diff --git a/.changelog/unreleased/dependencies/182-update-go-version.md b/.changelog/v0.9.5/dependencies/182-update-go-version.md similarity index 100% rename from .changelog/unreleased/dependencies/182-update-go-version.md rename to .changelog/v0.9.5/dependencies/182-update-go-version.md diff --git a/.changelog/v0.9.5/dependencies/191-goleveldb.md b/.changelog/v0.9.5/dependencies/191-goleveldb.md new file mode 100644 index 0000000..1f25c1d --- /dev/null +++ b/.changelog/v0.9.5/dependencies/191-goleveldb.md @@ -0,0 +1,2 @@ +- switched to `informalsystems/goleveldb` fork to fix a vulnerability imported + via dependencies ([\#191](https://github.com/cometbft/cometbft-db/pull/191)) diff --git a/.changelog/v0.9.5/summary.md b/.changelog/v0.9.5/summary.md new file mode 100644 index 0000000..9686d75 --- /dev/null +++ b/.changelog/v0.9.5/summary.md @@ -0,0 +1,3 @@ +*September 10, 2024* + +This release bumps the Go version to 1.22 and updates dependencies. diff --git a/CHANGELOG.md b/CHANGELOG.md index 9b63316..cbd415a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,13 +2,15 @@ ## v0.9.5 -*August 22, 2024* +*September 10, 2024* -This release updates the dependencies to the latest patch versions. +This release bumps the Go version to 1.22 and updates dependencies. ### DEPENDENCIES -- cometbft-db now depends on a fork of goleveldb to fix a vulnerability imported +- bumped go version to 1.22, updated depencency version to fix a + vulnerability ([\#200](https://github.com/cometbft/cometbft-db/pull/200)) +- switched to `informalsystems/goleveldb` fork to fix a vulnerability imported via dependencies ([\#191](https://github.com/cometbft/cometbft-db/pull/191)) ## v0.9.4 diff --git a/tools/Dockerfile b/tools/Dockerfile index 381a4f0..b4235c7 100644 --- a/tools/Dockerfile +++ b/tools/Dockerfile @@ -18,7 +18,7 @@ RUN apt update \ libleveldb-dev libleveldb1d FROM build AS install -ARG ROCKSDB=9.2.1 +ARG ROCKSDB=9.3.1 # Install Rocksdb RUN \