chore: update dependencies - #438
Draft
renovate[bot] wants to merge 1 commit into
Draft
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/dependencies
branch
2 times, most recently
from
March 7, 2025 10:49
1d5ed39 to
b460bd6
Compare
renovate
Bot
force-pushed
the
renovate/dependencies
branch
4 times, most recently
from
March 14, 2025 23:26
4274135 to
ff37e3d
Compare
renovate
Bot
force-pushed
the
renovate/dependencies
branch
2 times, most recently
from
March 21, 2025 10:11
8f606c5 to
7a78a37
Compare
renovate
Bot
force-pushed
the
renovate/dependencies
branch
from
March 21, 2025 12:12
7a78a37 to
6afeb46
Compare
renovate
Bot
force-pushed
the
renovate/dependencies
branch
2 times, most recently
from
March 26, 2025 08:03
d0c7eed to
5dd4665
Compare
renovate
Bot
force-pushed
the
renovate/dependencies
branch
5 times, most recently
from
April 4, 2025 08:02
21dffca to
3e5cc30
Compare
renovate
Bot
force-pushed
the
renovate/dependencies
branch
5 times, most recently
from
April 10, 2025 19:25
9e4e461 to
50b1227
Compare
renovate
Bot
force-pushed
the
renovate/dependencies
branch
from
April 12, 2025 19:44
50b1227 to
6f25a6c
Compare
renovate
Bot
force-pushed
the
renovate/dependencies
branch
from
May 24, 2025 11:59
2d246a1 to
fa24ade
Compare
renovate
Bot
force-pushed
the
renovate/dependencies
branch
4 times, most recently
from
June 6, 2025 10:50
e911e58 to
45f5a9b
Compare
renovate
Bot
force-pushed
the
renovate/dependencies
branch
3 times, most recently
from
June 15, 2025 07:57
80f9be9 to
368bed7
Compare
renovate
Bot
force-pushed
the
renovate/dependencies
branch
from
June 28, 2025 08:11
368bed7 to
1e32b7e
Compare
renovate
Bot
force-pushed
the
renovate/dependencies
branch
3 times, most recently
from
July 8, 2025 19:49
e29bbcf to
22d416a
Compare
renovate
Bot
force-pushed
the
renovate/dependencies
branch
4 times, most recently
from
July 16, 2025 14:09
62e43ac to
7c60459
Compare
renovate
Bot
force-pushed
the
renovate/dependencies
branch
from
July 27, 2025 16:00
7c60459 to
df0fcb8
Compare
renovate
Bot
force-pushed
the
renovate/dependencies
branch
4 times, most recently
from
August 7, 2025 12:34
61fd535 to
777ba2e
Compare
renovate
Bot
force-pushed
the
renovate/dependencies
branch
4 times, most recently
from
August 16, 2025 03:13
5ce8a27 to
f5f2e7b
Compare
renovate
Bot
force-pushed
the
renovate/dependencies
branch
2 times, most recently
from
August 24, 2025 23:14
70132b5 to
1edeced
Compare
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Update Request | Renovate Bot
This PR contains the following updates:
10.48→10.492.3.2→2.3.32.55.0→2.56.02.42.3→2.42.41.14→1.154.4.3→4.4.42_8_4→2_8_5v1.52.1→v1.53.022.1.8→23.1.21.12.0→1.12.13.6.4→4.0.33.0.3→3.0.43.14.7→3.14.8v0.6.3→v0.6.4Release Notes
PCRE2Project/pcre2 (PCRE2Project/pcre2)
v10.49Compare Source
arbitrary data. Applications are only affected if using the
pcre2_jit_stack_create() and pcre2_jit_stack_assign() APIs to provide a growable
JIT stack, and then matching against a pattern with unusually high JIT stack
usage, such as a large number of capturing groups.
The implications of an out-of-bounds write could include arbitrary code
execution.
The issue is not a regression and affects releases 10.48 and earlier.
davea42/libdwarf-code (davea42/libdwarf-code)
v2.3.3Compare Source
Fixes a bug reading MacOS 64bit universal object.
Fixes a bug reading Elf SHF_COMPRESSED sections
in 64bit object files.
Fixes a test of a .debug_str section read to
validate a section offset before adding to a local pointer
(it matters with 32bit pointer machines reading certain corrupt Elf object files).
Includes a change in builds using cmake which
does not require any changes to your cmake builds
(see READMEcmake.md for details).
cmake/cmake (https://gitlab.kitware.com/cmake/cmake.git)
v4.4.4Compare Source
libexpat/libexpat (libexpat/libexpat)
v2_8_5: 2.8.5Compare Source
libuv/libuv (libuv/libuv)
v1.53.0: : 2026.09.24, Version 1.53.0 (Stable)Compare Source
Dist files at https://dist.libuv.org/dist/v1.53.0/
What's Changed
70f4deetoe89f39fby @dependabot[bot] in #5166New Contributors
Full Changelog: libuv/libuv@v1.52.1...v1.53.0
llvm/llvm-project (llvm/llvm-project)
v23.1.2: LLVM 23.1.2Compare Source
LLVM 23.1.2 Release
Download links for common platforms will appear above once builds have completed, if they are available. Check the full list of release packages at the bottom of this release page if you do not find a link above.
If you do not find a release package for your platform, you may be able to find a community built package on the LLVM Discourse forum thread for this release. Remember that these are built by volunteers and may not always be available. If you rely on a platform or configuration that is not one of the defaults, we suggest you use the binaries that your platform provides, or build your own release packages.
Package Types
Each platform has binary release packages. The file name starts with either
LLVM-orclang+llvm-and ends with the platform's name. For example,LLVM-23.1.2-Linux-ARM64.tar.xzcontains LLVM binaries for Arm64 Linux. Binary archive packages may be available as.tar.xzor.tar.zstfiles. The.tar.zstfiles contain the same package contents, but use zstd compression.Except for Windows. Where
LLVM-*.msiis an installer intended for using LLVM as a toolchain and the archiveclang+llvm-contains the contents of the installer, plus libraries and tools not normally used in a toolchain. You most likely want theLLVM-installer, unless you are developing software which itself uses LLVM, in which case chooseclang+llvm-.In addition, source archives are available:
llvm-projectsource code for this release, choosellvm-project-23.1.2.src.tar.xz.test-suite-23.1.2.src.tar.xzis an archive of the LLVM Test Suite) for this release.Verifying Packages
All packages come with a matching
.sigand/or.jsonlfile. You should use these to verify the integrity of the packages.If it has a
.sigfile, it should have been signed by the release managers using GPG. Download the keys from the LLVM website, import them into your keyring and use them to verify the file:If it has a
.jsonlfile, use gh to verify the package:v23.1.1: LLVM 23.1.1Compare Source
LLVM 23.1.1 Release
Download links for common platforms will appear above once builds have completed, if they are available. Check the full list of release packages at the bottom of this release page if you do not find a link above.
If you do not find a release package for your platform, you may be able to find a community built package on the LLVM Discourse forum thread for this release. Remember that these are built by volunteers and may not always be available. If you rely on a platform or configuration that is not one of the defaults, we suggest you use the binaries that your platform provides, or build your own release packages.
Package Types
Each platform has binary release packages. The file name starts with either
LLVM-orclang+llvm-and ends with the platform's name. For example,LLVM-23.1.1-Linux-ARM64.tar.xzcontains LLVM binaries for Arm64 Linux. Binary archive packages may be available as.tar.xzor.tar.zstfiles. The.tar.zstfiles contain the same package contents, but use zstd compression.Except for Windows. Where
LLVM-*.msiis an installer intended for using LLVM as a toolchain and the archiveclang+llvm-contains the contents of the installer, plus libraries and tools not normally used in a toolchain. You most likely want theLLVM-installer, unless you are developing software which itself uses LLVM, in which case chooseclang+llvm-.In addition, source archives are available:
llvm-projectsource code for this release, choosellvm-project-23.1.1.src.tar.xz.test-suite-23.1.1.src.tar.xzis an archive of the LLVM Test Suite) for this release.Verifying Packages
All packages come with a matching
.sigand/or.jsonlfile. You should use these to verify the integrity of the packages.If it has a
.sigfile, it should have been signed by the release managers using GPG. Download the keys from the LLVM website, import them into your keyring and use them to verify the file:If it has a
.jsonlfile, use gh to verify the package:v23.1.0: LLVM 23.1.0Compare Source
LLVM 23.1.0 Release
Download links for common platforms will appear above once builds have completed, if they are available. Check the full list of release packages at the bottom of this release page if you do not find a link above.
If you do not find a release package for your platform, you may be able to find a community built package on the LLVM Discourse forum thread for this release. Remember that these are built by volunteers and may not always be available. If you rely on a platform or configuration that is not one of the defaults, we suggest you use the binaries that your platform provides, or build your own release packages.
Package Types
Each platform has binary release packages. The file name starts with either
LLVM-orclang+llvm-and ends with the platform's name. For example,LLVM-23.1.0-Linux-ARM64.tar.xzcontains LLVM binaries for Arm64 Linux. Binary archive packages may be available as.tar.xzor.tar.zstfiles. The.tar.zstfiles contain the same package contents, but use zstd compression.Except for Windows. Where
LLVM-*.msiis an installer intended for using LLVM as a toolchain and the archiveclang+llvm-contains the contents of the installer, plus libraries and tools not normally used in a toolchain. You most likely want theLLVM-installer, unless you are developing software which itself uses LLVM, in which case chooseclang+llvm-.In addition, source archives are available:
llvm-projectsource code for this release, choosellvm-project-23.1.0.src.tar.xz.test-suite-23.1.0.src.tar.xzis an archive of the LLVM Test Suite) for this release.Verifying Packages
All packages come with a matching
.sigand/or.jsonlfile. You should use these to verify the integrity of the packages.If it has a
.sigfile, it should have been signed by the release managers using GPG. Download the keys from the LLVM website, import them into your keyring and use them to verify the file:If it has a
.jsonlfile, use gh to verify the package:mesonbuild/meson (mesonbuild/meson)
v1.12.1Compare Source
openssl/openssl (openssl/openssl)
v4.0.3: OpenSSL 4.0.3Compare Source
OpenSSL 4.0.3 is a security patch release. The most severe CVE fixed
in this release is High.
This release incorporates the following bug fixes and mitigations:
Fixed DTLS retransmissions of handshake messages from a stale buffer offset.
(CVE-2026-84782)
Fixed a use-after-free in X.509 extension cache under concurrent use.
(CVE-2026-84783)
Fixed excessive memory allocation in relative CRLDP processing.
(CVE-2026-35189)
Fixed QUIC unvalidated amplification credit may be over-accounted.
(CVE-2026-35191)
Fixed potential CPU DoS via O(n^2) fragment reassembly in QUIC.
(CVE-2026-42772)
Fixed a timing side-channel in scalar multiplication for mon-NIST EC curves.
(CVE-2026-54872)
Fixed QUIC
STREAMfragment metadata DoS.(CVE-2026-54873)
Fixed non-constant-time SM2 scalar multiplication on ARM64 and RISC-V.
(CVE-2026-54875)
Fixed out-of-bounds access after
SSL_set_SSL_CTX()during a handshake.(CVE-2026-72897)
Fixed QUIC connection-level flow control was not enforced for streams.
(CVE-2026-75804)
Fixed a NULL pointer dereference in CMP client revocation response handling.
(CVE-2026-75805)
Fixed an unauthenticated and undersized DTLS 1.2 AEAD record causing DoS.
(CVE-2026-75806)
Fixed a timing side-channel in SM2 signature generation.
(CVE-2026-77696)
Fixed an unbounded
RETIRE_CONNECTION_IDbacklog in QUIC stackimplementation.
(CVE-2026-84784)
Fixed a bug where
EVP_DecryptFinal()incorrectly reported a stale successon AES-SIV authentication failure.
Fixed a regression in base64 encoding BIO filter introduced in OpenSSL 4.0,
where incomplete writes down the BIO chain may result in the loss of encoded
base64 data.
v4.0.2Compare Source
Fixed QUIC server being able to trigger double free when processing
INITIALpacket.
Severity: Moderate
Issue summary: QUIC server may double free QRX (QUIC record layer RX) object
when channel creation fails for initial packet.
Impact summary: Double free leads to heap corruption, which typically results
in termination of QUIC server process, leading to a Denial of Service.
There is so far no evidence that this double free is exploitable for remote
code execution, thus it is considered highly improbable.
Reported by: Fuzz0x (ZKSC Institute of Security Research), Emilio Galle,
and Feng Xue (ThreatBoon).
([CVE-2026-18798])
Alexandr Nedvědický
Fixed heap buffer overflow in CMS key unwrapping.
Severity: Moderate
Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer
based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap
primitive can write and cleanse more bytes than that query reports, causing
an 8-byte out-of-bounds heap write.
Impact summary: An attacker who supplies a crafted CMS message can trigger
a deterministic 8-byte out-of-bounds heap write when the victim decrypts it
with
CMS_decrypt(), corrupting the heap and typically resulting in a Denialof Service.
Reported by: Bhabani Sankar Das and Filipe Casal (Trail of Bits).
([CVE-2026-63072])
Daniel Kubec
Fixed invalid pointer dereference in CMP server via c
Configuration
📅 Schedule: (UTC)
* 0-4,22-23 * * 1-5)* * * * 0,6)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.