Skip to content

chore(deps): update all major dependencies to v4 in config/_default/params.yaml#511

Closed
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-4-all-major
Closed

chore(deps): update all major dependencies to v4 in config/_default/params.yaml#511
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-4-all-major

Conversation

@renovate

@renovate renovate Bot commented Jun 4, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Update Change Pending
coreruleset-v3 major 3.3.94.26.0 v4.27.0

Release Notes

coreruleset/coreruleset (coreruleset-v3)

v4.26.0

Compare Source

What's Changed
🆕 New features and detections 🎉
🧰 Other Changes
New Contributors

Full Changelog: coreruleset/coreruleset@v4.25.0...v4.26.0

v4.25.0: (LTS)

Compare Source

What's Changed
Important ⭐

These below fix CVE-2026-33691:

  • fix(933111): prevent whitespace padding bypass in PHP double-extension upload by @​fzipi in #​4547
  • fix(933110): prevent whitespace padding bypass in PHP upload detection by @​fzipi in #​4546
  • fix(944140): prevent whitespace padding bypass in JSP file upload detection by @​fzipi in #​4548
🆕 New features and detections 🎉
🧰 Other Changes

Full Changelog: coreruleset/coreruleset@v4.24.1...v4.25.0

v4.24.1

Compare Source

What's Changed
🆕 New features and detections 🎉
Fixes
🧰 Other Changes
New Contributors

Full Changelog: coreruleset/coreruleset@v4.24.0...v4.24.1

v4.24.0

Compare Source

What's Changed
🆕 New features and detections 🎉
🧰 Other Changes

Full Changelog: coreruleset/coreruleset@v4.23.0...v4.24.0

v4.23.0

Compare Source

What's Changed
⭐ Important changes
  • feat(920640): add rule to enforce content-type if there is body by @​fzipi in #​4406
🆕 New features and detections 🎉
🧰 Other Changes
New Contributors

Full Changelog: coreruleset/coreruleset@v4.22.0...v4.23.0

v4.22.0

Compare Source

What's Changed

CRITICAL
  • fix for 9AJ-260102
🧰 Other Changes

Special thanks to @​daytriftnewgen for responsible reporting 9AJ-260102

Full Changelog: coreruleset/coreruleset@v4.21.0...v4.22.0

v4.21.0

Compare Source

What's Changed
🆕 New features and detections 🎉
🧰 Other Changes

Full Changelog: coreruleset/coreruleset@v4.20.0...v4.21.0

v4.20.0

Compare Source

What's Changed

🆕 New features and detections 🎉
🧰 Other Changes

Full Changelog: coreruleset/coreruleset@v4.19.0...v4.20.0

v4.19.0

Compare Source

What's Changed

⭐ Important changes
🆕 New features and detections 🎉
🧰 Other Changes

New Contributors

Full Changelog: coreruleset/coreruleset@v4.18.0...v4.19.0

v4.18.0

Compare Source

What's Changed

🆕 New features and detections 🎉
🧰 Other Changes

Full Changelog: coreruleset/coreruleset@v4.17.1...v4.18.0

v4.17.1

Compare Source

What's Changed

⭐ Important changes
🧰 Other Changes

Full Changelog: coreruleset/coreruleset@v4.17.0...v4.17.1

v4.17.0

Compare Source

[!IMPORTANT]
This release contains a new rule to detect LaTeX injections which was not supposed to be released as it is too prone to false positives in it's current state. Please use v4.17.1 instead.

What's Changed

⭐ Important changes
🆕 New features and detections 🎉
🧰 Other Changes

New Contributors

Full Changelog: coreruleset/coreruleset@v4.16.0...v4.17.0

v4.16.0

Compare Source

What's Changed

🆕 New features and detections 🎉
🧰 Other Changes

New Contributors

Full Changelog: coreruleset/coreruleset@v4.15.0...v4.16.0

v4.15.0

Compare Source

What's Changed

🆕 New features and detections 🎉
🧰 Other Changes

Full Changelog: coreruleset/coreruleset@v4.14.0...v4.15.0

v4.14.0

Compare Source

What's Changed

🆕 New features and detections 🎉
🧰 Other Changes

Full Changelog: coreruleset/coreruleset@v4.13.0...v4.14.0

v4.13.0

Compare Source

What's Changed

⭐ Important changes
🆕 New features and detections 🎉
🪦 Rule removals
  • feat: remove rule 952100 for detecting Java Source Code Leakage by @​S0obi in #​4052
🧰 Other Changes
  • fix(934130): extend prototype pollution payload by @​Xhoenix in #​4036
  • fix: rule 930110 is not supposed to match bare '..' without (back)slashes by @​azurit in #​4050
  • fix: use boundary to fix false positive with email firstname.dockery@host.tld by @​EsadCetiner in #​4045
  • feat: refresh restricted-upload.data by @​S0obi in #​4046
  • fix: tag inconsistency per file by @​Xhoenix in #​4031
  • fix: added pre-check of unset TX variable by @​airween in #​4066
  • fix: false positive found in quantitative testing round 2 for unix rce rules (932230 PL-1, 932235 PL-1, 932250 PL-1, 932260 PL-1, 932231 PL-2, 932220 PL-2, 932236 PL-2, 932239 PL-2, 932232 PL-3, 932238 PL-3) by @​EsadCetiner in #​4019

New Contributors

Full Changelog: coreruleset/coreruleset@v4.12.0...v4.13.0

v4.12.0

Compare Source

What's Changed

🆕 New features and detections 🎉
🧰 Other Changes
  • fix: multipart header tag consistency by @​Xhoenix in #​3992
  • fix: prevent invalid commands matches on 5 characters or less (932220 PL-2, 932230 PL-1, 932232 PL-3, 932235 PL-1, 932236 PL-2, 932237 PL-3, 932238 PL-3, 932239 PL-2, 932250 PL-1, 932260 PL-1) by @​EsadCetiner in #​3735
  • docs: add warnin

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file github-releases major labels Jun 4, 2026
@fzipi fzipi closed this Jun 4, 2026
@renovate

renovate Bot commented Jun 4, 2026

Copy link
Copy Markdown
Contributor Author

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update. You will not get PRs for any future 4.x releases. But if you manually upgrade to 4.x then Renovate will re-enable minor and patch updates automatically.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.

@renovate renovate Bot deleted the renovate/major-4-all-major branch June 4, 2026 08:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github-releases major

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant