contentauth / c2pa-attacks

Content Authenticity Security Tool
Apache License 2.0
5 stars 4 forks source link

Bump c2pa from 0.32.6 to 0.32.7 #178

Closed dependabot[bot] closed 3 months ago

dependabot[bot] commented 4 months ago

Bumps c2pa from 0.32.6 to 0.32.7.

Release notes

Sourced from c2pa's releases.

v0.32.7

  • Ensure Ingredient data_types make it to the store and back. (#514)
  • draft security md (#508)
  • Make data_types field optional when serializing data-box-map (#512)
  • Fix box hash placeholder len (set to 1) (#511)
  • Set data box placeholder len to at least 1 for GIF (#510)
  • Rewind mp3 streams when reading/writing (#509)
  • Update README.md (#351)
  • Add GIF support (#489)
  • Update image requirement from 0.24.7 to 0.25.1 in /make_test_images (#445)
  • Upgrade uuid to 1.7.0 & fix removed wasm-bindgen feature (#450)
  • Expose SignatureInfo publicly (#501)
  • Cleanup empty/unused files + lints (#500)
Changelog

Sourced from c2pa's changelog.

0.32.7

18 July 2024

  • Ensure Ingredient data_types make it to the store and back. (#514)
  • draft security md (#508)
  • Make data_types field optional when serializing data-box-map (#512)
  • Fix box hash placeholder len (set to 1) (#511)
  • Set data box placeholder len to at least 1 for GIF (#510)
  • Rewind mp3 streams when reading/writing (#509)
  • Update README.md (#351)
  • Add GIF support (#489)
  • Update image requirement from 0.24.7 to 0.25.1 in /make_test_images (#445)
  • Upgrade uuid to 1.7.0 & fix removed wasm-bindgen feature (#450)
  • Expose SignatureInfo publicly (#501)
  • Cleanup empty/unused files + lints (#500)
Commits


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)