Skip to content

Conversation

@dependabot-preview
Copy link
Contributor

Bumps postgresql from 42.2.12 to 42.2.13.

Changelog

Sourced from postgresql's changelog.

[42.2.13] (2020-06-04)

Notable Changes The primary reason to release this version and to continue the 42.2.x branch is for CVE-2020-13692. Reported by David Dworken this is an XXE and more information can be found here Sehrope Sarkuni reworked the XML parsing to provide a solution in commit 14b62aca4 The build system has been changed to Gradle thanks to Vladimir PR 1627

Changed

Added

  • jre-6 was added back to allow us to release fixes for all artifacts in the 42.2.x branch PR 1787

Fixed

  • I/O error ru translation PR 1756
  • Issue 1771 PgDatabaseMetaData.getFunctions() returns procedures fixed in PR 1774
  • getTypeMap() returning null PR 1781
  • Updated openssl example command PR 1763
  • fix documentation with ordered list to be displayed correctly PR 1783
Commits
  • e63584c change release date to june 4 (#1792)
  • 5ca2b9e chore: include META-INF/services/java.sql.Driver for jre7 and jre6 jars
  • bb3c5ca create changelog and prepare release (#1790)
  • 14b62ac Merge pull request from GHSA-37xm-4h3m-5w3v
  • 97e2e8f chore: fix artifactid and version for -jre6 and -jre7 artifacts
  • 148840d chore: use REL$buildVersion for the release version as it was previously
  • d224acd chore: re-add pgjdbc-jre6 build (#1787)
  • 332b071 chore: show the current PostgreSQL HEAD commit id in Travis log
  • fda4299 fix numbered list to be displayed correctly (#1783)
  • f3abb4e fix: getTypeMap() returning null (#1781)
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.

If all status checks pass Dependabot will automatically merge this pull request.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in the .dependabot/config.yml file in this repo:

  • Update frequency
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

@dependabot-preview dependabot-preview bot added the dependencies Pull requests that update a dependency file label Jun 6, 2020
@dependabot-preview
Copy link
Contributor Author

Dependabot tried to automerge this PR, but received the following error from GitHub:

Waiting on code owner review from bsideup, kiview, and/or rnorth.

@rnorth rnorth merged commit adc3729 into master Jun 6, 2020
@rnorth rnorth deleted the dependabot/gradle/modules/spock/org.postgresql-postgresql-42.2.13 branch June 6, 2020 07:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants