Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github May 5, 2022

Bumps jubjub from 0.3.0 to 0.9.0.

Changelog

Sourced from jubjub's changelog.

0.9.0

Changed

  • Bumped MSRV to 1.56.0
  • Bumped dependencies to bls12_381 0.7, ff 0.12, group 0.12, bitvec 1.0.

0.8.0

Added

  • jubjub::Base, as an alias for jubjub::Fq.
  • jubjub::AffinePoint::batch_from_bytes, which enables the inversion inside jubjub::AffinePoint::from_bytes to be batched.

Changed

  • Bumped dependencies to bls12_381 0.6, ff 0.11, group 0.11.

0.7.0

Security

  • A bug in the jubjub::{AffinePoint, ExtendedPoint, SubgroupPoint}::from_bytes APIs (and their group::GroupEncoding implementations) has been fixed. The APIs were documented as rejecting non-canonical points, but were accidentally accepting two specific non-canonical encodings. This could potentially cause a problem in consensus-critical protocols that expect encodings to be round-trip compatible (i.e. AffinePoint::from_bytes(b).unwrap().to_bytes() == b). See ZIP 216 for more details.
    • A new API jubjub::AffinePoint::from_bytes_pre_zip216_compatibility preserves the previous behaviour, for use where consensus compatibility is required.

Changed

  • Bumped dependencies to bitvec 0.22, bls12_381 0.5, ff 0.10, group 0.10.
  • MSRV is now 1.51.0.

0.6.0

Changed

  • Bumped dependencies to bitvec 0.20, bls12_381 0.4, ff 0.9, group 0.9, rand_core 0.6.
  • MSRV is now 1.47.0.

0.5.1

Fixed

  • The crate now compiles for non-64-bit targets, such as the wasm32-* targets.

0.5.0

This upgrade bumps our dependencies bls12_381, group and ff, while making corresponding changes to the APIs. This release now only supports Rust compilers version 1.44.0 or later.

... (truncated)

Commits
  • 6af5abf Merge pull request #55 from zkcrypto/release-0.9.0
  • 512b8a8 Release 0.9.0
  • d88e355 Bump MSRV to 1.56.0
  • 00ca002 Merge pull request #54 from zkcrypto/release-0.8.0
  • 85461b8 jubjub 0.8.0
  • d005ba2 bls12_381 0.6, ff 0.11, group 0.11
  • ab1f764 Merge pull request #53 from zkcrypto/base-type
  • 1feb5f4 Add jubjub::Base type alias
  • 53c4895 Merge pull request #52 from zkcrypto/ff-batch-invert
  • 3c7996d Use ff crate version with batch APIs
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [jubjub](https://github.com/zkcrypto/jubjub) from 0.3.0 to 0.9.0.
- [Release notes](https://github.com/zkcrypto/jubjub/releases)
- [Changelog](https://github.com/zkcrypto/jubjub/blob/main/RELEASES.md)
- [Commits](zkcrypto/jubjub@0.3.0...0.9.0)

---
updated-dependencies:
- dependency-name: jubjub
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file rust Pull requests that update Rust code labels May 5, 2022
@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github May 5, 2022

Dependabot tried to add @dconnolly as a reviewer to this PR, but received the following error from GitHub:

POST https://api.github.com/repos/str4d/zebra/pulls/52/requested_reviewers: 422 - Reviews may only be requested from collaborators. One or more of the users or teams you specified is not a collaborator of the str4d/zebra repository. // See: https://docs.github.com/rest/reference/pulls#request-reviewers-for-a-pull-request

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update Rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants