fixes a TLS certificate validation issue with fetching packages from hex.pm; although there are various signature and hash checks meaning that any attack would be quite convoluted. great write-up in https://ferd.ca/you-ve-got-to-upgrade-rebar3.html 3.15.2 is the newest version of rebar3 that still supports older Erlang/OTP (19-23); newer rebar3 supports 22-24