Skip to content
This repository was archived by the owner on Nov 16, 2022. It is now read-only.

⬆️ Bump github.com/ethereum/go-ethereum from 1.9.19 to 1.9.25 in /chain#2988

Closed
dependabot-preview[bot] wants to merge 1 commit intomasterfrom
dependabot/go_modules/chain/github.com/ethereum/go-ethereum-1.9.25
Closed

⬆️ Bump github.com/ethereum/go-ethereum from 1.9.19 to 1.9.25 in /chain#2988
dependabot-preview[bot] wants to merge 1 commit intomasterfrom
dependabot/go_modules/chain/github.com/ethereum/go-ethereum-1.9.25

Conversation

@dependabot-preview
Copy link
Copy Markdown
Contributor

@dependabot-preview dependabot-preview bot commented Dec 13, 2020

Bumps github.com/ethereum/go-ethereum from 1.9.19 to 1.9.25.

Release notes

Sourced from github.com/ethereum/go-ethereum's releases.

Marljeh (v1.9.25)

Geth v1.9.25 is a maintenance release.

Notable changes in this release:

  • Geth has a new subcommand, geth version-check, which displays known security issues (#21859)
  • The geth --ws.origins flag now supports more expressive origin rules (#21481)
  • Recording of trie key preimages can now be disabled using the --cache.preimages flag (#21402)
  • The accounts/abi/bind package now offers replay-protected transaction signing (#21356)
  • The GraphQL API now always returns status code 400 if there is an error processing the query (#21882)
  • The devp2p nodeset filter command can now find snap-enabled nodes (#21950)
  • The eth protocol test suite has been extended with tests for transaction announcements and malicious announce behavior (#21857, #21792)
  • Support for 'retesteth' has been removed from geth since it is no longer used for tests. Its replacement, the evm t8n tool, was released in Geth v1.9.16 (#21861)
  • We now offer signify/minisign signatures for Geth binary downloads as an alternative to PGP. This is experimental, and not yet advertised on the downloads page (#21798)

Bug fixes:

  • A crash in LES server handling of the GetProofsV2 message is resolved. See CVE-2020-26264 advisory for more information (#21896)
  • The LES server no longer locks up during geth shutdown (#21927)
  • Clef now correctly derives accounts for Ledger Live devices (#21757)
  • The faucet now ignores URL query parameters in Facebook post URLs (#21838)
  • Light client peer discovery now uses DNS (#21906)
  • go mod vendor of go-ethereum should now work (#21735)
  • The peer connection acceptor doesn't hot-spin anymore when geth runs out of file descriptors (#21878)
  • Using the reexec option for tracing RPC methods no longer crashes the RPC handler (#21830)
  • common.Hash and common.Address now print as hex when using fmt.Println (#21834)
  • A rare deadlock in Discovery v5 message dispatch is fixed (#21858)
  • Failures in internal CPU metrics collection no longer crash geth (#21864)
  • In Go contract bindings generated by abigen, the Raw field of parsed events is now set correctly (#21807)

For a full rundown of the changes please consult the Geth 1.9.25 release milestone


As with all our previous releases, you can find the:

Akantha (v1.9.24)

Geth v1.9.24 is a security release. It is built with Go v1.15.5, fixing CVE-2020-28362, which has a critical impact for Ethereum. This release also contains a fix for a consensus issue related to mining, which would have triggered a chain split on January 1st 2021.

We recommend everyone to upgrade to this release or rebuild with Go 1.15.5.

Although we publish pre-built binaries for many platforms, certain systems may not have Go 1.15.5 available yet. Notably, our official Docker images will most probably not use Go 1.15.5 due to the base image not being updated yet. Please check the end of the release notes on how you can build your custom Docker image with Go 1.15.5.

If you are building geth from source, please ensure you are building with Go v1.15.5 or above. We do recommend using the latest Geth version, but if you are not mining and cannot upgrade to geth v1.9.24, please rebuild your current version with Go v1.15.5.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

@dependabot-preview dependabot-preview bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Dec 13, 2020
@render
Copy link
Copy Markdown

render bot commented Dec 13, 2020

@dependabot-preview dependabot-preview bot force-pushed the dependabot/go_modules/chain/github.com/ethereum/go-ethereum-1.9.25 branch 10 times, most recently from 0c8e3ce to 43efe98 Compare December 17, 2020 07:04
@dependabot-preview dependabot-preview bot force-pushed the dependabot/go_modules/chain/github.com/ethereum/go-ethereum-1.9.25 branch 6 times, most recently from cab95b6 to 011cd7d Compare December 24, 2020 08:12
@dependabot-preview dependabot-preview bot force-pushed the dependabot/go_modules/chain/github.com/ethereum/go-ethereum-1.9.25 branch 4 times, most recently from 1ecd345 to 254df8c Compare January 4, 2021 04:51
@dependabot-preview dependabot-preview bot force-pushed the dependabot/go_modules/chain/github.com/ethereum/go-ethereum-1.9.25 branch from 254df8c to bca497f Compare January 4, 2021 10:31
@dependabot-preview
Copy link
Copy Markdown
Contributor Author

Dependabot tried to update this pull request, but something went wrong. The most likely cause is #3052, which may be blocking Dependabot from updating your dependency files.

@dependabot-preview dependabot-preview bot force-pushed the dependabot/go_modules/chain/github.com/ethereum/go-ethereum-1.9.25 branch from bca497f to b43208e Compare January 5, 2021 10:42
@dependabot-preview
Copy link
Copy Markdown
Contributor Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot rebase.

@dependabot-preview dependabot-preview bot force-pushed the dependabot/go_modules/chain/github.com/ethereum/go-ethereum-1.9.25 branch 4 times, most recently from 2bd59d0 to 39fa100 Compare January 15, 2021 09:57
@dependabot-preview dependabot-preview bot force-pushed the dependabot/go_modules/chain/github.com/ethereum/go-ethereum-1.9.25 branch 4 times, most recently from af7e0e2 to 90dc2e7 Compare January 26, 2021 06:31
@dependabot-preview dependabot-preview bot force-pushed the dependabot/go_modules/chain/github.com/ethereum/go-ethereum-1.9.25 branch 9 times, most recently from 34e2b3a to e6216ff Compare February 4, 2021 09:49
@dependabot-preview dependabot-preview bot force-pushed the dependabot/go_modules/chain/github.com/ethereum/go-ethereum-1.9.25 branch 4 times, most recently from 7b1ccc4 to 58e0662 Compare February 16, 2021 18:29
@dependabot-preview dependabot-preview bot force-pushed the dependabot/go_modules/chain/github.com/ethereum/go-ethereum-1.9.25 branch 3 times, most recently from d38c680 to 319ac11 Compare February 20, 2021 10:53
Bumps [github.com/ethereum/go-ethereum](https://github.com/ethereum/go-ethereum) from 1.9.19 to 1.9.25.
- [Release notes](https://github.com/ethereum/go-ethereum/releases)
- [Commits](ethereum/go-ethereum@v1.9.19...v1.9.25)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot force-pushed the dependabot/go_modules/chain/github.com/ethereum/go-ethereum-1.9.25 branch from 319ac11 to 4e24edc Compare February 25, 2021 02:48
@dependabot-preview
Copy link
Copy Markdown
Contributor Author

Superseded by #3204.

@dependabot-preview dependabot-preview bot deleted the dependabot/go_modules/chain/github.com/ethereum/go-ethereum-1.9.25 branch March 4, 2021 06:11
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants