This release includes an important Tendermint update that fixes a security issue with Tendermint light clients. For more information, see Tendermint v0.34.9 release notes.
A number of macOS users have reported that their operating system's keychain prompt them for password to unlock the
keyring when using the os backend before executing any action. This release includes a small fix that automatically
adjusts applications keyring trust so that users are prompted for password only once when the keyring is unlocked.
Tx search results support for order-by
Although the Tendermint Core's RPC tx_search endpoint has been supporting an order-by parameter for quite some time now,
the Cosmos SDK did not respect the order-by parameter and incorrectly set the requests order-by to "" (null).
This releases introduces the relevant order-by parameter support when searching through Txs.
Multisig accounts and v0.40 genesis files migration
This release fixes security vulnerability identified in the simapp.
v0.42.0
Cosmos SDK v0.42.0 "Stargate" Release Notes
This release includes an important security fix for all non Cosmos Hub chains (e.g. any chain that does not use the default cosmos bech32 prefix), and a few performance improvements.
#9026 By default, the tx sign and tx sign-batch CLI commands use SIGN_MODE_DIRECT to sign transactions for local pubkeys. For multisigs and ledger keys, the default LEGACY_AMINO_JSON is used.
Bug Fixes
(gRPC) #9015 Fix invalid status code when accessing gRPC endpoints.
#9026 Fixed the bug that caused the gentx command to fail for Ledger keys.
Improvements
#9081 Upgrade Tendermint to v0.34.9 that includes a security issue fix for Tendermint light clients.
IMPORTANT: This release contains an important security fix for all non Cosmos Hub chains running Stargate version of the Cosmos SDK (>0.40). Non-hub chains should not be using any version of the SDK in the v0.40.x or v0.41.x release series. See #8461 for more details.
Improvements
(x/ibc) #8624 Emit full header in IBC UpdateClient message.
(x/crisis) #8621 crisis invariants names now print to loggers.
Bug fixes
(x/evidence) #8461 Fix bech32 prefix in evidence validator address conversion
(x/gov) #8806 Fix q gov proposals command's mishandling of the --status parameter's values.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Bumps github.com/cosmos/cosmos-sdk from 0.39.3 to 0.42.4.
Release notes
Sourced from github.com/cosmos/cosmos-sdk's releases.
... (truncated)
Changelog
Sourced from github.com/cosmos/cosmos-sdk's changelog.
... (truncated)
Commits
c4864e9
update changelog for v0.42.4 (#9083)13418f1
Backport #9081: bump tendermint core (#9082)c029a93
[Backport] fix: grpc-gateway error codes (#9015) (#9078)1e03826
[Backport] Add ledger/multisig detection in SignTx functions (#9026) (#9041)7648bfc
finalise release changelog and notes (#8987)4695808
Merge pull request from GHSA-2f3p-6gfj-jccq (#8985)8212771
Staking spec updates (bp #8843) (#8939)4749feb
update changelog8db5c2b
backport test detection ci fix (#8924) (#8942)c57f4cb
add +nobuild flags to all relevant test cases (bp #8934) (#8938)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)