Skip to content

Bump staticx from 0.12.2 to 0.13.8#46

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/pip/staticx-0.13.8
Open

Bump staticx from 0.12.2 to 0.13.8#46
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/pip/staticx-0.13.8

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Sep 1, 2022

Bumps staticx from 0.12.2 to 0.13.8.

Release notes

Sourced from staticx's releases.

v0.13.8

This is a re-release of v0.13.7 due to an incorrect wheel build. (PyPI doesn't allow re-uploads, and I didn't want to deal with a .post1 release).

https://pypi.org/project/staticx/0.13.8/

v0.13.7

This is a patch release.

https://pypi.org/project/staticx/0.13.7/

Fixed

  • Fixed an issue where library symlinks with the same basename would present problems (#225)
  • Don't crash if .git/ dir is present but git is not installed (#226)
  • Fixed potential issue where bootloader linked against glibc could result in target NSS libraries being loaded and causing a cash at startup (#228)

v0.13.6

This is a patch release.

https://pypi.org/project/staticx/0.13.6/

Changed

  • Change --debug option to appear in CLI help output

Fixed

  • Fix bug sometimes causing a crash when -l is used (#217)

v0.13.5

This is a patch release.

https://pypi.org/project/staticx/0.13.5/

Fixed

  • Handle variables in DT_NEEDED tags as seen in ldd output on RaspPI OS (#210)

v0.13.4

This is a patch release.

https://pypi.org/project/staticx/0.13.4/

Changed

  • Perform RUNPATH auditing on all PyInstaller archive libraries before aborting (#208)

Note: The wheel uploaded here and to PyPI was inadvertently built with GLIBC as opposed to musl-libc. (See 0.13.4 file size vs 0.13.3 file size)

v0.13.3

This is a patch release.

https://pypi.org/project/staticx/0.13.3/

... (truncated)

Changelog

Sourced from staticx's changelog.

[0.13.8] - 2022-08-07

Fixed

  • Fixed a problem with 0.13.7 release whl (PyPI won't allow re-uploads)

[0.13.7] - 2022-08-07

Fixed

  • Fixed an issue where library symlinks with the same basename would present problems (#225)
  • Don't crash if .git/ dir is present but git is not installed (#226)
  • Fixed potential issue where bootloader linked against glibc could result in target NSS libraries being loaded and causing a cash at startup (#228)

[0.13.6] - 2021-12-02

Changed

  • Change --debug option to appear in CLI help output

Fixed

  • Fix bug sometimes causing a crash when -l is used (#217)

[0.13.5] - 2021-10-26

Fixed

  • Handle variables in DT_NEEDED tags as seen in ldd output on RaspPI OS (#210)

[0.13.4] - 2021-10-22

Changed

  • Perform RUNPATH auditing on all PyInstaller archive libraries before aborting (#208)

[0.13.3] - 2021-10-14

Fixed

  • Fix ldd warning about libnssfix.so not being executable (#204)

[0.13.2] - 2021-10-09

Added

  • Log additional diagnostic information at startup (#199)

[0.13.1] - 2021-10-06

Added

  • Log staticx version and arguments at startup (#197)

[0.13.0] - 2021-10-04

Added

  • Added auditing of all shared libraries to detect problematic usages of RPATH/RUNPATH. Libraries now have RPATH/RUNPATH removed while being added, unless those libraries come from a PyInstalled application. (#173)

... (truncated)

Commits
  • e12a69e Release v0.13.8
  • 1674f78 Add build.sh script for consistent release builds
  • 6e4acbd Release v0.13.7
  • 7065692 test: Remove -F flag to pyinstaller when using spec file:
  • 5ac0441 Merge pull request #228 from JonathonReinhart/227-static-glibc-uses-nss
  • e883589 Update changelog for #228
  • 3acfbaa bootloader: Enable fatal linker warnings
  • 6fcecfa libtar: Remove now-unused th_get_uid and th_get_gid
  • 9ef7901 libtar: Remove tar_set_file_perms and restore fchmod call
  • b09953f libtar: Remove unused uid/gid in tar_extract_regfile()
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [staticx](https://github.com/JonathonReinhart/staticx) from 0.12.2 to 0.13.8.
- [Release notes](https://github.com/JonathonReinhart/staticx/releases)
- [Changelog](https://github.com/JonathonReinhart/staticx/blob/master/CHANGELOG.md)
- [Commits](JonathonReinhart/staticx@v0.12.2...v0.13.8)

---
updated-dependencies:
- dependency-name: staticx
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 1, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants