Skip to content

Bump github.com/cometbft/cometbft from 0.38.21 to 0.38.22#838

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/github.com/cometbft/cometbft-0.38.22
Closed

Bump github.com/cometbft/cometbft from 0.38.21 to 0.38.22#838
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/github.com/cometbft/cometbft-0.38.22

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 17, 2026

Bumps github.com/cometbft/cometbft from 0.38.21 to 0.38.22.

Release notes

Sourced from github.com/cometbft/cometbft's releases.

v0.38.22

What's Changed

Full Changelog: cometbft/cometbft@v0.38.21...v0.38.22

Changelog

Sourced from github.com/cometbft/cometbft's changelog.

v0.38.22

April 10, 2026

BUG FIXES

  • [evidence] Add validation for Light Client Attack evidence ByzantineValidators (#5638)
  • [blocksync] fix(blocksync): ExtendedCommit verification via next blocks LastCommit (#5629)
  • [blocksync] Modify blocksync to use full commit verification instead of light (#5663)
Commits
  • 6e5f768 chore: prep changelog for release (#5767)
  • 0214cbc prep changelog for release
  • ce162f9 chore: changelog cleanup (#5764)
  • a548ee5 changelog cleanup
  • d6ce436 fix(types): add signed header validation to light client attack evidence (bac...
  • 8c35b33 build(deps): Bump github.com/minio/highwayhash from 1.0.3 to 1.0.4 (backport ...
  • fccfb5c fix(blocksync): ensure full verification of second.LastCommit during sync (...
  • 332f763 build(deps): Bump github.com/sasha-s/go-deadlock from 0.3.7 to 0.3.9 (backpor...
  • a098f3f build(deps): Bump github.com/lib/pq from 1.11.2 to 1.12.0 (backport #5713) (#...
  • 0d463b2 fix(blocksync): use full commit verification in blocksync (backport #5711) (#...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/cometbft/cometbft](https://github.com/cometbft/cometbft) from 0.38.21 to 0.38.22.
- [Release notes](https://github.com/cometbft/cometbft/releases)
- [Changelog](https://github.com/cometbft/cometbft/blob/v0.38.22/CHANGELOG.md)
- [Commits](cometbft/cometbft@v0.38.21...v0.38.22)

---
updated-dependencies:
- dependency-name: github.com/cometbft/cometbft
  dependency-version: 0.38.22
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Apr 17, 2026
@dependabot dependabot Bot requested a review from a team as a code owner April 17, 2026 03:10
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Apr 17, 2026
@dependabot dependabot Bot requested review from RogerKSI and taobun April 17, 2026 03:10
@dependabot dependabot Bot added the go Pull requests that update Go code label Apr 17, 2026
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github May 12, 2026

Superseded by #844.

@dependabot dependabot Bot closed this May 12, 2026
@dependabot dependabot Bot deleted the dependabot/go_modules/github.com/cometbft/cometbft-0.38.22 branch May 12, 2026 08:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant