Skip to content

chore: update dependencies - #438

Draft
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/dependencies
Draft

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/dependencies

Conversation

@renovate

@renovate renovate Bot commented Mar 5, 2025 •

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

Update Request | Renovate Bot

This PR contains the following updates:

Package Update Change
PCRE2Project/pcre2 minor 10.48 → 10.49
davea42/libdwarf-code patch 2.3.2 → 2.3.3
git://git.kernel.org/pub/scm/git/git.git minor 2.55.0 → 2.56.0
git://git.kernel.org/pub/scm/utils/util-linux/util-linux.git patch 2.42.3 → 2.42.4
git://git.savannah.gnu.org/gzip.git minor 1.14 → 1.15
https://gitlab.kitware.com/cmake/cmake.git patch 4.4.3 → 4.4.4
libexpat/libexpat patch 2_8_4 → 2_8_5
libuv/libuv minor v1.52.1 → v1.53.0
llvm/llvm-project major 22.1.8 → 23.1.2
mesonbuild/meson patch 1.12.0 → 1.12.1
openssl/openssl major 3.6.4 → 4.0.3
pallets/markupsafe patch 3.0.3 → 3.0.4
python/cpython patch 3.14.7 → 3.14.8
siderolabs/bldr patch v0.6.3 → v0.6.4

Release Notes

PCRE2Project/pcre2 (PCRE2Project/pcre2)

v10.49

Compare Source

  1. (GHSA-r9hj-j2rw-4q3m) Security fix to prevent an out-of-bounds write with
    arbitrary data. Applications are only affected if using the
    pcre2_jit_stack_create() and pcre2_jit_stack_assign() APIs to provide a growable
    JIT stack, and then matching against a pattern with unusually high JIT stack
    usage, such as a large number of capturing groups.

The implications of an out-of-bounds write could include arbitrary code
execution.

The issue is not a regression and affects releases 10.48 and earlier.

davea42/libdwarf-code (davea42/libdwarf-code)

v2.3.3

Compare Source

Fixes a bug reading MacOS 64bit universal object.
Fixes a bug reading Elf SHF_COMPRESSED sections
in 64bit object files.
Fixes a test of a .debug_str section read to
validate a section offset before adding to a local pointer
(it matters with 32bit pointer machines reading certain corrupt Elf object files).
Includes a change in builds using cmake which
does not require any changes to your cmake builds
(see READMEcmake.md for details).

cmake/cmake (https://gitlab.kitware.com/cmake/cmake.git)

v4.4.4

Compare Source

libexpat/libexpat (libexpat/libexpat)

v2_8_5: 2.8.5

Compare Source

libuv/libuv (libuv/libuv)

v1.53.0: : 2026.09.24, Version 1.53.0 (Stable)

Compare Source

Dist files at https://dist.libuv.org/dist/v1.53.0/

What's Changed

New Contributors

Full Changelog: libuv/libuv@v1.52.1...v1.53.0

llvm/llvm-project (llvm/llvm-project)

v23.1.2: LLVM 23.1.2

Compare Source

LLVM 23.1.2 Release

Download links for common platforms will appear above once builds have completed, if they are available. Check the full list of release packages at the bottom of this release page if you do not find a link above.

If you do not find a release package for your platform, you may be able to find a community built package on the LLVM Discourse forum thread for this release. Remember that these are built by volunteers and may not always be available. If you rely on a platform or configuration that is not one of the defaults, we suggest you use the binaries that your platform provides, or build your own release packages.

Package Types

Each platform has binary release packages. The file name starts with either LLVM- or clang+llvm- and ends with the platform's name. For example, LLVM-23.1.2-Linux-ARM64.tar.xz contains LLVM binaries for Arm64 Linux. Binary archive packages may be available as .tar.xz or .tar.zst files. The .tar.zst files contain the same package contents, but use zstd compression.

Except for Windows. Where LLVM-*.msi is an installer intended for using LLVM as a toolchain and the archive clang+llvm- contains the contents of the installer, plus libraries and tools not normally used in a toolchain. You most likely want the LLVM- installer, unless you are developing software which itself uses LLVM, in which case choose clang+llvm-.

In addition, source archives are available:

  • To get all the llvm-project source code for this release, choose llvm-project-23.1.2.src.tar.xz.
  • test-suite-23.1.2.src.tar.xz is an archive of the LLVM Test Suite) for this release.

Verifying Packages

All packages come with a matching .sig and/or .jsonl file. You should use these to verify the integrity of the packages.

If it has a .sig file, it should have been signed by the release managers using GPG. Download the keys from the LLVM website, import them into your keyring and use them to verify the file:

$ gpg --import release-keys.asc
$ gpg --verify <package file name>.sig <package file name>

If it has a .jsonl file, use gh to verify the package:

$ gh attestation verify --repo llvm/llvm-project <package file name>
(if you are able to connect to GitHub)
$ gh attestation verify --repo llvm/llvm-project <package file name> --bundle <package file name>.jsonl
(using attestation file on disk)

v23.1.1: LLVM 23.1.1

Compare Source

LLVM 23.1.1 Release

Download links for common platforms will appear above once builds have completed, if they are available. Check the full list of release packages at the bottom of this release page if you do not find a link above.

If you do not find a release package for your platform, you may be able to find a community built package on the LLVM Discourse forum thread for this release. Remember that these are built by volunteers and may not always be available. If you rely on a platform or configuration that is not one of the defaults, we suggest you use the binaries that your platform provides, or build your own release packages.

Package Types

Each platform has binary release packages. The file name starts with either LLVM- or clang+llvm- and ends with the platform's name. For example, LLVM-23.1.1-Linux-ARM64.tar.xz contains LLVM binaries for Arm64 Linux. Binary archive packages may be available as .tar.xz or .tar.zst files. The .tar.zst files contain the same package contents, but use zstd compression.

Except for Windows. Where LLVM-*.msi is an installer intended for using LLVM as a toolchain and the archive clang+llvm- contains the contents of the installer, plus libraries and tools not normally used in a toolchain. You most likely want the LLVM- installer, unless you are developing software which itself uses LLVM, in which case choose clang+llvm-.

In addition, source archives are available:

  • To get all the llvm-project source code for this release, choose llvm-project-23.1.1.src.tar.xz.
  • test-suite-23.1.1.src.tar.xz is an archive of the LLVM Test Suite) for this release.

Verifying Packages

All packages come with a matching .sig and/or .jsonl file. You should use these to verify the integrity of the packages.

If it has a .sig file, it should have been signed by the release managers using GPG. Download the keys from the LLVM website, import them into your keyring and use them to verify the file:

$ gpg --import release-keys.asc
$ gpg --verify <package file name>.sig <package file name>

If it has a .jsonl file, use gh to verify the package:

$ gh attestation verify --repo llvm/llvm-project <package file name>
(if you are able to connect to GitHub)
$ gh attestation verify --repo llvm/llvm-project <package file name> --bundle <package file name>.jsonl
(using attestation file on disk)

v23.1.0: LLVM 23.1.0

Compare Source

LLVM 23.1.0 Release

Download links for common platforms will appear above once builds have completed, if they are available. Check the full list of release packages at the bottom of this release page if you do not find a link above.

If you do not find a release package for your platform, you may be able to find a community built package on the LLVM Discourse forum thread for this release. Remember that these are built by volunteers and may not always be available. If you rely on a platform or configuration that is not one of the defaults, we suggest you use the binaries that your platform provides, or build your own release packages.

Package Types

Each platform has binary release packages. The file name starts with either LLVM- or clang+llvm- and ends with the platform's name. For example, LLVM-23.1.0-Linux-ARM64.tar.xz contains LLVM binaries for Arm64 Linux. Binary archive packages may be available as .tar.xz or .tar.zst files. The .tar.zst files contain the same package contents, but use zstd compression.

Except for Windows. Where LLVM-*.msi is an installer intended for using LLVM as a toolchain and the archive clang+llvm- contains the contents of the installer, plus libraries and tools not normally used in a toolchain. You most likely want the LLVM- installer, unless you are developing software which itself uses LLVM, in which case choose clang+llvm-.

In addition, source archives are available:

  • To get all the llvm-project source code for this release, choose llvm-project-23.1.0.src.tar.xz.
  • test-suite-23.1.0.src.tar.xz is an archive of the LLVM Test Suite) for this release.

Verifying Packages

All packages come with a matching .sig and/or .jsonl file. You should use these to verify the integrity of the packages.

If it has a .sig file, it should have been signed by the release managers using GPG. Download the keys from the LLVM website, import them into your keyring and use them to verify the file:

$ gpg --import release-keys.asc
$ gpg --verify <package file name>.sig <package file name>

If it has a .jsonl file, use gh to verify the package:

$ gh attestation verify --repo llvm/llvm-project <package file name>
(if you are able to connect to GitHub)
$ gh attestation verify --repo llvm/llvm-project <package file name> --bundle <package file name>.jsonl
(using attestation file on disk)
mesonbuild/meson (mesonbuild/meson)

v1.12.1

Compare Source

openssl/openssl (openssl/openssl)

v4.0.3: OpenSSL 4.0.3

Compare Source

OpenSSL 4.0.3 is a security patch release. The most severe CVE fixed
in this release is High.

This release incorporates the following bug fixes and mitigations:

  • Fixed DTLS retransmissions of handshake messages from a stale buffer offset.
    (CVE-2026-84782)

  • Fixed a use-after-free in X.509 extension cache under concurrent use.
    (CVE-2026-84783)

  • Fixed excessive memory allocation in relative CRLDP processing.
    (CVE-2026-35189)

  • Fixed QUIC unvalidated amplification credit may be over-accounted.
    (CVE-2026-35191)

  • Fixed potential CPU DoS via O(n^2) fragment reassembly in QUIC.
    (CVE-2026-42772)

  • Fixed a timing side-channel in scalar multiplication for mon-NIST EC curves.
    (CVE-2026-54872)

  • Fixed QUIC STREAM fragment metadata DoS.
    (CVE-2026-54873)

  • Fixed non-constant-time SM2 scalar multiplication on ARM64 and RISC-V.
    (CVE-2026-54875)

  • Fixed out-of-bounds access after SSL_set_SSL_CTX() during a handshake.
    (CVE-2026-72897)

  • Fixed QUIC connection-level flow control was not enforced for streams.
    (CVE-2026-75804)

  • Fixed a NULL pointer dereference in CMP client revocation response handling.
    (CVE-2026-75805)

  • Fixed an unauthenticated and undersized DTLS 1.2 AEAD record causing DoS.
    (CVE-2026-75806)

  • Fixed a timing side-channel in SM2 signature generation.
    (CVE-2026-77696)

  • Fixed an unbounded RETIRE_CONNECTION_ID backlog in QUIC stack
    implementation.
    (CVE-2026-84784)

  • Fixed a bug where EVP_DecryptFinal() incorrectly reported a stale success
    on AES-SIV authentication failure.

  • Fixed a regression in base64 encoding BIO filter introduced in OpenSSL 4.0,
    where incomplete writes down the BIO chain may result in the loss of encoded
    base64 data.

v4.0.2

Compare Source

  • Fixed QUIC server being able to trigger double free when processing INITIAL
    packet.

    Severity: Moderate

    Issue summary: QUIC server may double free QRX (QUIC record layer RX) object
    when channel creation fails for initial packet.

    Impact summary: Double free leads to heap corruption, which typically results
    in termination of QUIC server process, leading to a Denial of Service.
    There is so far no evidence that this double free is exploitable for remote
    code execution, thus it is considered highly improbable.

    Reported by: Fuzz0x (ZKSC Institute of Security Research), Emilio Galle,
    and Feng Xue (ThreatBoon).

    ([CVE-2026-18798])

    Alexandr Nedvědický

  • Fixed heap buffer overflow in CMS key unwrapping.

    Severity: Moderate

    Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer
    based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap
    primitive can write and cleanse more bytes than that query reports, causing
    an 8-byte out-of-bounds heap write.

    Impact summary: An attacker who supplies a crafted CMS message can trigger
    a deterministic 8-byte out-of-bounds heap write when the victim decrypts it
    with CMS_decrypt(), corrupting the heap and typically resulting in a Denial
    of Service.

    Reported by: Bhabani Sankar Das and Filipe Casal (Trail of Bits).

    ([CVE-2026-63072])

    Daniel Kubec

  • Fixed invalid pointer dereference in CMP server via c

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At 12:00 AM through 04:59 AM and 10:00 PM through 11:59 PM, Monday through Friday (* 0-4,22-23 * * 1-5)
    • Only on Sunday and Saturday (* * * * 0,6)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-project-automation github-project-automation Bot moved this to To Do in Planning Mar 5, 2025
@talos-bot talos-bot moved this from To Do to In Review in Planning Mar 5, 2025
@smira smira removed this from Planning Mar 5, 2025
@renovate renovate Bot changed the title chore: update dependencies chore: update dependency git://git.kernel.org/pub/scm/utils/kernel/kmod/kmod.git to v34 Mar 5, 2025
@renovate
renovate Bot force-pushed the renovate/dependencies branch 2 times, most recently from 1d5ed39 to b460bd6 Compare March 7, 2025 10:49
@renovate renovate Bot changed the title chore: update dependency git://git.kernel.org/pub/scm/utils/kernel/kmod/kmod.git to v34 chore: update dependencies Mar 7, 2025
@renovate
renovate Bot force-pushed the renovate/dependencies branch 4 times, most recently from 4274135 to ff37e3d Compare March 14, 2025 23:26
@renovate
renovate Bot force-pushed the renovate/dependencies branch 2 times, most recently from 8f606c5 to 7a78a37 Compare March 21, 2025 10:11
@renovate renovate Bot changed the title chore: update dependencies chore: update dependency swig/swig to v4.3.0 Mar 21, 2025
@renovate
renovate Bot force-pushed the renovate/dependencies branch from 7a78a37 to 6afeb46 Compare March 21, 2025 12:12
@renovate renovate Bot changed the title chore: update dependency swig/swig to v4.3.0 chore: update dependencies Mar 21, 2025
@renovate
renovate Bot force-pushed the renovate/dependencies branch 2 times, most recently from d0c7eed to 5dd4665 Compare March 26, 2025 08:03
@renovate
renovate Bot force-pushed the renovate/dependencies branch 5 times, most recently from 21dffca to 3e5cc30 Compare April 4, 2025 08:02
@renovate
renovate Bot force-pushed the renovate/dependencies branch 5 times, most recently from 9e4e461 to 50b1227 Compare April 10, 2025 19:25
@renovate
renovate Bot force-pushed the renovate/dependencies branch from 50b1227 to 6f25a6c Compare April 12, 2025 19:44
@renovate
renovate Bot force-pushed the renovate/dependencies branch from 2d246a1 to fa24ade Compare May 24, 2025 11:59
@renovate
renovate Bot force-pushed the renovate/dependencies branch 4 times, most recently from e911e58 to 45f5a9b Compare June 6, 2025 10:50
@renovate
renovate Bot force-pushed the renovate/dependencies branch 3 times, most recently from 80f9be9 to 368bed7 Compare June 15, 2025 07:57
@renovate
renovate Bot force-pushed the renovate/dependencies branch from 368bed7 to 1e32b7e Compare June 28, 2025 08:11
@renovate
renovate Bot force-pushed the renovate/dependencies branch 3 times, most recently from e29bbcf to 22d416a Compare July 8, 2025 19:49
@renovate
renovate Bot force-pushed the renovate/dependencies branch 4 times, most recently from 62e43ac to 7c60459 Compare July 16, 2025 14:09
@renovate
renovate Bot force-pushed the renovate/dependencies branch from 7c60459 to df0fcb8 Compare July 27, 2025 16:00
@renovate
renovate Bot force-pushed the renovate/dependencies branch 4 times, most recently from 61fd535 to 777ba2e Compare August 7, 2025 12:34
@renovate
renovate Bot force-pushed the renovate/dependencies branch 4 times, most recently from 5ce8a27 to f5f2e7b Compare August 16, 2025 03:13
@renovate
renovate Bot force-pushed the renovate/dependencies branch 2 times, most recently from 70132b5 to 1edeced Compare August 24, 2025 23:14
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants