8000 Comparing v0.38.13...v0.38.14 · cometbft/cometbft · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: cometbft/cometbft
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v0.38.13
Choose a base ref
...
head repository: cometbft/cometbft
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v0.38.14
Choose a head ref
  • 12 commits
  • 31 files changed
  • 5 contributors

Commits on Nov 1, 2024

  1. build(deps): Bump github.com/prometheus/client_golang from 1.20.4 to …

    …1.20.5 (#4385)
    
    Bumps
    [github.com/prometheus/client_golang](https://github.com/prometheus/client_golang)
    from 1.20.4 to 1.20.5.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/prometheus/client_golang/releases">github.com/prometheus/client_golang's
    releases</a>.</em></p>
    <blockquote>
    <h2>v1.20.5 / 2024-10-15</h2>
    <p>We decided to revert <a
    href="https://redirect.github.com/prometheus/client_golang/pull/1424">the
    <code>testutil</code> change</a> that made our util functions less
    error-prone, but created a lot of work for our downstream users.
    Apologies for the pain! This revert should not cause any major breaking
    change, even if you already did the work--unless you depend on the <a
    href="https://redirect.github.com/grafana/mimir/pull/9624#issuecomment-2413401565">exact
    error message</a>.</p>
    <p>Going forward, we plan to reinforce our release testing strategy <a
    href="https://redirect.github.com/prometheus/client_gol
    10000
    ang/issues/1646">[1]</a>,<a
    href="https://redirect.github.com/prometheus/client_golang/issues/1648">[2]</a>
    and deliver an enhanced <a
    href="https://redirect.github.com/prometheus/client_golang/issues/1639"><code>testutil</code>
    package/module</a> with more flexible and safer APIs.</p>
    <p>Thanks to <a
    href="https://github.com/dashpole"><code>@​dashpole</code></a> <a
    href="https://github.com/dgrisonnet"><code>@​dgrisonnet</code></a> <a
    href="https://github.com/kakkoyun"><code>@​kakkoyun</code></a> <a
    href="https://github.com/ArthurSens"><code>@​ArthurSens</code></a> <a
    href="https://github.com/vesari"><code>@​vesari</code></a> <a
    href="https://github.com/logicalhan"><code>@​logicalhan</code></a> <a
    href="https://github.com/krajorama"><code>@​krajorama</code></a> <a
    href="https://github.com/bwplotka"><code>@​bwplotka</code></a> who
    helped in this patch release! 🤗</p>
    <h3>Changelog</h3>
    <p>[BUGFIX] testutil: Reverted <a
    href="https://redirect.github.com/prometheus/client_golang/issues/1424">#1424</a>;
    functions using compareMetricFamilies are (again) only failing if
    filtered metricNames are in the expected input. <a
    href="https://redirect.github.com/prometheus/client_golang/issues/1645">#1645</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/prometheus/client_golang/blob/main/CHANGELOG.md">github.com/prometheus/client_golang's
    changelog</a>.</em></p>
    <blockquote>
    <h2>1.20.5 / 2024-10-15</h2>
    <ul>
    <li>[BUGFIX] testutil: Reverted <a
    href="https://redirect.github.com/prometheus/client_golang/issues/1424">#1424</a>;
    functions using compareMetricFamilies are (again) only failing if
    filtered metricNames are in the expected input.</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/prometheus/client_golang/commit/48e12a185519fd76b4e514b597483781d9ba4093"><code>48e12a1</code></a>
    Merge pull request <a
    href="https://redirect.github.com/prometheus/client_golang/issues/1645">#1645</a>
    from prometheus/cut-1204-pr1424</li>
    <li><a
    href="https://github.com/prometheus/client_golang/commit/504ad9bf5c6419449d2cacf8cf8855bfdcfcfc18"><code>504ad9b</code></a>
    Cut 1.20.5; update comments.</li>
    <li><a
    href="https://github.com/prometheus/client_golang/commit/584a7ce3d935e4fdca7b893f5f741d59f3289140"><code>584a7ce</code></a>
    Revert &quot;testutil compareMetricFamilies: make less error-prone (<a
    href="https://redirect.github.com/prometheus/client_golang/issues/1424">#1424</a>)&quot;</li>
    <li>See full diff in <a
    href="https://github.com/prometheus/client_golang/compare/v1.20.4...v1.20.5">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/prometheus/client_golang&package-manager=go_modules&previous-version=1.20.4&new-version=1.20.5)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot merge` will merge this PR after your CI passes on it
    - `@dependabot squash and merge` will squash and merge this PR after
    your CI passes on it
    - `@dependabot cancel merge` will cancel a previously requested merge
    and block automerging
    - `@dependabot reopen` will reopen this PR if it is closed
    - `@dependabot close` will close this PR and stop Dependabot recreating
    it. You can achieve the same result by closing it manually
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Nov 1, 2024
    Configuration menu
    Copy the full SHA
    e5c7d39 View commit details
    Browse the repository at this point in the history
  2. build(deps): Bump google.golang.org/grpc from 1.67.0 to 1.67.1 (#4383)

    Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from
    1.67.0 to 1.67.1.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/grpc/grpc-go/releases">google.golang.org/grpc's
    releases</a>.</em></p>
    <blockquote>
    <h2>Release 1.67.1</h2>
    <h1>Bug Fixes</h1>
    <ul>
    <li>transport: Fix a bug causing stream failures due to miscalculation
    of the flow control window in both clients and servers. (<a
    href="https://redirect.github.com/grpc/grpc-go/issues/7667">#7667</a>)</li>
    <li>xds/server: Fix xDS Server memory leak. (<a
    href="https://redirect.github.com/grpc/grpc-go/issues/7681">#7681</a>)</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/grpc/grpc-go/commit/3f95b38ded016ebf32507fc7cb6baeb2f15aef59"><code>3f95b38</code></a>
    Update version to 1.67.1 (<a
    href="https://redirect.github.com/grpc/grpc-go/issues/7682">#7682</a>)</li>
    <li><a
    href="https://github.com/grpc/grpc-go/commit/4f6c5f2348afe333a3552aa4c4854eae62e22353"><code>4f6c5f2</code></a>
    xds/server: Fix xDS Server leak (<a
    href="https://redirect.github.com/grpc/grpc-go/issues/7664">#7664</a>)
    (<a
    href="https://redirect.github.com/grpc/grpc-go/issues/7681">#7681</a>)</li>
    <li><a
    href="https://github.com/grpc/grpc-go/commit/935f8cb5ac28f604d696d8ca9f5187e75551c185"><code>935f8cb</code></a>
    transport: Fix reporting of bytes read while reading headers (<a
    href="https://redirect.github.com/grpc/grpc-go/issues/7660">#7660</a>)
    (<a
    href="https://redirect.github.com/grpc/grpc-go/issues/7667">#7667</a>)</li>
    <li><a
    href="https://github.com/grpc/grpc-go/commit/02bbb657b6e68e7f838f51e71722630d34060fb2"><code>02bbb65</code></a>
    Change version to 1.67.1-dev (<a
    href="https://redirect.github.com/grpc/grpc-go/issues/7605">#7605</a>)</li>
    <li>See full diff in <a
    href="https://github.com/grpc/grpc-go/compare/v1.67.0...v1.67.1">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=google.golang.org/grpc&package-manager=go_modules&previous-version=1.67.0&new-version=1.67.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot merge` will merge this PR after your CI passes on it
    - `@dependabot squash and merge` will squash and merge this PR after
    your CI passes on it
    - `@dependabot cancel merge` will cancel a previously requested merge
    and block automerging
    - `@dependabot reopen` will reopen this PR if it is closed
    - `@dependabot close` will close this PR and stop Dependabot recreating
    it. You can achieve the same result by closing it manually
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
    dependabot[bot] and mergify[bot] authored Nov 1, 2024
    Configuration menu
    Copy the full SHA
    be0ad58 View commit details
    Browse the repository at this point in the history
  3. build(deps): Bump golang.org/x/crypto from 0.27.0 to 0.28.0 (#4379)

    Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from
    0.27.0 to 0.28.0.
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/golang/crypto/commit/adef4cc1a8c2ca4da1b1f4e6c976b59ca22dbfb8"><code>adef4cc</code></a>
    go.mod: update golang.org/x dependencies</li>
    <li><a
    href="https://github.com/golang/crypto/commit/a0819fbb0244af70857f03b6984e1d4f93e6cabf"><code>a0819fb</code></a>
    sha3: fix cSHAKE initialization for extremely large N and or S</li>
    <li><a
    href="https://github.com/golang/crypto/commit/42ee18b963777d907bbef3e59665cf80968d57e6"><code>42ee18b</code></a>
    ssh: return ServerAuthError after too many auth failures</li>
    <li><a
    href="https://github.com/golang/crypto/commit/9e92970a1eb41e446822e037016aa89d24c0ce7a"><code>9e92970</code></a>
    bn256: add missing symbols in comment</li>
    <li>See full diff in <a
    href="https://github.com/golang/crypto/compare/v0.27.0...v0.28.0">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=golang.org/x/crypto&package-manager=go_modules&previous-version=0.27.0&new-version=0.28.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot merge` will merge this PR after your CI passes on it
    - `@dependabot squash and merge` will squash and merge this PR after
    your CI passes on it
    - `@dependabot cancel merge` will cancel a previously requested merge
    and block automerging
    - `@dependabot reopen` will reopen this PR if it is closed
    - `@dependabot close` will close this PR and stop Dependabot recreating
    it. You can achieve the same result by closing it manually
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
    dependabot[bot] and mergify[bot] authored Nov 1, 2024
    Configuration menu
    Copy the full SHA
    5226a8d View commit details
    Browse the repository at this point in the history
  4. build(deps): Bump google.golang.org/protobuf from 1.34.2 to 1.35.1 (#…

    …4380)
    
    Bumps google.golang.org/protobuf from 1.34.2 to 1.35.1.
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=google.golang.org/protobuf&package-manager=go_modules&previous-version=1.34.2&new-version=1.35.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot merge` will merge this PR after your CI passes on it
    - `@dependabot squash and merge` will squash and merge this PR after
    your CI passes on it
    - `@dependabot cancel merge` will cancel a previously requested merge
    and block automerging
    - `@dependabot reopen` will reopen this PR if it is closed
    - `@dependabot close` will close this PR and stop Dependabot recreating
    it. You can achieve the same result by closing it manually
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
    dependabot[bot] and mergify[bot] authored Nov 1, 2024
    Configuration menu
    Copy the full SHA
    7275ed2 View commit details
    Browse the repository at this point in the history
  5. build(deps): Bump github.com/decred/dcrd/dcrec/secp256k1/v4 from 4.0.…

    …1 to 4.3.0 (#4381)
    
    Bumps
    [github.com/decred/dcrd/dcrec/secp256k1/v4](https://github.com/decred/dcrd)
    from 4.0.1 to 4.3.0.
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/decred/dcrd/commit/08d8572807872f2b9737f8a118b16c320a04b077"><code>08d8572</code></a>
    secp256k1: Prepare v4.3.0.</li>
    <li><a
    href="https://github.com/decred/dcrd/commit/fe9a28cd1e4f341105001496b135a58d09717647"><code>fe9a28c</code></a>
    secp256k1: No allocs in slow scalar base mult path.</li>
    <li><a
    href="https://github.com/decred/dcrd/commit/2104419fc012bb162222a5e0a2c06e4d806cbfae"><code>2104419</code></a>
    wire: Fix typo in comment.</li>
    <li><a
    href="https://github.com/decred/dcrd/commit/b9d8d49c901bb7cbb19ed36d636c3e3d86a1fe43"><code>b9d8d49</code></a>
    wire: add p2p mixing messages</li>
    <li><a
    href="https://github.com/decred/dcrd/commit/25adf60a9f4e12aec13565f6345f769965b0135a"><code>25adf60</code></a>
    secp256k1: Add scalar base mult variant benchmarks.</li>
    <li><a
    href="https://github.com/decred/dcrd/commit/2ee2ebeb678398d3f9333a2cfa937378efe27cfb"><code>2ee2ebe</code></a>
    secp256k1: Add TinyGo support.</li>
    <li><a
    href="https://github.com/decred/dcrd/commit/c6322d513aee03139d91a4e45490dc02d070f278"><code>c6322d5</code></a>
    docker: Update image to golang:1.22.1-alpine3.19.</li>
    <li><a
    href="https://github.com/decred/dcrd/commit/20dedca001392442f83a7d5b218fe54a92c1c565"><code>20dedca</code></a>
    server: Update required minimum protocol version.</li>
    <li><a
    href="https://github.com/decred/dcrd/commit/eb3de8e7299ba919d4ccd67cb1b56a17030f85b7"><code>eb3de8e</code></a>
    docs: Update README.md to required Go 1.21/1.22.</li>
    <li><a
    href="https://github.com/decred/dcrd/commit/fedbaf982b460c7b639d1c577efe51e3f255f8dc"><code>fedbaf9</code></a>
    build: Test against Go 1.22.</li>
    <li>Additional commits viewable in <a
    href="https://github.com/decred/dcrd/compare/dcrjson/v4.0.1...dcrec/secp256k1/v4.3.0">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/decred/dcrd/dcrec/secp256k1/v4&package-manager=go_modules&previous-version=4.0.1&new-version=4.3.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot merge` will merge this PR after your CI passes on it
    - `@dependabot squash and merge` will squash and merge this PR after
    your CI passes on it
    - `@dependabot cancel merge` will cancel a previously requested merge
    and block automerging
    - `@dependabot reopen` will reopen this PR if it is closed
    - `@dependabot close` will close this PR and stop Dependabot recreating
    it. You can achieve the same result by closing it manually
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
    dependabot[bot] and mergify[bot] authored Nov 1, 2024
    Configuration menu
    Copy the full SHA
    899095f View commit details
    Browse the repository at this point in the history
  6. build(deps): Bump github.com/prometheus/common from 0.59.1 to 0.60.1 (#…

    …4382)
    
    Bumps
    [github.com/prometheus/common](https://github.com/prometheus/common)
    from 0.59.1 to 0.60.1.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/prometheus/common/releases">github.com/prometheus/common's
    releases</a>.</em></p>
    <blockquote>
    <h2>v0.60.1</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>promslog: Only log basename, not full path by <a
    href="https://github.com/roidelapluie"><code>@​roidelapluie</code></a>
    in <a
    href="https://redirect.github.com/prometheus/common/pull/705">prometheus/common#705</a></li>
    <li>Reload certificates even when no CA is used by <a
    href="https://github.com/roidelapluie"><code>@​roidelapluie</code></a>
    in <a
    href="https://redirect.github.com/prometheus/common/pull/707">prometheus/common#707</a></li>
    <li>Synchronize common files from prometheus/prometheus by <a
    href="https://github.com/prombot"><code>@​prombot</code></a> in <a
    href="https://redirect.github.com/prometheus/common/pull/701">prometheus/common#701</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/prometheus/common/compare/v0.60.0...v0.60.1">https://github.com/prometheus/common/compare/v0.60.0...v0.60.1</a></p>
    <h2>v0.60.0</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Synchronize common files from prometheus/prometheus by <a
    href="https://github.com/prombot"><code>@​prombot</code></a> in <a
    href="https://redirect.github.com/prometheus/common/pull/692">prometheus/common#692</a></li>
    <li>slog: expose io.Writer by <a
    href="https://github.com/jkroepke"><code>@​jkroepke</code></a> in <a
    href="https://redirect.github.com/prometheus/common/pull/694">prometheus/common#694</a></li>
    <li>Synchronize common files from prometheus/prometheus by <a
    href="https://github.com/prombot"><code>@​prombot</code></a> in <a
    href="https://redirect.github.com/prometheus/common/pull/695">prometheus/common#695</a></li>
    <li>promslog: use UTC timestamps for go-kit log style by <a
    href="https://github.com/dswarbrick"><code>@​dswarbrick</code></a> in <a
    href="https://redirect.github.com/prometheus/common/pull/696">prometheus/common#696</a></li>
    <li>feat: add <code>promslog.NewNopLogger()</code> convenience func by
    <a href="https://github.com/tjhop"><code>@​tjhop</code></a> in <a
    href="https://redirect.github.com/prometheus/common/pull/697">prometheus/common#697</a></li>
    <li>Bump golang.org/x/net from 0.28.0 to 0.29.0 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a> in <a
    href="https://redirect.github.com/prometheus/common/pull/699">prometheus/common#699</a></li>
    <li>Bump golang.org/x/oauth2 from 0.22.0 to 0.23.0 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a> in <a
    href="https://redirect.github.com/prometheus/common/pull/698">prometheus/common#698</a></li>
    <li>Update supported Go versions by <a
    href="https://github.com/SuperQ"><code>@​SuperQ</code></a> in <a
    href="https://redirect.github.com/prometheus/common/pull/700">prometheus/common#700</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/prometheus/common/compare/v0.59.1...v0.60.0">https://github.com/prometheus/common/compare/v0.59.1...v0.60.0</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/prometheus/common/commit/653e0fa37b474f7af331bbfb409c0f654fb04a94"><code>653e0fa</code></a>
    Update common Prometheus files (<a
    href="https://redirect.github.com/prometheus/common/issues/701">#701</a>)</li>
    <li><a
    href="https://github.com/prometheus/common/commit/0d2e2e509b05032929d08ab69362a58ce540fcb1"><code>0d2e2e5</code></a>
    Reload certificates even when no CA is used (<a
    href="https://redirect.github.com/prometheus/common/issues/707">#707</a>)</li>
    <li><a
    href="https://github.com/prometheus/common/commit/a9d2e3ff1686621e6f772f7b503b12d242701c48"><code>a9d2e3f</code></a>
    Merge pull request <a
    href="https://redirect.github.com/prometheus/common/issues/705">#705</a>
    from roidelapluie/sourcefile</li>
    <li><a
    href="https://github.com/prometheus/common/commit/fdc50c720a071b6796bcb5e08c3a1a03cc6ef121"><code>fdc50c7</code></a>
    promslog: Only log basename, not full path</li>
    <li><a
    href="https://github.com/prometheus/common/commit/dae848db5327d2a4e2e06cbe883093a71b4226d7"><code>dae848d</code></a>
    Update supported Go versions (<a
    href="https://redirect.github.com/prometheus/common/issues/700">#700</a>)</li>
    <li><a
    href="https://github.com/prometheus/common/commit/63ff77eeea3cfd552d81d455b44546db75a3b4ac"><code>63ff77e</code></a>
    Bump golang.org/x/oauth2 from 0.22.0 to 0.23.0 (<a
    href="https://redirect.github.com/prometheus/common/issues/698">#698</a>)</li>
    <li><a
    href="https://github.com/prometheus/common/commit/b7aa68c1be77461e7ed0987ee66a288bbaa324ae"><code>b7aa68c</code></a>
    Bump golang.org/x/net from 0.28.0 to 0.29.0 (<a
    href="https://redirect.github.com/prometheus/common/issues/699">#699</a>)</li>
    <li><a
    href="https://github.com/prometheus/common/commit/4e3a6fd348a3c764fff5193cd0ee34eea4402318"><code>4e3a6fd</code></a>
    feat: add <code>promslog.NewNopLogger()</code> convenience func (<a
    href="https://redirect.github.com/prometheus/common/issues/697">#697</a>)</li>
    <li><a
    href="https://github.com/prometheus/common/commit/d66e745b02ad50e6763ec5a0765aae5014a6c188"><code>d66e745</code></a>
    promslog: use UTC timestamps for go-kit log style (<a
    href="https://redirect.github.com/prometheus/common/issues/696">#696</a>)</li>
    <li><a
    href="https://github.com/prometheus/common/commit/14bac55a992f7b83ab9d147a041e274606bdb607"><code>14bac55</code></a>
    Merge pull request <a
    href="https://redirect.github.com/prometheus/common/issues/695">#695</a>
    from prometheus/repo_sync</li>
    <li>Additional commits viewable in <a
    href="https://github.com/prometheus/common/compare/v0.59.1...v0.60.1">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/prometheus/common&package-manager=go_modules&previous-version=0.59.1&new-version=0.60.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot merge` will merge this PR after your CI passes on it
    - `@dependabot squash and merge` will squash and merge this PR after
    your CI passes on it
    - `@dependabot cancel merge` will cancel a previously requested merge
    and block automerging
    - `@dependabot reopen` will reopen this PR if it is closed
    - `@dependabot close` will close this PR and stop Dependabot recreating
    it. You can achieve the same result by closing it manually
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
    dependabot[bot] and mergify[bot] authored Nov 1, 2024
    Configuration menu
    Copy the full SHA
    b2866fa View commit details
    Browse the repository at this point in the history
  7. build(deps): Bump golang.org/x/net from 0.29.0 to 0.30.0 (#4384)

    Bumps [golang.org/x/net](https://github.com/golang/net) from 0.29.0 to
    0.30.0.
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/golang/net/commit/6cc5ac4e9a03d73b331eb1d6db98a02e558243b7"><code>6cc5ac4</code></a>
    go.mod: update golang.org/x dependencies</li>
    <li><a
    href="https://github.com/golang/net/commit/f88258d67e0f0f144c79964ca05bb81d51ee8411"><code>f88258d</code></a>
    websocket: update nhooyr.io/websocket to github.com/coder/websocket</li>
    <li><a
    href="https://github.com/golang/net/commit/7191757bc637cf79a7ece0546e33f903bf5e9709"><code>7191757</code></a>
    http2: add support for net/http HTTP2 config field</li>
    <li><a
    href="https://github.com/golang/net/commit/4790dc7047441aed4889873cdd30e1e6adf49735"><code>4790dc7</code></a>
    http2: add support for server-originated pings</li>
    <li><a
    href="https://github.com/golang/net/commit/541dbe58b6bc869fc1c7de361846682a34365325"><code>541dbe5</code></a>
    http2: add Server.WriteByteTimeout</li>
    <li><a
    href="https://github.com/golang/net/commit/3c333c0c5288a7cf127e427ddda5b1b54020a2b4"><code>3c333c0</code></a>
    route: fix address parsing of messages on Darwin</li>
    <li>See full diff in <a
    href="https://github.com/golang/net/compare/v0.29.0...v0.30.0">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=golang.org/x/net&package-manager=go_modules&previous-version=0.29.0&new-version=0.30.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot merge` will merge this PR after your CI passes on it
    - `@dependabot squash and merge` will squash and merge this PR after
    your CI passes on it
    - `@dependabot cancel merge` will cancel a previously requested merge
    and block automerging
    - `@dependabot reopen` will reopen this PR if it is closed
    - `@dependabot close` will close this PR and stop Dependabot recreating
    it. You can achieve the same result by closing it manually
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Nov 1, 2024
    10000
    Configuration menu
    Copy the full SHA
    ab9cc83 View commit details
    Browse the repository at this point in the history

Commits on Nov 4, 2024

  1. build(deps): Bump bufbuild/buf-setup-action from 1.45.0 to 1.46.0 (#4414

    )
    
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Nov 4, 2024
    Configuration menu
    Copy the full SHA
    c71de55 View commit details
    Browse the repository at this point in the history
  2. chore: use the latest cometbft-db in v0.38.x (#4297)

    Co-authored-by: Anton Kaliaev <anton.kalyaev@gmail.com>
    faddat and melekes authored Nov 4, 2024
    Configuration menu
    Copy the full SHA
    28a308f View commit details
    Browse the repository at this point in the history
  3. fix(p2p): adjust backoff seconds to increase reconnect retries close …

    …to 24 hours (backport #4377) (#4425)
    
    close: #3519 
    
    Adjust `reconnectBackOffBaseSeconds` to increase reconnect retries to up
    1 day (~24 hours).
    
    The new value can be validated here: https://go.dev/play/p/k8F5rS-i24p,
    which will show that the total time is increased to almost 24 hours.
    
    Initial reconnecting time: 2m8.493s
    Total reconnecting time. : 23h55m56.249s
    
    The `reconnectBackOffBaseSeconds` is increased by a bit over 10% (from
    3.0 to 3.4 seconds) so this would not affect reconnection retries too
    much.
    
    #### PR checklist
    
    - [ ] ~~Tests written/updated~~
    - [x] Changelog entry added in `.changelog` (we use
    [unclog](https://github.com/informalsystems/unclog) to manage our
    changelog)
    - [x] Updated relevant documentation (`docs/` or `spec/`) and code
    comments
    <hr>This is an automatic backport of pull request #4377 done by
    [Mergify](https://mergify.com).
    
    ---------
    
    Co-authored-by: Andy Nogueira <me@andynogueira.dev>
    mergify[bot] and andynog authored Nov 4, 2024
    Configuration menu
    Copy the full SHA
    deef97f View commit details
    Browse the repository at this point in the history

Commits on Nov 6, 2024

  1. Merge commit from fork

    melekes authored Nov 6, 2024
    Configuration menu
    Copy the full SHA
    3a023da View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    ce0949e View commit details
    Browse the repository at this point in the history
Loading
0