curl removed from Omnibus-GitLab FIPS packages in 19.0
Blog post from GitLab
Starting with Omnibus-GitLab 19.0, GitLab will no longer include a GitLab-built version of curl in FIPS packages, opting instead to use the curl package provided by the customer's Linux distribution. This change is driven by curl 8.18.0's deprecation of compilation against OpenSSL 1.x, affecting systems like Amazon Linux 2 and AlmaLinux 8. GitLab's approach aligns with its existing practice of using the distribution's cryptographic libraries in FIPS packages for maintainability and security reasons. The transition, effective from May 21, 2026, means that GitLab will not be responsible for curl security updates specifically in FIPS packages, and customers must ensure their OS's curl is up to date. The change is intended to maintain functionality without requiring immediate action from users, though they should note that scanner findings for curl will now reflect the host OS package.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.