-
-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): update all non-major dependencies #35
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate
bot
force-pushed
the
renovate/minor-all-minor-patch
branch
from
January 10, 2024 00:18
e380452
to
4340f07
Compare
renovate
bot
changed the title
chore(deps): update linuxserver/nextcloud docker tag to v27.1.4
chore(deps): update all non-major dependencies
Jan 10, 2024
renovate
bot
force-pushed
the
renovate/minor-all-minor-patch
branch
9 times, most recently
from
January 20, 2024 17:54
985f535
to
71c5a11
Compare
renovate
bot
changed the title
chore(deps): update all non-major dependencies
chore(deps): update linuxserver/nextcloud docker tag to v27.1.4
Jan 20, 2024
renovate
bot
force-pushed
the
renovate/minor-all-minor-patch
branch
from
January 21, 2024 10:28
71c5a11
to
7ca8e7c
Compare
renovate
bot
force-pushed
the
renovate/minor-all-minor-patch
branch
from
January 30, 2024 19:06
7ca8e7c
to
8d24d58
Compare
renovate
bot
changed the title
chore(deps): update linuxserver/nextcloud docker tag to v27.1.4
chore(deps): update all non-major dependencies
Jan 30, 2024
renovate
bot
force-pushed
the
renovate/minor-all-minor-patch
branch
4 times, most recently
from
February 4, 2024 14:43
ec6cad2
to
b414fff
Compare
renovate
bot
changed the title
chore(deps): update all non-major dependencies
chore(deps): update linuxserver/nextcloud docker tag to v27.1.4
Feb 4, 2024
renovate
bot
force-pushed
the
renovate/minor-all-minor-patch
branch
from
February 7, 2024 21:52
b414fff
to
e8f0151
Compare
renovate
bot
changed the title
chore(deps): update linuxserver/nextcloud docker tag to v27.1.4
chore(deps): update all non-major dependencies
Feb 7, 2024
renovate
bot
force-pushed
the
renovate/minor-all-minor-patch
branch
7 times, most recently
from
February 13, 2024 11:48
8e8c6ed
to
a26035e
Compare
renovate
bot
force-pushed
the
renovate/minor-all-minor-patch
branch
from
July 3, 2024 18:19
04cf400
to
c245edf
Compare
renovate
bot
changed the title
chore(deps): update mongo docker tag to v7.0.12
chore(deps): update all non-major dependencies
Jul 3, 2024
renovate
bot
changed the title
chore(deps): update all non-major dependencies
chore(deps): update all non-major dependencies - autoclosed
Jul 6, 2024
renovate
bot
changed the title
chore(deps): update all non-major dependencies - autoclosed
chore(deps): update all non-major dependencies
Jul 8, 2024
renovate
bot
force-pushed
the
renovate/minor-all-minor-patch
branch
from
July 8, 2024 15:44
c245edf
to
51ab726
Compare
renovate
bot
changed the title
chore(deps): update all non-major dependencies
chore(deps): update vectorim/element-web docker tag to v1.11.70
Jul 8, 2024
renovate
bot
changed the title
chore(deps): update vectorim/element-web docker tag to v1.11.70
chore(deps): update all non-major dependencies
Jul 9, 2024
renovate
bot
force-pushed
the
renovate/minor-all-minor-patch
branch
2 times, most recently
from
July 9, 2024 19:38
b3ebaf4
to
7e3efae
Compare
renovate
bot
changed the title
chore(deps): update all non-major dependencies
chore(deps): update all non-major dependencies - autoclosed
Jul 14, 2024
renovate
bot
changed the title
chore(deps): update all non-major dependencies - autoclosed
chore(deps): update all non-major dependencies
Jul 16, 2024
renovate
bot
force-pushed
the
renovate/minor-all-minor-patch
branch
3 times, most recently
from
July 21, 2024 15:40
8a52180
to
d931c06
Compare
renovate
bot
force-pushed
the
renovate/minor-all-minor-patch
branch
3 times, most recently
from
July 30, 2024 18:49
642b85e
to
4bae266
Compare
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
renovate
bot
force-pushed
the
renovate/minor-all-minor-patch
branch
from
July 30, 2024 21:55
4bae266
to
712a8e9
Compare
dr460nf1r3
approved these changes
Aug 4, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v1.110.0
->v1.112.0
2.317.0
->2.318.0
v1.11.70
->v1.11.72
Release Notes
element-hq/synapse (matrixdotorg/synapse)
v1.112.0
Compare Source
Synapse 1.112.0 (2024-07-30)
This security release is to update our locked dependency on Twisted to 24.7.0rc1, which includes a security fix for CVE-2024-41671 / GHSA-c8m8-j448-xjx7: Disordered HTTP pipeline response in twisted.web, again.
Note that this security fix is also available as Synapse 1.111.1, which does not include the rest of the changes in Synapse 1.112.0.
This issue means that, if multiple HTTP requests are pipelined in the same TCP connection, Synapse can send responses to the wrong HTTP request.
If a reverse proxy was configured to use HTTP pipelining, this could result in responses being sent to the wrong user, severely harming confidentiality.
With that said, despite being a high severity issue, we consider it unlikely that Synapse installations will be affected.
The use of HTTP pipelining in this fashion would cause worse performance for clients (request-response latencies would be increased as users' responses would be artificially blocked behind other users' slow requests). Further, Nginx and Haproxy, two common reverse proxies, do not appear to support configuring their upstreams to use HTTP pipelining and thus would not be affected. For both of these reasons, we consider it unlikely that a Synapse deployment would be set up in such a configuration.
Despite that, we cannot rule out that some installations may exist with this unusual setup and so we are releasing this security update today.
pip users: Note that by default, upgrading Synapse using pip will not automatically upgrade Twisted. Please manually install the new version of Twisted using
pip install Twisted==24.7.0rc1
. Note also that even the--upgrade-strategy=eager
flag topip install -U matrix-synapse
will not upgrade Twisted to a patched version because it is only a release candidate at this time.Internal Changes
Synapse 1.112.0rc1 (2024-07-23)
Please note that this release candidate does not include the security dependency update
included in version 1.111.1 as this version was released before 1.111.1.
The same security fix can be found in the full release of 1.112.0.
Features
/sync
endpoint. (#17416)name
/avatar
fields in experimental MSC3575 Sliding Sync/sync
endpoint. (#17418)heroes
and room summary fields (joined_count
,invited_count
) in experimental MSC3575 Sliding Sync/sync
endpoint. (#17419)is_dm
room field in experimental MSC3575 Sliding Sync/sync
endpoint. (#17429)/sync
endpoint. (#17432)/sync
endpoint. (#17454)Bugfixes
/sync
endpoint when using room type filters and the user has one or more remote invites. (#17434)heroes
bystream_ordering
as the Matrix specification states (applies to/sync
). (#17435)/sync
would break for a user when using workers with multiple stream writers. (#17438)Improved Documentation
default_power_level_content_override
config option. (#17451)Internal Changes
RateLimiter.record_action
. (#17426)/sync
endpoint to bump room when it is created. (#17453)get_rooms_for_local_user_where_membership_is
to speed up sliding sync. (#17460)$ME
as a state key in sliding sync. (#17469)Updates to locked dependencies
v1.111.1
Compare Source
Synapse 1.111.1 (2024-07-30)
This security release is to update our locked dependency on Twisted to 24.7.0rc1, which includes a security fix for CVE-2024-41671 / GHSA-c8m8-j448-xjx7: Disordered HTTP pipeline response in twisted.web, again.
This issue means that, if multiple HTTP requests are pipelined in the same TCP connection, Synapse can send responses to the wrong HTTP request.
If a reverse proxy was configured to use HTTP pipelining, this could result in responses being sent to the wrong user, severely harming confidentiality.
With that said, despite being a high severity issue, we consider it unlikely that Synapse installations will be affected.
The use of HTTP pipelining in this fashion would cause worse performance for clients (request-response latencies would be increased as users' responses would be artificially blocked behind other users' slow requests). Further, Nginx and Haproxy, two common reverse proxies, do not appear to support configuring their upstreams to use HTTP pipelining and thus would not be affected. For both of these reasons, we consider it unlikely that a Synapse deployment would be set up in such a configuration.
Despite that, we cannot rule out that some installations may exist with this unusual setup and so we are releasing this security update today.
pip users: Note that by default, upgrading Synapse using pip will not automatically upgrade Twisted. Please manually install the new version of Twisted using
pip install Twisted==24.7.0rc1
. Note also that even the--upgrade-strategy=eager
flag topip install -U matrix-synapse
will not upgrade Twisted to a patched version because it is only a release candidate at this time.Internal Changes
v1.111.0
Compare Source
Synapse 1.111.0 (2024-07-16)
No significant changes since 1.111.0rc2.
Synapse 1.111.0rc2 (2024-07-10)
Bugfixes
synapse.app.media_repository
worker configuration would break the new media endpoints. (#17420)Improved Documentation
Internal Changes
Synapse 1.111.0rc1 (2024-07-09)
Features
rooms
data to experimental MSC3575 Sliding Sync/sync
endpoint. (#17320)room_types
/not_room_types
filtering to experimental MSC3575 Sliding Sync/sync
endpoint. (#17337)/sync
endpoint. (#17342)_matrix/client/v1/media/download
endpoint. (#17365)by adding
_matrix/client/v1/media/thumbnail
,_matrix/federation/v1/media/thumbnail
endpoints and stabilizing theremaining
_matrix/client/v1/media
endpoints. (#17388)rooms.bump_stamp
for easier client-side sorting in experimental MSC3575 Sliding Sync/sync
endpoint. (#17395)Bugfixes
/sync
endpoint when using an old database. (#17398)Improved Documentation
url_preview_url_blacklist
is a usability feature. (#17356)Internal Changes
ruff
version. (#17381, #17411)Updates to locked dependencies
element-hq/element-web (vectorim/element-web)
v1.11.72
Compare Source
✨ Features
widget_build_url_ignore_dm
with call behaviour switch between 1:1 and Widget (#12760). Contributed by @t3chguy.🐛 Bug Fixes
v1.11.71
Compare Source
✨ Features
🐛 Bug Fixes
Match system theme
toggle (#12719). Contributed by @florianduros.Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.