main
tls: drop hand-rolled TLS client hello parser
src: implement MemoryRetainer protocol for ByteSource
crypto: preserve OpenSSL errors from KDF failures
crypto: fix potential null pointer dereference when BIO_meth_new() fails
src: use `v8::ExternalMemoryAccounter`
crypto: add mgf1Hash for RSA-OAEP
crypto: split OpenSSL 3, BoringSSL, and legacy backends
src: cleanup crypto more
tls,quic: commonize TLS cert handling between tls, dtls & quic
crypto: handle DH operation failures
crypto: decorate async crypto job errors with OpenSSL error details
src: remove unused DSAKeyExportJob
src: update repeated use strings to env
crypto: accept key data in crypto.diffieHellman() and cleanup DH jobs
crypto: support non-byte WebCrypto lengths and cSHAKE
crypto: support loading private keys through STORE loaders
crypto: harden WebCrypto against prototype pollution
crypto: wire ML-DSA and ML-KEM for use when using BoringSSL
src: improve StringBytes error handling
src: register external references in crypto bindings
crypto: fix argument validation in crypto.timingSafeEqual fast path
tls: don't trigger SNICallback or OCSPRequest from the TLS lib stack
crypto: handle XOF output allocation failure
src: report why --enable-fips failed
src: improve error handling in crypto_x509