SSL_CTX_set_default_verify_paths() only works if OpenSSL's compiled-in
default CA path happens to exist on the machine running the binary -
a path baked in wherever OpenSSL was built, not where the release
binary ends up. That almost never matched an end user's machine
(no such path on stock macOS; Linux distros disagree on the
location), so --upload failed with a TLS/certificate error on nearly
every machine except the one that built the release binaries.
Embed the Mozilla CA root bundle (src/ca_bundle.h) as a fallback trust
source, tried alongside the system's own default paths so locally-
trusted/corporate CAs still work where present. Windows is unaffected
since TLS is stubbed out there already.
Bump to 0.1.5-hotfix2.