Skip to content

build(deps): bump third-party/FFmpeg/FFmpeg from 9047fa1 to fa4ee7a#639

Closed
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/submodules/third-party/FFmpeg/FFmpeg-fa4ee7a
Closed

build(deps): bump third-party/FFmpeg/FFmpeg from 9047fa1 to fa4ee7a#639
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/submodules/third-party/FFmpeg/FFmpeg-fa4ee7a

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 23, 2026

Bumps third-party/FFmpeg/FFmpeg from 9047fa1 to fa4ee7a.

Commits
  • fa4ee7a aarch64/hpeldsp_neon: fix out-of-bounds read
  • 26fdd22 avformat/mov: check return value of mov_read_iref_thmb()
  • 343938f avformat/mov: Fix multiple issues related to mov_read_iref_dimg()
  • 0ef3600 avformat/mov: free item_name on infe entry parsing failure
  • f9b6121 avformat/mov: check for EOF in more loops
  • 6a756fb avformat/mov: abort if the queried item doesn't exist instead of overwriting it
  • 7399d53 avformat/mov: add overflow checks to item offset values
  • 85a32c7 avformat/mov: reindent after the previous change
  • 19df26b avformat/mov: don't parse reserved ISOBMFF fields as if they were QT
  • 5acd4d1 avformat/mov: make items referencing items generic
  • Additional commits viewable in compare view

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [third-party/FFmpeg/FFmpeg](https://github.com/FFmpeg/FFmpeg) from `9047fa1` to `fa4ee7a`.
- [Commits](FFmpeg/FFmpeg@9047fa1...fa4ee7a)

---
updated-dependencies:
- dependency-name: third-party/FFmpeg/FFmpeg
  dependency-version: fa4ee7ab3c1734795149f6dbc3746e834e859e8c
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file submodules Pull requests that update Submodules code labels Mar 23, 2026
@sonarqubecloud
Copy link
Copy Markdown

@ReenigneArcher
Copy link
Copy Markdown
Member

not a tagged release

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot bot commented on behalf of github Mar 23, 2026

OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot bot deleted the dependabot/submodules/third-party/FFmpeg/FFmpeg-fa4ee7a branch March 23, 2026 12:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file submodules Pull requests that update Submodules code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant