This release supersedes v0.38.14, which mistakenly updated the Go version to
1.23, introducing an unintended breaking change. It sets the Go version back
to 1.22.7 by reverting #4297.
The release includes the bug fixes, performance improvements, and importantly,
the fix for the security vulnerability in the vote extensions (VE) validation
logic that were part of v0.38.14. For more details, please refer to ASA-2024-011.
v0.38.14
November 6, 2024
This release fixes a security vulnerability in the vote extensions (VE)
validation logic. For more details, please refer to
ASA-2024-011.
We recommend upgrading ASAP if you’re using vote extensions (VE).
BUG FIXES
[consensus] Do not panic if the validator index of a Vote message is out
of bounds, when vote extensions are enabled
(#ABC-0021)
[p2p] fix exponential backoff logic to increase reconnect retries close to 24 hours
(#3519)
v0.38.13
October 24, 2024
This patch release addresses the issue where tx_search was not returning all results, which only arises when upgrading
to CometBFT-DB version 0.13 or later. It includes a fix in the state indexer to resolve this problem. We recommend
upgrading to this patch release if you are affected by this issue.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/palomachain/paloma/network/alerts).
Bumps github.com/cometbft/cometbft from 0.38.12 to 0.38.15.
Release notes
Sourced from github.com/cometbft/cometbft's releases.
Changelog
Sourced from github.com/cometbft/cometbft's changelog.
... (truncated)
Commits
e8eb5bd
Release v0.38.15 (#4447)f58e4b0
Retract v0.38.14 (#4446)17d3bb6
Revert "chore: use the latest cometbft-db in v0.38.x (#4297)" (#4442)d8980f9
test: fix TestStateDoesntCrashOnInvalidVote (#4439)ce0949e
build: v0.38.14 (#4437)3a023da
Merge commit from forkdeef97f
fix(p2p): adjust backoff seconds to increase reconnect retries close to 24 ho...28a308f
chore: use the latest cometbft-db in v0.38.x (#4297)c71de55
build(deps): Bump bufbuild/buf-setup-action from 1.45.0 to 1.46.0 (#4414)ab9cc83
build(deps): Bump golang.org/x/net from 0.29.0 to 0.30.0 (#4384)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show