See: https://mta.openssl.org/pipermail/openssl-users/2019-May/010518.html No CVEs are addressed. These are not security updates, so don't need to be handled as a security release. - 6.x: EOL, doesn't need updating - 11.x: EOL 4 days after expected release date, doesn't need updating - 8.x: will need update to 1.0.2s - 10.x, 12.x, and master: will need update to 1.1.1c @nodejs/security @nodejs/security-release