Skip to content

chore(deps): bump https://github.com/microsoft/vcpkg from HEAD to 2026.03.18#534

Closed
dependabot[bot] wants to merge 1 commit into
developmentfrom
dependabot/vcpkg/https-/github.com/microsoft/vcpkg-2026.03.18
Closed

chore(deps): bump https://github.com/microsoft/vcpkg from HEAD to 2026.03.18#534
dependabot[bot] wants to merge 1 commit into
developmentfrom
dependabot/vcpkg/https-/github.com/microsoft/vcpkg-2026.03.18

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Mar 21, 2026

Bumps https://github.com/microsoft/vcpkg from HEAD to 2026.03.18. This release includes the previously tagged commit.

Release notes

Sourced from https://github.com/microsoft/vcpkg's releases.

2026.03.18 Release

This release contains a fix for a vulnerability in how vcpkg packaged OpenSSL on Windows: microsoft/vcpkg#50518

The vulnerability was originally reported by Xavier DANEST working with TrendAI Zero Day Initiative and assigned ZDI-CAN-29616 (visible at the time of this writing on https://www.zerodayinitiative.com/advisories/upcoming/ ). It has also been recorded as GitHub advisory GHSA-p322-v6vw-vrq9 .

If you only want to update OpenSSL you should be able to override the selected version to 3.6.1#3 or later.

Total port count: 2773

Total port count per triplet (tested): https://dev.azure.com/vcpkg/public/_build/results?buildId=128681&view=results

triplet ports available
x86-windows 2583
x64-windows 2714
x64-windows-release 2714
x64-windows-static 2594
x64-windows-static-md (infrastructure failed... 2 days earlier build result was 2648)
arm64-windows 2346
arm64-windows-static-md 2329
arm64-osx 2528
x64-linux 2725
arm64-linux 2091
arm-neon-android 2135
x64-android 2197
arm64-android 2144

The following vcpkg-tool releases have occurred since the last registry release:

In those tool releases, the following changes are particularly meaningful:

port version
ddtdanilo-lmdb-wrapper 1.0.1
frei0r 2.5.4
hesphoros-uniconv 3.3.2
libdxfrw 2025-09-25
libsharp 1.0.0
obfuscxx 1.3.1
sdl3-mixer 3.2.0
spine-c 4.2.20260227
spine-cpp 4.2.20260227
stillwater-universal 3.96

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file vcpkg_package_manager Pull requests that update vcpkg_package_manager code labels Mar 21, 2026
@dependabot dependabot Bot requested a review from nam20485 as a code owner March 21, 2026 06:32
@dependabot dependabot Bot added the vcpkg_package_manager Pull requests that update vcpkg_package_manager code label Mar 21, 2026
@github-actions
Copy link
Copy Markdown

github-actions Bot commented Mar 21, 2026

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Snapshot Warnings

⚠️: The number of snapshots compared for the base SHA (2) and the head SHA (1) do not match. You may see unexpected removals in the diff.
Consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice.

OpenSSF Scorecard

PackageVersionScoreDetails

Scanned Files

@kilo-code-bot
Copy link
Copy Markdown

kilo-code-bot Bot commented Mar 21, 2026

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Overview

This Dependabot PR updates the vcpkg baseline from commit d1ff36c to c3867e7, bringing in the 2026.03.18 release. Key changes include a security fix for a vulnerability in how vcpkg packaged OpenSSL on Windows (ZDI-CAN-29616 / GHSA-p322-v6vw-vrq9).

Severity Count
CRITICAL 0
WARNING 0
SUGGESTION 0
Files Reviewed (1 file)
  • vcpkg-configuration.json - Dependency version update only, no code issues

Reviewed by minimax-m2.5-20260211 · 164,061 tokens

@dependabot dependabot Bot changed the title build(deps): bump https://github.com/microsoft/vcpkg from HEAD to 2026.03.18 chore(deps): bump https://github.com/microsoft/vcpkg from HEAD to 2026.03.18 Apr 16, 2026
Bumps [https://github.com/microsoft/vcpkg](https://github.com/microsoft/vcpkg) from HEAD to 2026.03.18. This release includes the previously tagged commit.
- [Release notes](https://github.com/microsoft/vcpkg/releases)
- [Commits](microsoft/vcpkg@d1ff36c...c3867e7)

---
updated-dependencies:
- dependency-name: https://github.com/microsoft/vcpkg
  dependency-version: 2026.03.18
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/vcpkg/https-/github.com/microsoft/vcpkg-2026.03.18 branch from f64ddd2 to 809d0eb Compare April 16, 2026 03:47
@codacy-production
Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

TIP This summary will be updated as you push new changes. Give us feedback

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github May 2, 2026

Superseded by #543.

@dependabot dependabot Bot closed this May 2, 2026
@dependabot dependabot Bot deleted the dependabot/vcpkg/https-/github.com/microsoft/vcpkg-2026.03.18 branch May 2, 2026 06:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file vcpkg_package_manager Pull requests that update vcpkg_package_manager code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants