Full changelog: https://cryptography.io/en/latest/changelog/#v48-0-0
This contains one backwards-incompatible change, but which is in a
failure path where the previous behavior was unexpected.
- BACKWARDS INCOMPATIBLE: Loading an X.509 CRL whose inner
TBSCertList.signature algorithm does not match the outer
signatureAlgorithm now raises ValueError. Previously, such CRLs were
parsed successfully and only rejected during signature validation.
- Added support for ML-KEM key encapsulation and ML-DSA signing when
using OpenSSL 3.5.0 or later
Signed-off-by: Jeremy Cline <jeremycline@microsoft.com>