will no longer include a GitLab-built version of curl in FIPS packages, opting instead to use the curl package provided by the customer's Linux distribution. This change is driven by curl 8.18.0's deprecation of compilation against OpenSSL 1.x, affecting systems like Amazon Linux 2 and AlmaLinux 8. GitLab's approach aligns with its existing practice of using the distribution's cryptographic libraries in FIPS packages for maintainability and security reasons. The transition, effective from May 21, 2026, means that GitLab will not be responsible for curl security updates specifically in FIPS packages, and customers must ensure their OS's curl is up to date. The change is intended to maintain functionality without requiring immediate action from users, though they should note that scanner findings for curl will now reflect the host OS package.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.