Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): Bump github.com/cosmos/ibc-go/v6 from 6.1.0 to 6.1.1 #1832

Merged

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github May 25, 2023

Bumps github.com/cosmos/ibc-go/v6 from 6.1.0 to 6.1.1.

Release notes

Sourced from github.com/cosmos/ibc-go/v6's releases.

v6.1.1

This release includes a fix for the huckleberry security advisory. Credits to Felix Wilhelm (@​felixwilhelm) of Jump Crypto for the discovery and responsible disclosure via our bug bounty program.

Please see the v6.1.1 changelog for the full set of changes included in this release.


To learn more about ibc-go versioning, please read our RELEASES.md.

IMPORTANT: Please read the migration guides for any versions of ibc-go that you might be going through when upgrading to this version. For example: if you upgrade from the IBC module contained in the Cosmos SDK 0.42.0 to SDK v0.46.7 and ibc-go v6.1.1, please follow:

  1. The migration from SDK 0.41.x or 0.42.x to the IBC module in the ibc-go repository based on the SDK v0.44.x.
  2. The migration from ibc-go v1 to v2.
  3. The migration from ibc-go v2 to v3.
  4. The migration from ibc-go v3 to v4.
  5. The migration from ibc-go v4 to v5.
  6. The migration from ibc-go v5 to v6.
Changelog

Sourced from github.com/cosmos/ibc-go/v6's changelog.

v6.1.1 - 2023-05-25

Bug Fixes

  • #3346 Properly handle ordered channels in UnreceivedPackets query.
Commits
  • fa3116f Merge pull request from GHSA-3v7p-4x7p-4rx7
  • 9cdf99f Merge pull request from GHSA-3v7p-4x7p-4rx7
  • 742445f Merge pull request from GHSA-3v7p-4x7p-4rx7
  • f5c2681 Merge pull request from GHSA-3v7p-4x7p-4rx7
  • 05f5fa9 Merge pull request from GHSA-3v7p-4x7p-4rx7
  • 19d7fce Merge pull request from GHSA-3v7p-4x7p-4rx7
  • e5d3fe5 Merge pull request from GHSA-3v7p-4x7p-4rx7
  • b7795b3 Merge pull request from GHSA-3v7p-4x7p-4rx7
  • bd7b51c Update CHANGELOG.md
  • 4c745a8 Handle ordered packets in UnreceivedPackets query. (backport #3346) (#3611)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/cosmos/ibc-go/v6](https://github.com/cosmos/ibc-go) from 6.1.0 to 6.1.1.
- [Release notes](https://github.com/cosmos/ibc-go/releases)
- [Changelog](https://github.com/cosmos/ibc-go/blob/v6.1.1/CHANGELOG.md)
- [Commits](cosmos/ibc-go@v6.1.0...v6.1.1)

---
updated-dependencies:
- dependency-name: github.com/cosmos/ibc-go/v6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label May 25, 2023
@github-actions github-actions bot added the bot item was created by a bot label May 25, 2023
@MSevey MSevey requested a review from a team May 25, 2023 15:03
@codecov-commenter
Copy link

Codecov Report

Merging #1832 (1367a82) into main (5b35a01) will not change coverage.
The diff coverage is n/a.

@@           Coverage Diff           @@
##             main    #1832   +/-   ##
=======================================
  Coverage   21.76%   21.76%           
=======================================
  Files         116      116           
  Lines       13236    13236           
=======================================
  Hits         2881     2881           
  Misses      10063    10063           
  Partials      292      292           

@rootulp
Copy link
Collaborator

rootulp commented May 25, 2023

Note that the patch is NOT state-machine breaking. The patch can be deployed individually by validators and full nodes without a chain-halt upgrade and should be applied as soon as possible.

Source: https://forum.cosmos.network/t/ibc-security-advisory-huckleberry/10731

@evan-forbes evan-forbes enabled auto-merge (squash) May 31, 2023 16:10
@MSevey MSevey requested a review from a team May 31, 2023 16:16
@evan-forbes evan-forbes merged commit ae27d52 into main May 31, 2023
14 of 16 checks passed
@evan-forbes evan-forbes deleted the dependabot/go_modules/github.com/cosmos/ibc-go/v6-6.1.1 branch May 31, 2023 16:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bot item was created by a bot dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants