pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/chat/matrix-synapse



Module Name:    pkgsrc
Committed By:   js
Date:           Wed Mar 26 23:18:49 UTC 2025

Modified Files:
        pkgsrc/chat/matrix-synapse: Makefile cargo-depends.mk distinfo

Log Message:
Update chat/matrix-synapse to 1.127.1

Fixes high severity vulnerability *exploited in the wild*!

# Synapse 1.127.1 (2025-03-26)

## Security
- Fix [CVE-2025-30355](https://www.cve.org/CVERecord?id=CVE-2025-30355) / [GHSA-v56r-hwv5-mxg6](https://github.com/element-hq/synapse/security/advisories/GHSA-v56r-hwv5-mxg6). **High severity 
vulnerability affecting federation. The vulnerability has been exploited in the wild.**

# Synapse 1.127.0 (2025-03-25)

No significant changes since 1.127.0rc1.

# Synapse 1.127.0rc1 (2025-03-18)

### Features

- Update [MSC4140](https://github.com/matrix-org/matrix-spec-proposals/pull/4140) implementation to no longer cancel a user's own delayed state events with an event type & state key that match a more 
recent state event sent by that user. ([\#17810](https://github.com/element-hq/synapse/issues/17810))

### Improved Documentation

- Fixed a minor typo in the Synapse documentation. Contributed by @karuto12. ([\#18224](https://github.com/element-hq/synapse/issues/18224))

### Internal Changes

- Remove undocumented `SYNAPSE_USE_FROZEN_DICTS` environment variable. ([\#18123](https://github.com/element-hq/synapse/issues/18123))
- Fix detection of workflow failures in the release script. ([\#18211](https://github.com/element-hq/synapse/issues/18211))
- Add caching support to media endpoints. ([\#18235](https://github.com/element-hq/synapse/issues/18235))

### Updates to locked dependencies

* Bump anyhow from 1.0.96 to 1.0.97. ([\#18201](https://github.com/element-hq/synapse/issues/18201))
* Bump bcrypt from 4.2.1 to 4.3.0. ([\#18207](https://github.com/element-hq/synapse/issues/18207))
* Bump bytes from 1.10.0 to 1.10.1. ([\#18227](https://github.com/element-hq/synapse/issues/18227))
* Bump http from 1.2.0 to 1.3.1. ([\#18245](https://github.com/element-hq/synapse/issues/18245))
* Bump sentry-sdk from 2.19.2 to 2.22.0. ([\#18205](https://github.com/element-hq/synapse/issues/18205))
* Bump serde from 1.0.218 to 1.0.219. ([\#18228](https://github.com/element-hq/synapse/issues/18228))
* Bump serde_json from 1.0.139 to 1.0.140. ([\#18202](https://github.com/element-hq/synapse/issues/18202))
* Bump ulid from 1.2.0 to 1.2.1. ([\#18246](https://github.com/element-hq/synapse/issues/18246))


To generate a diff of this commit:
cvs rdiff -u -r1.110 -r1.111 pkgsrc/chat/matrix-synapse/Makefile
cvs rdiff -u -r1.25 -r1.26 pkgsrc/chat/matrix-synapse/cargo-depends.mk
cvs rdiff -u -r1.78 -r1.79 pkgsrc/chat/matrix-synapse/distinfo

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: pkgsrc/chat/matrix-synapse/Makefile
diff -u pkgsrc/chat/matrix-synapse/Makefile:1.110 pkgsrc/chat/matrix-synapse/Makefile:1.111
--- pkgsrc/chat/matrix-synapse/Makefile:1.110   Fri Mar 14 11:57:53 2025
+++ pkgsrc/chat/matrix-synapse/Makefile Wed Mar 26 23:18:49 2025
@@ -1,6 +1,6 @@
-# $NetBSD: Makefile,v 1.110 2025/03/14 11:57:53 gdt Exp $
+# $NetBSD: Makefile,v 1.111 2025/03/26 23:18:49 js Exp $
 
-DISTNAME=      matrix-synapse-1.126.0
+DISTNAME=      matrix-synapse-1.127.1
 CATEGORIES=    chat
 MASTER_SITES=  ${MASTER_SITE_GITHUB:=element-hq/}
 GITHUB_PROJECT=        synapse

Index: pkgsrc/chat/matrix-synapse/cargo-depends.mk
diff -u pkgsrc/chat/matrix-synapse/cargo-depends.mk:1.25 pkgsrc/chat/matrix-synapse/cargo-depends.mk:1.26
--- pkgsrc/chat/matrix-synapse/cargo-depends.mk:1.25    Fri Mar 14 11:57:53 2025
+++ pkgsrc/chat/matrix-synapse/cargo-depends.mk Wed Mar 26 23:18:49 2025
@@ -1,7 +1,7 @@
-# $NetBSD: cargo-depends.mk,v 1.25 2025/03/14 11:57:53 gdt Exp $
+# $NetBSD: cargo-depends.mk,v 1.26 2025/03/26 23:18:49 js Exp $
 
 CARGO_CRATE_DEPENDS+=  aho-corasick-1.1.3
-CARGO_CRATE_DEPENDS+=  anyhow-1.0.96
+CARGO_CRATE_DEPENDS+=  anyhow-1.0.97
 CARGO_CRATE_DEPENDS+=  arc-swap-1.7.1
 CARGO_CRATE_DEPENDS+=  autocfg-1.3.0
 CARGO_CRATE_DEPENDS+=  base64-0.21.7
@@ -9,7 +9,7 @@ CARGO_CRATE_DEPENDS+=   bitflags-2.8.0
 CARGO_CRATE_DEPENDS+=  blake2-0.10.6
 CARGO_CRATE_DEPENDS+=  block-buffer-0.10.4
 CARGO_CRATE_DEPENDS+=  bumpalo-3.16.0
-CARGO_CRATE_DEPENDS+=  bytes-1.10.0
+CARGO_CRATE_DEPENDS+=  bytes-1.10.1
 CARGO_CRATE_DEPENDS+=  cfg-if-1.0.0
 CARGO_CRATE_DEPENDS+=  cpufeatures-0.2.12
 CARGO_CRATE_DEPENDS+=  crypto-common-0.1.6
@@ -21,7 +21,7 @@ CARGO_CRATE_DEPENDS+= headers-0.4.0
 CARGO_CRATE_DEPENDS+=  headers-core-0.3.0
 CARGO_CRATE_DEPENDS+=  heck-0.5.0
 CARGO_CRATE_DEPENDS+=  hex-0.4.3
-CARGO_CRATE_DEPENDS+=  http-1.2.0
+CARGO_CRATE_DEPENDS+=  http-1.3.1
 CARGO_CRATE_DEPENDS+=  httpdate-1.0.3
 CARGO_CRATE_DEPENDS+=  indoc-2.0.5
 CARGO_CRATE_DEPENDS+=  itoa-1.0.11
@@ -51,16 +51,16 @@ CARGO_CRATE_DEPENDS+=       regex-1.11.1
 CARGO_CRATE_DEPENDS+=  regex-automata-0.4.8
 CARGO_CRATE_DEPENDS+=  regex-syntax-0.8.5
 CARGO_CRATE_DEPENDS+=  ryu-1.0.18
-CARGO_CRATE_DEPENDS+=  serde-1.0.218
-CARGO_CRATE_DEPENDS+=  serde_derive-1.0.218
-CARGO_CRATE_DEPENDS+=  serde_json-1.0.139
+CARGO_CRATE_DEPENDS+=  serde-1.0.219
+CARGO_CRATE_DEPENDS+=  serde_derive-1.0.219
+CARGO_CRATE_DEPENDS+=  serde_json-1.0.140
 CARGO_CRATE_DEPENDS+=  sha1-0.10.6
 CARGO_CRATE_DEPENDS+=  sha2-0.10.8
 CARGO_CRATE_DEPENDS+=  subtle-2.5.0
 CARGO_CRATE_DEPENDS+=  syn-2.0.85
 CARGO_CRATE_DEPENDS+=  target-lexicon-0.12.14
 CARGO_CRATE_DEPENDS+=  typenum-1.17.0
-CARGO_CRATE_DEPENDS+=  ulid-1.2.0
+CARGO_CRATE_DEPENDS+=  ulid-1.2.1
 CARGO_CRATE_DEPENDS+=  unicode-ident-1.0.12
 CARGO_CRATE_DEPENDS+=  unindent-0.2.3
 CARGO_CRATE_DEPENDS+=  version_check-0.9.4

Index: pkgsrc/chat/matrix-synapse/distinfo
diff -u pkgsrc/chat/matrix-synapse/distinfo:1.78 pkgsrc/chat/matrix-synapse/distinfo:1.79
--- pkgsrc/chat/matrix-synapse/distinfo:1.78    Fri Mar 14 11:57:53 2025
+++ pkgsrc/chat/matrix-synapse/distinfo Wed Mar 26 23:18:49 2025
@@ -1,11 +1,11 @@
-$NetBSD: distinfo,v 1.78 2025/03/14 11:57:53 gdt Exp $
+$NetBSD: distinfo,v 1.79 2025/03/26 23:18:49 js Exp $
 
 BLAKE2s (aho-corasick-1.1.3.crate) = 36150b5dacb72fa7cd0d33aee15e14857914224878f0af76eabcb9daa68e3ae0
 SHA512 (aho-corasick-1.1.3.crate) = ba422a54688c4678fcf16e34fdf3ed06c333e6e3fc8b75af9272a215add494d43ebaef319021134b61327fd5d3572aec0dc655b714ffb3bc71ba3c265c9ebb69
 Size (aho-corasick-1.1.3.crate) = 183311 bytes
-BLAKE2s (anyhow-1.0.96.crate) = a0cce61b0a1708914191bc98239613b25c2ec43b350a005e669e2b69c3accdd2
-SHA512 (anyhow-1.0.96.crate) = 673b083ba8ca51865d0b1c41e2ebd410039109db71d251a5048f24bfe009a4ca59f80f72b1b05c35155e523c74e326e349fb9c6f2654b5893eb8b3d50460fc8e
-Size (anyhow-1.0.96.crate) = 52168 bytes
+BLAKE2s (anyhow-1.0.97.crate) = b00e9f38f0f4eba68d28e29f45a1886fe673292efbde3306cb07c5d771d618b3
+SHA512 (anyhow-1.0.97.crate) = 340bd50af85ec816a6123a73154a2ef89d0ffd4c74c99121663649cadf230665c72437872df693c26a1da644b0f867339372a7898315f3d7733203785c588356
+Size (anyhow-1.0.97.crate) = 52221 bytes
 BLAKE2s (arc-swap-1.7.1.crate) = e2cecae4fd3315b92dc0378242bfbff9c25a39b692659bf71969c631242fba75
 SHA512 (arc-swap-1.7.1.crate) = 070fa8dd17b380b6d7d72f6f45c84e591de9a9770b9662351e7a41af03798bf5e34d185a5fcb948f4d8ac5e210a33acd465c39eff6097662c2442b34ee3dbdff
 Size (arc-swap-1.7.1.crate) = 68512 bytes
@@ -27,9 +27,9 @@ Size (block-buffer-0.10.4.crate) = 10538
 BLAKE2s (bumpalo-3.16.0.crate) = 718bb7ba9add434df2b5e3f8ea1ac354f2e51c0f0a6d8d77296504d6c1ca87b2
 SHA512 (bumpalo-3.16.0.crate) = a51b75c36f6794db444cab20eeb24f42a319080ecb486a56d254d6f873f3d188b5ccba11db30c068bd0c52c4322d4a3f5f5195c81c94b0bc04387030418835b1
 Size (bumpalo-3.16.0.crate) = 85677 bytes
-BLAKE2s (bytes-1.10.0.crate) = 770c752dfc1d4f58d1c705a240beb7a9d0c0e5f46422939839b0b49c7d222cf7
-SHA512 (bytes-1.10.0.crate) = ee02d6c0ae18e75ac3a44f949f3891b98865bae5594b25a866b619c42fb574b5249e4e936972373845030c27cd94d2bfcc14885f9f92ef23bf059ad7fc8fbb2b
-Size (bytes-1.10.0.crate) = 76656 bytes
+BLAKE2s (bytes-1.10.1.crate) = 5b3216b1cac8c7d1740ecf85c7cdfcf54dfc2fab12d4e634b882fc8bcf27e480
+SHA512 (bytes-1.10.1.crate) = 03429f01927b94ba6c958c46b2e5bf92a23b39ce9385689e21accd34a5d3be01fd0f665f4bbffb1f7c5bdf1edfb1bf11d5ccad00eff0f9388be39fe2f753d296
+Size (bytes-1.10.1.crate) = 76779 bytes
 BLAKE2s (cfg-if-1.0.0.crate) = fbb02f63b24cc224b045ff2aac3aefd0a77cf7b578df4d5f9da9517a59aaf9bb
 SHA512 (cfg-if-1.0.0.crate) = 0fb16a8882fd30e86b62c5143b1cb18ab564e84e75bd1f28fd12f24ffdc4a42e0d2e012a99abb606c12efe3c11061ff5bf8e24ab053e550ae083f7d90f6576ff
 Size (cfg-if-1.0.0.crate) = 7934 bytes
@@ -63,9 +63,9 @@ Size (heck-0.5.0.crate) = 11517 bytes
 BLAKE2s (hex-0.4.3.crate) = 299902a1da9d88101e5b8b06dde30b77e8f7a802285aae519981ada5959383f8
 SHA512 (hex-0.4.3.crate) = fd8ff33b68eea2d6f2c6b02a6d82a2807cbcdc209ca5a76e3e3e5d006917ee151f236b6d18e2646cc9a9674bcdda1d6ce6ee363a89cadd99bef00d0eea9989e6
 Size (hex-0.4.3.crate) = 13299 bytes
-BLAKE2s (http-1.2.0.crate) = e662ea7723cf1502c6c2f7472a3fd38f35baae2f5e3be77c05ced1471a4c5077
-SHA512 (http-1.2.0.crate) = 2c8e7234ec3aa720c9dd762c0bb06367fbc39ea89446fc9d8d2e55052a4ac461559a20a8294c877879f3e94d5db06fe41e2cdbb9664ea7ab1bc8003abb038bb5
-Size (http-1.2.0.crate) = 105932 bytes
+BLAKE2s (http-1.3.1.crate) = eb05c22ce1a43f9145af09f5cdd7154fe2cbbb87c7ede05586fe4b53990e686a
+SHA512 (http-1.3.1.crate) = 20c6a049d93294e081150991eec281f531d2f2aa66b04b5d51585995bd07c1f9748df7f21a4f94fddf4cb04872c83d77822cce12b2d65778ea55197666e550ac
+Size (http-1.3.1.crate) = 106063 bytes
 BLAKE2s (httpdate-1.0.3.crate) = 9d7d481199e2a0a4f61010c28d20a32426605905a9db6ffc707008dfb6328b31
 SHA512 (httpdate-1.0.3.crate) = 0586888fe89f40b838d5ceb083084d0b8058feff1d2933faedb96896dc86eec68b541a0374a508fd11b86eeadab3c62f88568ffe2c53206fad438373a50b2e5a
 Size (httpdate-1.0.3.crate) = 10639 bytes
@@ -87,9 +87,9 @@ Size (libc-0.2.154.crate) = 743304 bytes
 BLAKE2s (log-0.4.26.crate) = 3281d6a65278f9390ff5cb4246d4e5320875fc6ba09e999ff1867b4451cc85bf
 SHA512 (log-0.4.26.crate) = d85f3cb8bf90893d59b3174785295616d719c8d2078c04fa3e131c3f3cf84b73c75b932348df70b7eab2aedf261b27e6544f051696eb5c287fb461d1ee699ec1
 Size (log-0.4.26.crate) = 47022 bytes
-BLAKE2s (matrix-synapse-1.126.0.tar.gz) = 28ca622ee6de7e17c6d09b58cdb91f76a3c5846e181094a921e83afea41d6f85
-SHA512 (matrix-synapse-1.126.0.tar.gz) = c97d9110b800995413c97884002f70f08c095d063adbd6baf1b13065ed9c0768a8573105031104937fadb7c710eca58a81058a315785c2d787c75da66f3183a9
-Size (matrix-synapse-1.126.0.tar.gz) = 8882168 bytes
+BLAKE2s (matrix-synapse-1.127.1.tar.gz) = b1a466dd981f3c9d5a062a8d21c1c928c6d9de820bdd375e915c948cf690a5e7
+SHA512 (matrix-synapse-1.127.1.tar.gz) = d469bc7e7c6b8f0554e5f4d40cba775ca865157815948e13a1bcf51fc11fd2e73ac36e87f2e632126625b96dda088cf92f4f6952b3e92d9ecaa8d5e2af85882c
+Size (matrix-synapse-1.127.1.tar.gz) = 8885485 bytes
 BLAKE2s (memchr-2.7.2.crate) = 58bad593cd29bb59ae79239f6f69364c2c512fa365107c1c46c37878bf53126f
 SHA512 (memchr-2.7.2.crate) = cadcb4239c7f3aaab042592c5186770a225621e32f8583052fd3dbebb4a6d9b99be28f589b39b5ca36cb2d56fb3709e7d4ba91838ebb882e28e51280c02bbc40
 Size (memchr-2.7.2.crate) = 96220 bytes
@@ -156,15 +156,15 @@ Size (regex-syntax-0.8.5.crate) = 357541
 BLAKE2s (ryu-1.0.18.crate) = 738ae2cbeac90a6adef5e5c05c31be6c18f2860ab8ea4bfdc729325dceb923ae
 SHA512 (ryu-1.0.18.crate) = a9b2beac778ec47e6be303148d7512ee681bd2361f6e4ac6db32c8b4baf86a8c5eb5b0d02eacd6131ae88c7b5105c57018c3050676e0b3dd1ed9c4d2fd650e84
 Size (ryu-1.0.18.crate) = 47713 bytes
-BLAKE2s (serde-1.0.218.crate) = 75cc952826e4124a013fda66bf79e6dc5f5aa54d300388cd495f5b1b9a76381a
-SHA512 (serde-1.0.218.crate) = 35ffd8556287fa270beb90539c1641912d8fb233c53c4017f1f65a483b2dc340385458b9a869b7142b4d514bcc87c25e69c9370b3867e463be887bdebd19ead8
-Size (serde-1.0.218.crate) = 78968 bytes
-BLAKE2s (serde_derive-1.0.218.crate) = 631cf60f1205fe6923f9263c9478c45510ae41668f302b935b9a939a4cb9be73
-SHA512 (serde_derive-1.0.218.crate) = e89c076b0aa22ad74010f5b6a60397b9b78b59ca50a9660b29ceb1fd608cab820c47e787e450da306062c0cea1ade7142a7d4626a77aa0ae486096c130442cde
-Size (serde_derive-1.0.218.crate) = 57782 bytes
-BLAKE2s (serde_json-1.0.139.crate) = dd8925e79883458f99b59ddc64ce464b05cc930c7dd064b210f30243b88fac63
-SHA512 (serde_json-1.0.139.crate) = d90f4a02894b9c0f1d8d210af7639b0d6cb1929a159d1557ec220ce74d327c5d25fbdda6c5dfc2c00763ab3510a8ad11ce949b9cafac5b6d2203721aeaf3b5a0
-Size (serde_json-1.0.139.crate) = 154839 bytes
+BLAKE2s (serde-1.0.219.crate) = 3385d14c789f343566721ebd56545ca426c8ab7ecbdd924a3c2afe3faf7fd720
+SHA512 (serde-1.0.219.crate) = 0d3fe9a47af027d0d79499e60d940661dba6e29e8f0ce47d0db2ab722030d255aff637248af6f893a9c4224239733db09ffcdc6e1923a7177bfae55c98ebe769
+Size (serde-1.0.219.crate) = 78983 bytes
+BLAKE2s (serde_derive-1.0.219.crate) = 871c98d0a22904b21fc4ed9b6f67689ffd45b15bfaef16d7b9853542fcf568c8
+SHA512 (serde_derive-1.0.219.crate) = 1676bbf09e11273705a35c540d52d35d1bba7cdf1f347d40a364d7ae9269167f9f0f62ff4fa384aaa613c83e432a8eb3c016587ea643bb11434c00664a5c116b
+Size (serde_derive-1.0.219.crate) = 57798 bytes
+BLAKE2s (serde_json-1.0.140.crate) = 3f9395e3e753bd015a46f6e711c0f4fe9420192e793340ef2ea23e4815f5cc9c
+SHA512 (serde_json-1.0.140.crate) = bafa26fd43ba30cbf73572b8203292b1f275995636e9dfc3d47954939453fe4ecf0c60f25d2af1ec16c7cb0e7ce3b96cc07507d1b53b7db566fe7cb2624f0e12
+Size (serde_json-1.0.140.crate) = 154852 bytes
 BLAKE2s (sha1-0.10.6.crate) = de97b70d4fb6a4dc4e3db64696720ea96e7b38eec57b2e8fa01ecd5102d96eab
 SHA512 (sha1-0.10.6.crate) = fd37be7e3f1d4b6addd313a36b55215fb70abd21be7831b71de28bd3eb03b7352817d8a7b1a166df002c3a23eadc8224e49edd4a37556c0e5357565305d4128f
 Size (sha1-0.10.6.crate) = 13517 bytes
@@ -183,9 +183,9 @@ Size (target-lexicon-0.12.14.crate) = 25
 BLAKE2s (typenum-1.17.0.crate) = 09823684788c5902da7490db1fa86b53defd3c31eab6e511d3cbbc851616596c
 SHA512 (typenum-1.17.0.crate) = 99773d5d9f850c0602db4bb67dd062b0ade6f086e155216f1bb2fb6569461ba7e1b7c2f2af81ea8833bc3bfcf3fe5033edecb7c438adae63f59d3e30cf63a508
 Size (typenum-1.17.0.crate) = 42849 bytes
-BLAKE2s (ulid-1.2.0.crate) = 5c13931313534f911090bf3dc4d910705eac9b727fe85dd6dd5a58a4fa24fc36
-SHA512 (ulid-1.2.0.crate) = fa14acb831f3ee65ebb84fa4423ea085721e52742eb6ddd3d9d252e25c0fb65514b15644345321576329be999cff6747811a7afda4541c1c9074cc6c6c5ee0ee
-Size (ulid-1.2.0.crate) = 11401 bytes
+BLAKE2s (ulid-1.2.1.crate) = 757a97919f2da143606ec797c196797ab529cc118421dba9f9b33113914cfb42
+SHA512 (ulid-1.2.1.crate) = e77fb93e5c210cf87bb4a26cc4f3631dc1903e62bd05b5952e29ad809152360a15c4b1942e3e00c1a6249651a0dd841b88d97a47779f124210440b05b324863b
+Size (ulid-1.2.1.crate) = 17727 bytes
 BLAKE2s (unicode-ident-1.0.12.crate) = d3afb0938724e7bb0f5c2a5f76ff614511446dd54b363f76e84353254acd3739
 SHA512 (unicode-ident-1.0.12.crate) = bc1824e1e4452a40732fc69874d7e1a66f7803717a314790dcf48867eba34bc9441331ef031e386912e52c385645c25b6ed39d4f149973b5b97371b1b96b1920
 Size (unicode-ident-1.0.12.crate) = 42168 bytes



Home | Main Index | Thread Index | Old Index