Skip to content

build(deps): bump github.com/cometbft/cometbft from 0.38.17 to 0.38.21#8

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/go_modules/github.com/cometbft/cometbft-0.38.21
Open

build(deps): bump github.com/cometbft/cometbft from 0.38.17 to 0.38.21#8
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/go_modules/github.com/cometbft/cometbft-0.38.21

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot bot commented on behalf of github Feb 12, 2026

Bumps github.com/cometbft/cometbft from 0.38.17 to 0.38.21.

Release notes

Sourced from github.com/cometbft/cometbft's releases.

v0.38.21

What's Changed

Full Changelog: cometbft/cometbft@v0.38.20...v0.38.21

v0.38.20

What's Changed

Full Changelog: cometbft/cometbft@v0.38.19...v0.38.20

v0.38.19

This is a security patch release to the CometBFT v0.38.x family that fixes GHSA-hrhf-2vcr-ghch

What's Changed

Full Changelog: cometbft/cometbft@v0.38.18...v0.38.19

v0.38.18

What's Changed

... (truncated)

Changelog

Sourced from github.com/cometbft/cometbft's changelog.

CHANGELOG

UNRELEASED

DEPENDENCIES

BUG FIXES

  • [evidence] Add validation for Light Client Attack evidence ByzantineValidators (#5638)
  • [types] Fix buffer offset bug in ProposerPriorityHash that caused hash collisions when validator priorities differed (#5613)
  • [p2p] fix(privval): Ephemeral Port Exhaustion (#5433)
  • [blocksync] fix(blocksync): ExtendedCommit verification via next blocks LastCommit (#5629)
  • [p2p] fix(lp2p): enforce stream max size (#5647)
  • [metrics] fix(metrics)!: peer_send_queue_size (#5648)
  • [statesync] fix adaptive_sync and streamline stateSync logic (#5663)
  • [blocksync] Modify blocksync to use full commit verification instead of light (#5663)
  • [adaptivesync] Simplify loop, reuse blockExec.ValidateBlock (#5717)

IMPROVEMENTS

  • [ci]: add lp2p testnet (#5643)
  • [mempool] feat!(p2p): introduce follower-mode. Improve lib-p2p integraap access
  • [types] Add validation for AuthorityParams.Authority field in consensus params, enforcing a maximum length of 256 characters (#5511)
  • [mempool] perf(mempool/cache): Optimize LRUTxCache.Remove to reduce lock contention and map access (#5244)
  • [e2e] add support for testing different keytypes, including BLS (#3513)
  • [crypto] Reduce BLS signature size to 48 bytes by increasing pubkey size to 192 bytes (#3624
  • [statesync] Add configurable max-snapshot-chunks parameter to validate max amount of chunks in a SnapshotResponse. (#5549)
  • [p2p] feat(lp2p): make reactor queue configurable (#5662)
  • [cli] print lib-p2p peer id (#5667)
  • [p2p] Add warning when go-libp2p transport is enabled, conveying that the setting should only be activated if it can be enabled simultaneously for all validators and peer IDs have been predetermined and exchanged (#5692)
  • [p2p] feat(p2p): add adaptive sync for comet-p2p (#5705)

... (truncated)

Commits

@dependabot dependabot bot added dependencies Dependency updates go labels Feb 12, 2026
@allora-org-manager allora-org-manager bot removed the go label Feb 12, 2026
@spooktheducks
Copy link
Copy Markdown

@dependabot rebase

Bumps [github.com/cometbft/cometbft](https://github.com/cometbft/cometbft) from 0.38.17 to 0.38.21.
- [Release notes](https://github.com/cometbft/cometbft/releases)
- [Changelog](https://github.com/cometbft/cometbft/blob/main/CHANGELOG.md)
- [Commits](cometbft/cometbft@v0.38.17...v0.38.21)

---
updated-dependencies:
- dependency-name: github.com/cometbft/cometbft
  dependency-version: 0.38.21
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/go_modules/github.com/cometbft/cometbft-0.38.21 branch from 10c6518 to 092fd4a Compare April 8, 2026 05:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant