Repository navigation
chore(deps): update dependency dalli to v5.2.2 - #592
Merged
Merged
Conversation
renovate
Bot
force-pushed
the
renovate/dalli-5.x-lockfile
branch
3 times, most recently
from
October 6, 2026 01:54
87343a7 to
343dc00
Compare
renovate
Bot
force-pushed
the
renovate/dalli-5.x-lockfile
branch
from
October 6, 2026 20:08
343dc00 to
deb8b65
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.2.0→5.2.2Release Notes
petergoldstein/dalli (dalli)
v5.2.2Compare Source
==========
Security:
namespace, a request retried after a transient network error (a timeout, or a connection closed by memcached or a proxy) applied the namespace a second time, so a retried read could return a different key's value and a retried write could overwrite a different keyget_multisince 5.1.0, andget_with_metadataandfetch_with_locksince 4.1.0; fixed in 5.2.2, 5.1.4, 5.0.10 and 4.3.7. Clients without a namespace aren't affectedraw: trueon reads (GHSA-wr87-m4jw-29x5)raw: truedoesn't ask for flags, but a reply carrying them anyway (from a proxy or a hostile server) still had its value deserialized. Raw reads now ignore flags in the replyBug fixes:
get_with_metadataandfetch_with_lockretried the final error raised when a server is marked down, so withdown_retry_delay: 0they retried an unresponsive server forever. They now retry only retryable errors, like other operationsget_multithat didn't finish withinsocket_timeoutcounted towardsocket_max_failures, so two slowget_multicalls in a row marked a healthy server down. It now just closes the connectionquietblock was sent as its own TLS record and system call (2.5 times slower for a block of 2000 deletes). Each flush is one write againsflag could leave the connection out of step or raise a non-Dalli errordecompressed_max_bytesin effect, data after the end of a compressed value's stream was returned as part of the value. It's now ignored, as without the limitdigest_classwhose digests aren't short hex strings, shortening a long key could loop forever. It now raisesArgumentErrorNotes:
Development:
mainand the*-stablebranches only, so a pull request's branch isn't tested twice (once for the push and once for the pull request) (#1198)v5.2.1Compare Source
==========
Security:
get_multireturning one key's value for another after an error reply (GHSA-p6pm-ch9v-44vx)CLIENT_ERROR,SERVER_ERROR, orENfrom a proxy) ended it early, and the replies still on the connection were read as the replies to later commands, so agetcould return another key's valuep_tokenandl_tokennow reject whitespace and control characters, not just CR, LF and NUL. A space let a token add meta flags to the request it was sent with: changing an item's TTL on a read, creating stub items on a miss, turning a delete into a stale tombstone, or reading a different keysocket_max_failuresattempts and the server is marked down, as when it can't be reached at all; it gets a full set of attempts again afterdown_retry_delaycompressorserializersettings. The newdecompressed_max_bytesoption (default 128 MiB;nildisables it) makes a read that would pass it raiseDalli::UnmarshalError. Custom compressors whosedecompresstakes only the data keep working, without the limitDalli::DalliErrorbefore readingraw: trueon reads, and addDalli::JSONSerializer(GHSA-wr87-m4jw-29x5)get_multi,get_multi_cas,get_multi_with_metadata,get_casandget_with_metadataignored a per-requestraw: trueand deserialized the value according to its stored flags, so a caller who asked for raw bytes could still haveMarshal.loadrun on data someone else wrote to memcached. They now return the stored bytesrawpart affectsget_with_metadatasince 4.2.0, and the other methods since they gained per-request options in 5.1.0serializer: JSONreads values withJSON.load, which on json gem versions before 3.0 creates an object of the class named in a storedjson_classkey when the json additions are loaded. The newDalli::JSONSerializerreads withJSON.parseand only returns plain JSON types. The README and the Marshal security warning now recommend it;serializer: JSONitself is unchangedserializer: JSONpart affects any version used with the json gem before 3.0quietblock, sent them again when it closed the client or reconnected: quiet writes ran twice, and the parent's later replies could be read as the replies to other requests, returning one key's value for another. Dalli now buffers requests itself and a forked child discards themBug fixes:
get_multiblock (such asTimeout::Error) was treated as a network failure: swallowed, with the wholeget_multiretried and keys yielded twice. It now reaches the callerNotes:
[BUG] rb_sys_fail_path_in(io_fillbuf, ...) - errno == 0) when a socket read usingIO#timeoutis interrupted by a signal, in the README (#1189)Development:
SECURITY.md), give every workflow a least-privilege token, and pin third-party actions by commit SHA (#1190)Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.