Skip to content

Conversation

@KaloyanTanev
Copy link
Collaborator

There were vulnerabilities in the QUIC package. libp2p latest version fixes those.

category: misc
ticket: none

@pinebit
Copy link
Collaborator

pinebit commented Dec 18, 2025

FYI: I disabled the flakey TestSyncFlow (in main already), as it warrants complete redesign.
If you rebase this branch, it shall be all green.

@sonarqubecloud
Copy link

@KaloyanTanev KaloyanTanev added the do not merge Indicate to bulldozer bot that this PR should not be merged label Dec 18, 2025
@KaloyanTanev
Copy link
Collaborator Author

I have removed the ActivationThresh variable, as it had data race. It did seem like it was a part of a discv5 protocol, which was removed long time ago.

I would like first to test this change in a cluster though.

@codecov
Copy link

codecov bot commented Dec 18, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 56.66%. Comparing base (f9042d5) to head (915c8cb).
⚠️ Report is 5 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #4184      +/-   ##
==========================================
- Coverage   56.91%   56.66%   -0.26%     
==========================================
  Files         237      237              
  Lines       31004    31306     +302     
==========================================
+ Hits        17646    17739      +93     
- Misses      11108    11292     +184     
- Partials     2250     2275      +25     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@KaloyanTanev KaloyanTanev changed the title deps: bump golibp2p vulnerabilities deps: update libp2p Dec 19, 2025
@sonarqubecloud
Copy link

@KaloyanTanev KaloyanTanev added merge when ready Indicates bulldozer bot may merge when all checks pass and removed do not merge Indicate to bulldozer bot that this PR should not be merged labels Jan 27, 2026
@obol-bulldozer obol-bulldozer bot merged commit 20ad1ea into main Jan 28, 2026
11 of 12 checks passed
@obol-bulldozer obol-bulldozer bot deleted the kalo/bump-go-libp2p branch January 28, 2026 10:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merge when ready Indicates bulldozer bot may merge when all checks pass

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants