Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(docker-image): update matrixdotorg/synapse docker tag to v1.94.0 #261

Merged
merged 2 commits into from
Oct 23, 2023

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Oct 10, 2023

Mend Renovate

This PR contains the following updates:

Package Update Change
matrixdotorg/synapse minor v1.93.0 -> v1.94.0

Release Notes

matrix-org/synapse (matrixdotorg/synapse)

v1.94.0

Compare Source

Synapse 1.94.0 (2023-10-10)

No significant changes since 1.94.0rc1.
However, please take note of the security advisory that follows.

Security advisory

The following issue is fixed in 1.94.0 (and RC).

  • GHSA-5chr-wjw5-3gq4 / CVE-2023-45129 — Moderate Severity

    A malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service.

    Homeservers running on a closed federation (which presumably do not need to use server ACLs) are not affected.

See the advisory for more details. If you have any questions, email security@matrix.org.

Synapse 1.94.0rc1 (2023-10-03)

Features
  • Render plain, CSS, CSV, JSON and common image formats in the browser (inline) when requested through the /download endpoint. (#​15988)
  • Add experimental support for MSC4028 to push all encrypted events to clients. (#​16361)
  • Minor performance improvement when sending presence to federated servers. (#​16385)
  • Minor performance improvement by caching server ACL checking. (#​16360)
Improved Documentation
  • Add developer documentation concerning gradual schema migrations with column alterations. (#​15691)
  • Improve documentation of the user directory search algorithm. (#​16320)
  • Fix rendering of user admin API documentation around deactivation. This was broken in Synapse 1.91.0. (#​16355)
  • Update documentation around message retention policies. (#​16382)
  • Add note to federation_domain_whitelist config option to clarify its usage. (#​16416)
  • Improve legacy release notes. (#​16418)
Deprecations and Removals
  • Remove Python version from /_synapse/admin/v1/server_version. (#​16380)
Internal Changes
Updates to locked dependencies
  • Bump actions/checkout from 3 to 4. (#​16250)
  • Bump cryptography from 41.0.3 to 41.0.4. (#​16362)
  • Bump dawidd6/action-download-artifact from 2.27.0 to 2.28.0. (#​16374)
  • Bump docker/setup-buildx-action from 2 to 3. (#​16375)
  • Bump gitpython from 3.1.35 to 3.1.37. (#​16376)
  • Bump msgpack from 1.0.5 to 1.0.6. (#​16377)
  • Bump msgpack from 1.0.6 to 1.0.7. (#​16412)
  • Bump phonenumbers from 8.13.19 to 8.13.22. (#​16413)
  • Bump psycopg2 from 2.9.7 to 2.9.8. (#​16409)
  • Bump pydantic from 2.3.0 to 2.4.2. (#​16410)
  • Bump regex from 1.9.5 to 1.9.6. (#​16408)
  • Bump sentry-sdk from 1.30.0 to 1.31.0. (#​16378)
  • Bump types-netaddr from 0.8.0.9 to 0.9.0.1. (#​16411)
  • Bump types-psycopg2 from 2.9.21.11 to 2.9.21.14. (#​16381)
  • Bump urllib3 from 1.26.15 to 1.26.17. (#​16422)

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

| datasource | package              | from    | to      |
| ---------- | -------------------- | ------- | ------- |
| docker     | matrixdotorg/synapse | v1.93.0 | v1.94.0 |
@renovate renovate bot force-pushed the renovate/matrixdotorg-synapse-1.x branch from cd3457e to de109c5 Compare October 23, 2023 08:32
@renovate
Copy link
Contributor Author

renovate bot commented Oct 23, 2023

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

Warning: custom changes will be lost.

@zekker6 zekker6 merged commit d140c3f into main Oct 23, 2023
12 checks passed
@zekker6 zekker6 deleted the renovate/matrixdotorg-synapse-1.x branch October 23, 2023 10:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant