Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Oct 24, 2022

Updates the requirements on goblin to permit the latest version.

Changelog

Sourced from goblin's changelog.

[0.6.0] - 2022-10-23

Breaking

macho: add support for archives in multi-arch binaries, big thanks to @​nick96: m4b/goblin#322

Changed

elf: only consider loadable segments for VM translation (this may semantically break someone, if they depended on older behavior), thanks @​lumag: m4b/goblin#329

Fixed

archive: fix potential panic in bsd filenames, thanks @​nathaniel-daniel: m4b/goblin#335 archive: fix subtract with overflow, thanks @​anfedotoff: m4b/goblin#333 pe: fix oob access, thanks @​anfedetoff: m4b/goblin#330 archive: fix oob access, thanks @​anfedetoff: m4b/goblin#329

Added

pe: add machine_to_str utility function, thanks @​cgzones: m4b/goblin#338 fuzz: add debug info for line numbers, thanks @​SweetVishnya: m4b/goblin#336

[0.5.4] - 2022-8-14

Fixed

pe: fix regression in PE binary parsing, thanks @​SquareMan: m4b/goblin#321

[0.5.3] - 2022-7-16

Fixed

elf: fix elf strtab parsing, thanks @​tux3: m4b/goblin#316

Added

elf: implement plain for note headers, thanks @​mkroening: m4b/goblin#317

[0.5.2] - 2022-6-5

Fixed

elf: fix arithmetic overflows in file_range() and vm_range(), thanks @​alessandron: m4b/goblin#306 pe: fix string table containing empty strings, thanks @​track-5: m4b/goblin#310 pe: remove check on debug directory size, thanks @​lzybkr: m4b/goblin#313

Added

elf: expose more of programheader impl regardless of alloc feature flag, thanks @​dancrossnyc: m4b/goblin#308 mach.parse: Handle DyldExportsTrie, thanks @​apalm: m4b/goblin#303

[0.5.1] - 2022-2-13

BREAKING

goblin: guard all capacity allocations with bounds checks, this is breaking because we introduced a new error enum, which is now marked as non_exhaustive, thanks @​Swatinem: m4b/goblin#298 pe: support exports without an offset, thanks @​dureuill: m4b/goblin#293

Fixed

mach: fix overflow panics, thanks @​Swatinem: m4b/goblin#302 pe: add signature header check, thanks @​skdltmxn: m4b/goblin#286 elf: improve parsing SHT_SYMTAB complexity from O(N^2) to O(N), thanks @​Lichsto: m4b/goblin#297

Added

elf: clarify documentation on strtab behavior better, and add nice doc example, thanks @​n01e0: m4b/goblin#301 elf: add rpaths and runpath to elf, thanks @​messense: m4b/goblin#294 elf: complete elf OSABI constants, thanks @​messense: m4b/goblin#295 elf: fill out more elf constants, thanks @​n01e0: m4b/goblin#296

[0.5.0] - 2022-2-13

YANKED, see 0.5.1

... (truncated)

Commits
  • d035559 build: bump version to 0.6.0
  • aa40ece docs: update changelog for 0.6.0; add 5!! new contributors to README.md
  • b275e75 fuzz: enable debug info in fuzz targets
  • 9633205 pe: add machine_to_str
  • b281e4d mach, tests: fix two rustc warnings
  • 761ffd8 archive: fix potential panic in bsd_filename_length (#335)
  • 6fdaffd archive: fix subtract with overflow for header.size
  • e2b5207 mach: support archive entries in fat binaries (fixes #320)
  • a20ce47 elf.dynamic: only consider loadable segments for VM translation
  • cb19f3b pe: fix unbound access to bytes slice at im pe/debug.rs:172
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [goblin](https://github.com/m4b/goblin) to permit the latest version.
- [Release notes](https://github.com/m4b/goblin/releases)
- [Changelog](https://github.com/m4b/goblin/blob/master/CHANGELOG.md)
- [Commits](m4b/goblin@0.5.0...0.6.0)

---
updated-dependencies:
- dependency-name: goblin
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Oct 24, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

amd sev dependencies Pull requests that update a dependency file kvm

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants