Update dependency nghttp2/nghttp2 to v1.61.0
This MR contains the following updates:
Package | Type | Update | Change |
---|---|---|---|
nghttp2/nghttp2 | ironbank-github | minor |
v1.60.0 -> v1.61.0
|
Release Notes
nghttp2/nghttp2 (nghttp2/nghttp2)
v1.61.0
: nghttp2 v1.61.0
What's Changed
- Fixes CVE-2024-28182
- nghttpx: Shutdown h3 stream read with trailer as well by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2087
- Checkout with submodules by @jonaski in https://github.com/nghttp2/nghttp2/pull/2093
- Respect BUILD_STATIC_LIBS and add option for tests by @jonaski in https://github.com/nghttp2/nghttp2/pull/2092
- build(deps): bump golang.org/x/net from 0.21.0 to 0.22.0 by @dependabot in https://github.com/nghttp2/nghttp2/pull/2097
- Workaround llvm issue on github ubuntu runner by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2098
- docker: Use copy --link by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2099
- Nghttpx header idle timeout by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2100
- nghttpx: Fix frontend-header-timeout does not work in config file by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2101
- Rewrite hexdump by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2102
- Switch to distroless/base-nossl by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2103
- Bump ngtcp2 by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2105
- nghttpx: Simplify quic connection close handling by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2106
- build(deps): bump github.com/quic-go/quic-go from 0.41.0 to 0.42.0 by @dependabot in https://github.com/nghttp2/nghttp2/pull/2107
- autotools: Use tar-ustar automake option by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2108
- Automate release process by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2109
- autotools: Switch to tar-pax by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2110
- nghttpx: Drop a UDP datagram from well-known port by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2111
- nghttpx: Fix port byte order by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2112
- h2load: Allow host header to be overridden by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2113
- nghttpx: Rework QUIC stateless reset packet size by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2114
- nghttpx: More QUIC prohibited ports by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2115
- Add actions/stale by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2116
- nghttpx: Discard UDP datagram that is too short to be a valid QUIC packet by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2117
- nghttp: Support SSLKEYLOGFILE by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2119
- No rfc7540 priority fix by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2120
- Further reduce Stateless reset emission by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2122
- nghttpx: Rework Connection ID construction by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2124
- Nghttpx faster worker lookup by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2125
- nghttpx: Split thread into worker_process and thread by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2126
- bpf: Drop bad QUIC packet by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2127
- cmake: check
SSL_provide_quic_data
whenENABLE_HTTP3
isON
by @jimmy-park in https://github.com/nghttp2/nghttp2/pull/2128 - nghttpx: Allocate 3 bits for QUIC configuration in Connection ID by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2129
- nghttpx: Migrate to ares_getaddrinfo by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2132
- Bump munit by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2131
- nghttpx: Fix error message by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2133
- nghttpd: Fix read stall by @tatsuhiro-t in https://github.com/nghttp2/nghttp2/pull/2134
New Contributors
- @jonaski made their first contribution in https://github.com/nghttp2/nghttp2/pull/2093
- @jimmy-park made their first contribution in https://github.com/nghttp2/nghttp2/pull/2128
Full Changelog: https://github.com/nghttp2/nghttp2/compare/v1.60.0...v1.61.0
[!CAUTION]
Do not download from https://github.com/nghttp2/nghttp2/archive/refs/tags/v1.61.0.zip or https://github.com/nghttp2/nghttp2/archive/refs/tags/v1.61.0.tar.gz. They do not work.
Configuration
-
If you want to rebase/retry this MR, check this box
This MR has been generated by Renovate Bot.