This release includes a security fix for the light client and is recommended
for all users.
BUG FIXES
[light] Cross-check proposer priorities in retrieved validator sets
(#ASA-2024-009)
[privval] Ignore duplicate privval listen when already connected (#3828
DEPENDENCIES
[crypto/secp256k1] Adjust to breaking interface changes in
btcec/v2 latest release, while avoiding breaking changes to
local CometBFT functions
(#3728)
IMPROVEMENTS
[types] Check that proposer is one of the validators in ValidateBasic
(#ASA-2024-009)
[e2e] Add log_level option to manifest file
(#3819).
[e2e] Add log_format option to manifest file
(#3836).
v0.38.11
August 12, 2024
This release fixes a panic in consensus where CometBFT would previously panic
if there's no extension signature in non-nil Precommit EVEN IF vote extensions
themselves are disabled.
It also includes a few other bug fixes and performance improvements.
BUG FIXES
[types] Only check IFF vote is a non-nil Precommit if extensionsEnabled
types (#3565)
IMPROVEMENTS
[indexer] Fixed ineffective select break statements; they now
point to their enclosing for loop label to exit
(#3544)
[25.0] remove erroneous platform from image config OCI descriptor in docker save output. moby/moby#47695
[25.0 backport] Fix a nil dereference when getting image history for images having layers without the Created value set. moby/moby#47759
[25.0 backport] apparmor: Allow confined runc to kill containers. moby/moby#47830
[25.0 backport] Fix an issue where rapidly promoting a Swarm node after another node was demoted could cause the promoted node to fail its promotion. moby/moby#47869
[25.0 backport] don't depend on containerd platform.Parse to return a typed error. moby/moby#47890
This release contains a security fix for CVE-2024-29018, a potential data exfiltration from 'internal' networks via authoritative DNS servers.
Bug fixes and enhancements
CVE-2024-29018: Do not forward requests to external DNS servers for a container that is only connected to an 'internal' network. Previously, requests were forwarded if the host's DNS server was running on a loopback address, like systemd's 127.0.0.53. moby/moby#47589
plugin: fix mounting /etc/hosts when running in UserNS. moby/moby#47588
rootless: fix open /etc/docker/plugins: permission denied. moby/moby#47587
Fix multiple parallel docker build runs leaking disk space. moby/moby#47527
... (truncated)
Commits
b08a51f Merge pull request #48231 from austinvazquez/backport-vendor-otel-v0.46.1-to-...
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/onsonr/sonr/network/alerts).
Bumps the go_modules group with 2 updates in the /interchaintest directory: github.com/cometbft/cometbft and github.com/docker/docker.
Updates
github.com/cometbft/cometbft
from 0.38.8 to 0.38.12Release notes
Sourced from github.com/cometbft/cometbft's releases.
Changelog
Sourced from github.com/cometbft/cometbft's changelog.
... (truncated)
Commits
9722b6d
v0.38.12 (#3982)52c00a5
Merge commit from forkf2ae0f4
build(deps): Bump github.com/cosmos/gogoproto from 1.4.11 to 1.7.0 (#3912)cbedf6d
build(deps): Bump github.com/BurntSushi/toml from 1.2.1 to 1.4.0 (#3908)1013c80
test(mempool): Add twoUpdate
benchmarks (backport #3873) (#3892)2fb0cdd
build(deps): Bump github.com/rs/cors from 1.8.3 to 1.11.1 (#3907)dcbf359
build(deps): Bump github.com/Masterminds/semver/v3 from 3.2.0 to 3.3.0 (#3906)8de81d5
build(deps): Bump golang.org/x/net from 0.26.0 to 0.28.0 (#3905)221c744
fix(privval): CV ignore duplicate privval listen when connected (backport #38...969c8d1
mempool: Fix the benchmarks (backport #934) (#3893)Updates
github.com/docker/docker
from 24.0.9+incompatible to 25.0.6+incompatibleRelease notes
Sourced from github.com/docker/docker's releases.
... (truncated)
Commits
b08a51f
Merge pull request #48231 from austinvazquez/backport-vendor-otel-v0.46.1-to-...d151b0f
vendor: OTEL v0.46.1 / v1.21.0c6ba9a5
Merge pull request #48225 from austinvazquez/backport-workflow-artifact-reten...4673a3c
Merge pull request #48227 from austinvazquez/backport-backport-branch-check-t...30f8908
github/ci: Check if backport is opened against the expected branch7454d6a
ci: update workflow artifacts retention65cc597
Merge commit from forkb722836
Merge pull request #48199 from austinvazquez/update-containerd-binary-to-1.7.20e8ecb9c
update containerd binary to v1.7.20e6cae1f
update containerd binary to v1.7.19Updates
github.com/rs/cors
from 1.10.1 to 1.11.1Commits
a814d79
Re-add support for multiple Access-Control-Request-Headers field (fixes #184)...1562b17
Removed redundant log nil checks (#178)3d336ea
Update all dependencies to latest in examples (#175)85fc0ca
Make Gin wrapper's status configurable and use 204 as default (fixes #145) (#...4c32059
Normalize allowed request headers and store them in a sorted set (fixes #170)...8d33ca4
Complete documentation; deprecate AllowOriginRequestFunc in favour of AllowOr...af821ae
Merge branch 'jub0bs-master'0bcf73f
Update benchmarkeacc8e8
Fix skewed middleware benchmarks (#165)9297f15
Respect the documented precedence of options (#163)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show