Skip to content

[Release 2026.4.1] Updating curl - #4621

Merged
przepeck merged 1 commit into
releases/2026/4from
przepeck-releases-curl-update
Oct 2, 2026
Merged

przepeck merged 1 commit into
releases/2026/4from
przepeck-releases-curl-update

Conversation

@przepeck

@przepeck przepeck commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

🛠 Summary

BDBA found multiple vulnerabilities in current version of curl. Updating it on Windows.

🧪 Checklist

  • Unit tests added.
  • The documentation updated.
  • Change follows security best practices.
    ``

@przepeck
przepeck requested review from dtrawins and michalkulakowski and a balanced review from Copilot October 2, 2026 09:44

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The valid dependency version is updated consistently across all Windows build references.

Review effort: Balanced
Findings: None

What changed in this PR

Updates the Windows curl dependency to address reported vulnerabilities.

Changes:

  • Upgrades curl from 8.21.0_7 to 8.22.0_2.
  • Aligns Bazel, libgit2, and Windows dependency configuration.
File Description
WORKSPACE Updates the Windows curl repository path.
versions.mk Sets the new curl package version.
third_party/​libgit2/​libgit2_engine.bzl Points libgit2 to the updated curl directory.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@przepeck
przepeck merged commit cfc9ac7 into releases/2026/4 Oct 2, 2026
2 checks passed
@przepeck
przepeck deleted the przepeck-releases-curl-update branch October 2, 2026 10:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants