Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build(deps): bump goblin from 0.4.2 to 0.6.0 in /internal/shim-sev #338

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

dependabot[bot]
Copy link

@dependabot dependabot bot commented on behalf of github Oct 24, 2022

Bumps goblin from 0.4.2 to 0.6.0.

Changelog

Sourced from goblin's changelog.

[0.6.0] - 2022-10-23

Breaking

macho: add support for archives in multi-arch binaries, big thanks to @​nick96: m4b/goblin#322

Changed

elf: only consider loadable segments for VM translation (this may semantically break someone, if they depended on older behavior), thanks @​lumag: m4b/goblin#329

Fixed

archive: fix potential panic in bsd filenames, thanks @​nathaniel-daniel: m4b/goblin#335 archive: fix subtract with overflow, thanks @​anfedotoff: m4b/goblin#333 pe: fix oob access, thanks @​anfedetoff: m4b/goblin#330 archive: fix oob access, thanks @​anfedetoff: m4b/goblin#329

Added

pe: add machine_to_str utility function, thanks @​cgzones: m4b/goblin#338 fuzz: add debug info for line numbers, thanks @​SweetVishnya: m4b/goblin#336

[0.5.4] - 2022-8-14

Fixed

pe: fix regression in PE binary parsing, thanks @​SquareMan: m4b/goblin#321

[0.5.3] - 2022-7-16

Fixed

elf: fix elf strtab parsing, thanks @​tux3: m4b/goblin#316

Added

elf: implement plain for note headers, thanks @​mkroening: m4b/goblin#317

[0.5.2] - 2022-6-5

Fixed

elf: fix arithmetic overflows in file_range() and vm_range(), thanks @​alessandron: m4b/goblin#306 pe: fix string table containing empty strings, thanks @​track-5: m4b/goblin#310 pe: remove check on debug directory size, thanks @​lzybkr: m4b/goblin#313

Added

elf: expose more of programheader impl regardless of alloc feature flag, thanks @​dancrossnyc: m4b/goblin#308 mach.parse: Handle DyldExportsTrie, thanks @​apalm: m4b/goblin#303

[0.5.1] - 2022-2-13

BREAKING

goblin: guard all capacity allocations with bounds checks, this is breaking because we introduced a new error enum, which is now marked as non_exhaustive, thanks @​Swatinem: m4b/goblin#298 pe: support exports without an offset, thanks @​dureuill: m4b/goblin#293

Fixed

mach: fix overflow panics, thanks @​Swatinem: m4b/goblin#302 pe: add signature header check, thanks @​skdltmxn: m4b/goblin#286 elf: improve parsing SHT_SYMTAB complexity from O(N^2) to O(N), thanks @​Lichsto: m4b/goblin#297

Added

elf: clarify documentation on strtab behavior better, and add nice doc example, thanks @​n01e0: m4b/goblin#301 elf: add rpaths and runpath to elf, thanks @​messense: m4b/goblin#294 elf: complete elf OSABI constants, thanks @​messense: m4b/goblin#295 elf: fill out more elf constants, thanks @​n01e0: m4b/goblin#296

[0.5.0] - 2022-2-13

YANKED, see 0.5.1

... (truncated)

Commits
  • d035559 build: bump version to 0.6.0
  • aa40ece docs: update changelog for 0.6.0; add 5!! new contributors to README.md
  • b275e75 fuzz: enable debug info in fuzz targets
  • 9633205 pe: add machine_to_str
  • b281e4d mach, tests: fix two rustc warnings
  • 761ffd8 archive: fix potential panic in bsd_filename_length (#335)
  • 6fdaffd archive: fix subtract with overflow for header.size
  • e2b5207 mach: support archive entries in fat binaries (fixes #320)
  • a20ce47 elf.dynamic: only consider loadable segments for VM translation
  • cb19f3b pe: fix unbound access to bytes slice at im pe/debug.rs:172
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [goblin](https://github.com/m4b/goblin) from 0.4.2 to 0.6.0.
- [Release notes](https://github.com/m4b/goblin/releases)
- [Changelog](https://github.com/m4b/goblin/blob/master/CHANGELOG.md)
- [Commits](m4b/goblin@0.4.2...0.6.0)

---
updated-dependencies:
- dependency-name: goblin
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Oct 24, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
0 participants