SecureTransport has been deprecated by Apple several years ago, is considered less secure because it does not support TLS 1.3, and has been removed from e.g. libcurl for that reason, see curl/curl#15759 and https://daniel.haxx.se/blog/2025/01/14/secure-transport-support-in-curl-is-on-its-way-out/
In addition, users of the R bindings of this library have experienced regular hangs on MacOS when fetching git repos with the current libgit2. These problems disappear when we build against OpenSSL.
Maybe we should follow libcurl, and switch the default on MacOS to -DUSE_HTTPS=OpenSSL and mark SecureTransport as deprecated.
SecureTransport has been deprecated by Apple several years ago, is considered less secure because it does not support TLS 1.3, and has been removed from e.g. libcurl for that reason, see curl/curl#15759 and https://daniel.haxx.se/blog/2025/01/14/secure-transport-support-in-curl-is-on-its-way-out/
In addition, users of the R bindings of this library have experienced regular hangs on MacOS when fetching git repos with the current libgit2. These problems disappear when we build against OpenSSL.
Maybe we should follow libcurl, and switch the default on MacOS to
-DUSE_HTTPS=OpenSSLand mark SecureTransport as deprecated.