Skip to content

⬆️ Update 4 vendored dependencies - #3093

Open
github-actions[bot] wants to merge 1 commit into
masterfrom
update-vendor
Open

⬆️ Update 4 vendored dependencies#3093
github-actions[bot] wants to merge 1 commit into
masterfrom
update-vendor

Conversation

@github-actions

@github-actions github-actions Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

📦 Automatically updated 4 dependencies

Name Old Version New Version Build Status
🚀 git-for-windows 2.52.0.windows.1 2.55.0.windows.4 Build status
⬆️ clink 1.9.5 1.9.31
🚀 windows-terminal 1.23.12811.0 1.24.11911.0 Terminal Build Status
⬆️ clink-completions 0.6.7 0.6.9 Build status

Release notes for updated vendors

git-for-windows

Release notes · Compare changes

Minor changelog

MinGit for Windows 2.53.0(4)

Changes since Git for Windows v2.53.0(3) (April 14th 2026)

This is a security fix release, addressing CVE-2026-62960.

  • CVE-2026-62960, Git for Windows: Attacker-controlled servers may advertise bundle URIs that point to network shares, causing Windows to transparently perform NTLM authentication and disclose the user's NTLMv2 hash. Since NTLM hashing is weak, the captured hash can potentially be brute-forced to recover the user's credentials. This is addressed by limiting the bundle URIs that git clone respects by the same protocol.<name>.allow rules as usual, which excludes file:// URIs by default.
Filename SHA-256
MinGit-2.54.0.3-64-bit.zip abf956f9e8d7f393c8d9a1d974402e55a0682e45fc8340acf1d668ccd4933896
MinGit-2.54.0.3-arm64.zip 3b64234cb3dc22500856e2f5cbeb9c733e64e4a1bd91925d8d74bf09981df968
MinGit-2.54.0.3-32-bit.zip 928ceca1b0ea6367b48e2e9b74489a66edafa123a83f94f4dd0ff08696c10928
MinGit-2.54.0.3-busybox-64-bit.zip 4a6519f7d6e4751e33255f5b7b440801c09f8fd55f2ef7ee...

Release notes truncated; open the release link for the full text.

Git for Windows 2.55.0(4)

Changes since Git for Windows v2.55.0(3) (July 14th 2026)

Following the MSYS2 project, on which Git for Windows is based, Windows 8.1 support will be dropped after Git for Windows v2.55.

This is a security fix release, addressing CVE-2026-62960.

  • CVE-2026-62960, Git for Windows: Attacker-controlled servers may advertise bundle URIs that point to network shares, causing Windows to transparently perform NTLM authentication and disclose the user's NTLMv2 hash. Since NTLM hashing is weak, the captured hash can potentially be brute-forced to recover the user's credentials. This is addressed by limiting the bundle URIs that git clone respects by the same protocol.<name>.allow rules as usual, which excludes file:// URIs by default.
Filename SHA-256
Git-2.55.0.4-64-bit.exe 0cbc0b34a74b3aff3ace0910328549155a770e228331b19cb1498218a120e7ff
Git-2.55.0.4-arm64.exe 8d358f4d53a5a475570edca3124dc0d4f1a020321594984...

Release notes truncated; open the release link for the full text.

MinGit for Windows 2.54.0(3)

Changes since Git for Windows v2.54.0(2) (July 14th 2026)

This is a security fix release, addressing CVE-2026-62960.

  • CVE-2026-62960, Git for Windows: Attacker-controlled servers may advertise bundle URIs that point to network shares, causing Windows to transparently perform NTLM authentication and disclose the user's NTLMv2 hash. Since NTLM hashing is weak, the captured hash can potentially be brute-forced to recover the user's credentials. This is addressed by limiting the bundle URIs that git clone respects by the same protocol.<name>.allow rules as usual, which excludes file:// URIs by default.
Filename SHA-256
MinGit-2.54.0.3-64-bit.zip abf956f9e8d7f393c8d9a1d974402e55a0682e45fc8340acf1d668ccd4933896
MinGit-2.54.0.3-arm64.zip 3b64234cb3dc22500856e2f5cbeb9c733e64e4a1bd91925d8d74bf09981df968
MinGit-2.54.0.3-32-bit.zip 928ceca1b0ea6367b48e2e9b74489a66edafa123a83f94f4dd0ff08696c10928
MinGit-2.54.0.3-busybox-64-bit.zip 4a6519f7d6e4751e33255f5b7b440801c09f8fd55f2ef7eee...

Release notes truncated; open the release link for the full text.

Git for Windows 2.55.0(3)

Changes since Git for Windows v2.55.0(2) (July 2nd 2026)

New Features

Bug Fixes

  • Fixes heap overflows in the credential helper wincred, see GHSA-rxqw-wxqg-g7hw for full details.
Filename SHA-256
Git-2.55.0.3-64-bit.exe af12577d0fdff74243a5988197aa49b957d5044edc17004f6ddf0768996f1dca
Git-2.55.0.3-arm64.exe e3d7f5a2214f214f0a93cf0d8915dab236a0e91c7de6de70a7dbde9a61c794db
PortableGit-2.55.0.3-64-bit.7z.exe ab00566336b5472120f9a52d34f2e79c5406535792acb0548001ffd0bd090e5d
PortableGit-2.55.0.3-arm64.7z.exe 3bf26b94d9399b16a890776e468334f501742861576cbcdea2d9134643c374bd
MinGit-2.55.0.3-64-bit.zip f48e2d2dc74a24454adc6d8fd0ac25bf9c2386f19cfb06202b9465aaad4f9f05
MinGit-2.55.0.3-arm64.zip f7748965d5068e81ad93ca1923650db6742d6e22332b1ae7567a841c59f6bde5
MinGit-2.55.0.3-32-bit.zip 352380d06caa45e569a3b3967b6d1d6c605d564c29f37ef059b59e657a522ef4
MinGit-2.55.0.3-busybox-64-bit.zip cbb2ade2bf690b62f0d692ec64733cb26c6b4ea294...

Release notes truncated; open the release link for the full text.

Git for Windows v2.55.0.windows.2

Changes since Git for Windows v2.55.0 (June 29th 2026)

Following the MSYS2 project, on which Git for Windows is based, Windows 8.1 support will be dropped after Git for Windows v2.55.

Bug Fixes

  • NTLM opt-in support, which had been [prematurely disabled](https://gith...

Release notes truncated; open the release links for the full text.

clink

Release notes · Compare changes

Patch changelog

v1.9.31

Recent Breaking Change

  • Breaking Change: the "gray text" auto-suggestions display is now off by default, due to too many complaints and frustration and support cost.
    • The Suggestions List since v1.8.0 is friendlier and more powerful; toggle it by pressing F2 or enable it by default via clink set suggestionlist.default true.
    • The "gray text" or "inline" auto-suggestions display can be turned on again via clink set autosuggest.inline true if preferred.

v1.9.31

  • Added new Lua API rl.gethistoryindex() which returns the current interactive history index, if any.
  • Fixed git.isgitdir() and git.getgitdir() to not get confused by the empty .git directories that the Codex app leaves scattered around (due to a bug in Codex that's currently tracked by a large number of open issues).
  • Fixed :chaincommand("doskey") to be able to expand doskey aliases (regression introduced in v1.6.18).
  • Fixed an undo list memory management bug in clink-reset-line that could leak memory (regression introduced in v1.8.0)...

Release notes truncated; open the release link for the full text.

v1.9.30

Recent Breaking Change

  • Breaking Change: the "gray text" auto-suggestions display is now off by default, due to too many complaints and frustration and support cost.
    • The Suggestions List since v1.8.0 is friendlier and more powerful; toggle it by pressing F2 or enable it by default via clink set suggestionlist.default true.
    • The "gray text" or "inline" auto-suggestions display can be turned on again via clink set autosuggest.inline true if preferred.

v1.9.30

  • Added new Lua API rl.issuggestionlistactive() which returns whether the suggestion list is currently active.
  • Fixed to not show suggestions if the input line contains only space characters.
  • Fixed clink.onfiltermatches() events (regression introduced in v1.9.26).

v1.9.29

Recent Breaking Change

  • Breaking Change: the "gray text" auto-suggestions display is now off by default, due to too many complaints and frustration and support cost.
    • The Suggestions List since v1.8.0 is friendlier and more powerful; toggle it by pressing F2 or enable it by default via clink set suggestionlist.default true.
    • The "gray text" or "inline" auto-suggestions display can be turned on again via clink set autosuggest.inline true if preferred.

v1.9.29

  • Added new Lua APIs to query Readline's kill-ring (see rl.getkillringcount() and etc).
  • Changed oh-my-posh.clinkprompt to work around an issue where in error cases oh-my-posh can accidentally emit a bash script instead of a Lua script.
  • Fixed how popup lists distributed column widths when fitting them into the terminal width; they were meant to be distributed evenly but were accidentally skewed.
  • Fixed macro text limit in rl.getkeybindings(); it was being limited as though the clink-help command was invoked, but the Lua function shou...

Release notes truncated; open the release link for the full text.

v1.9.28

Recent Breaking Change

  • Breaking Change: the "gray text" auto-suggestions display is now off by default, due to too many complaints and frustration and support cost.
    • The Suggestions List since v1.8.0 is friendlier and more powerful; toggle it by pressing F2 or enable it by default via clink set suggestionlist.default true.
    • The "gray text" or "inline" auto-suggestions display can be turned on again via clink set autosuggest.inline true if preferred.

v1.9.28

  • Fixed a case where clink-select-complete could accidentally wrap long matches with descriptions instead of truncating them.
  • Fixed a case where clink-select-complete could get confused about how many matches it meant to print per line when showing descriptions inline (especially when using a wide terminal window).

v1.9.27

Recent Breaking Change

  • Breaking Change: the "gray text" auto-suggestions display is now off by default, due to too many complaints and frustration and support cost.
    • The Suggestions List since v1.8.0 is friendlier and more powerful; toggle it by pressing F2 or enable it by default via clink set suggestionlist.default true.
    • The "gray text" or "inline" auto-suggestions display can be turned on again via clink set autosuggest.inline true if preferred.

v1.9.27

  • Added new suggestionlist.max_width setting to override the default width of the suggestion list.
  • Changed clink.onhistory() to let the handler function return a string to override what is saved to history.
  • Fixed scrolling jitter while trying to scroll the legacy conhost terminal while Lua scripts are trying to refresh the prompt in the background (e.g. async prompt filtering or animated prompts); refreshing the prompt is paused while the legacy conhost terminal is scrolled, and resumes after the prompt and input line are fully visible again....

_Release notes truncated; open t...

Release notes truncated; open the release links for the full text.

windows-terminal

Release notes · Compare changes

Minor changelog

Windows Terminal Preview v1.25.1912.0

Since we decided to push Terminal 1.26 out a little bit, please enjoy these bug fixes instead.

Bug Fixes

  • Terminal should no longer crash when you drag a small tab into a larger window (which never crashed for some people, and always crashed for others) (#20366) (thanks @yuu61!)
  • Terminal will now make a screen reader-audible announcement when you interact with the expand/collapse option in the Settings page (#20275)
  • Pressing Enter in the Export Text dialog will no longer send Enter to the connected application (#20358)
  • Scrolling the screen should no longer result in us failing to detect URLs in it before the next refresh (#20357)
  • The compatibility.reloadEnvironmentVariables setting will no longer be ignored when you use wt.exe <command> (#20321)
  • The actions editor should now update the action name more consistently (#20381)
  • We have fixed a memory corruption issue in DRCS font handling (#20409)
  • We have speculatively moved some initialization earlier to prevent a deadlock caused by the NVIDIA graphics driver (#20351)
  • We no longer reset your font size if you zoom and we reload settings (for whatever reason) (#20230)

---...

Release notes truncated; open the release link for the full text.

Windows Terminal v1.24.11911.0

The stable channel just keeps getting stabler! We decided to push Terminal 1.26 out a little bit, so hopefully this set of fixes helps fill the void where it would be.

Bug Fixes

  • Terminal should no longer crash when you drag a small tab into a larger window (which never crashed for some people, and always crashed for others) (#20366) (thanks @yuu61!)
  • Terminal will now make a screen reader-audible announcement when you interact with the expand/collapse option in the Settings page (#20275)
  • Pressing Enter in the Export Text dialog will no longer send Enter to the connected application (#20358)
  • Scrolling the screen should no longer result in us failing to detect URLs in it before the next refresh (#20357)
  • We have fixed a memory corruption issue in DRCS font handling (#20409)
  • We have speculatively moved some initialization earlier to prevent a deadlock caused by the NVIDIA graphics driver (#20351)
  • We no longer reset your font size if you zoom and we reload settings (for whatever reason) (#20230)

Binary files inside the unpackaged distribution archive bear the version number 1.24.260710001.

Windows Terminal Preview v1.25.1322.0

This is the fourth servicing release for Terminal! We've fixed a couple of our more annoying issues, and added a new feature thanks to @ltrzesniewski for configuring the new URL warning dialog.

These release notes include changes from v1.25.1241.0 so that you don't need to go read those separately.

Changes

  • You can now change the behavior of the URL warning dialog with the new safeUriSchemes setting (JSON safeUriSchemes, array of strings, default []) (#20207) (thanks @ltrzesniewski!)
  • We have disabled store licensing checks on startup, which should improve launch performance and reliability and prevent the store from deciding that nobody is allowed to run Terminal (#20163)

Bug Fixes

  • We will no longer attempt to allocate too much memory or crash with an access violation on certain specially-crafted Sixel images (#20213)
  • Overridden tab titles should no longer spontaneously reset to Default or Windows PowerShell or the default for any given profile (#20214) (thanks @imsh!)
  • Terminal windows should no longer shrink by one row or column at a time every time you exit neovim (#20183)
  • Terminal's WM_COPYDATA handler will no longer accept outra...

Release notes truncated; open the release link for the full text.

Windows Terminal v1.24.11321.0

Finally! Terminal Stable is getting all of the fun bug fixes that landed in preview over the past couple releases.

Changes

  • Terminal will now display a warning dialog if you attempt to open a URL that might harm your computer (as voted by a bunch of security researchers) (#20065) (#20096)
    • ... and you can change its behavior with the new safeUriSchemes setting (JSON safeUriSchemes, array of strings, default []) (#20207) (thanks @ltrzesniewski!)
  • We have disabled store licensing checks on startup, which should improve launch performance and reliability and prevent the store from deciding that nobody is allowed to run Terminal (#20163)
  • We've reworked how text selection is handled when an application requests mouse mode; Shift clicks will no longer extend an existing selection and positioning will use absolute coordinates rather than selecting the nearest half cell (#19973)
  • Terminal will now assert focus when you drag and drop a file on it (#20003) (thanks @etbala!)

Bug Fixes

  • IME composition will no longer blindly overwrite text to the right of the cursor, but "intelligently" push it further to the right to ensure that it stays vis...

Release notes truncated; open the release link for the full text.

Windows Terminal Preview v1.25.1241.0

This was a short-term bridge release for Windows Terminal Preview that was intended to test our licensing changes before we rolled them out to stable.

Changes

  • We have disabled store licensing checks on startup, which should improve launch performance and reliability and prevent the store from deciding that nobody is allowed to run Terminal (#20163)

Bug Fixes

  • Wordwise selection that starts at a word boundary will no longer selec...

Release notes truncated; open the release links for the full text.

clink-completions

Release notes · Compare changes

Patch changelog

v0.6.9

v0.6.8

  • [git] Added support for git reftables.

v0.6.7

  • [git] Always complete local files for git log and git diff.
    • [git] Clean up file and directory completions to properly support Clink enhancements (e.g. match coloring, the mark-directories var in .inputrc, and so on).
    • [git] Be more clear that git branch -d accepts multiple arguments.
    • [git] Tuned the git color used in git.lua to exactly match the official git color.
    • [git] Fixed "chery" typos in git.lua.
    • [git] Fixed [Bug] cmd_commands.lua:256: attempt to call method 'setcmdcommand' (a nil value) #3050; cmd_commands.lua could encounter a Lua error when using Clink versions older than v1.3.45 (Oct 2022).

v0.6.6

  • [git] Adjust completions for git diff and git log so that e.g. git log ./TAB or git log -- TAB list file completions instead of branches or tags.

v0.6.4

  • Fixed script error when completing procdump due to missing pid_complete module.

v0.6.3

  • Speeded up the initial load time of clink-completions by around 35 milliseconds (maybe more or less, depending on the CPU speed). This also speeds up loading Clink in a new command window.
    • Added completions for Rust: cargo, rustc, and rustup.
    • Added completions for the new Windows sudo command.
    • Added completions for procdump from sysinternals.net.
    • [git] Fixed a freeze in git completion when an aliased command starts with the alias name (include zsh and tmux from cygwin #194).
    • Updated dirx completions.
    • Updated reg completions for *.hiv and *.reg files.
    • Updated where completions to handle its $envvar:pattern and path:pattern syntaxes, and to accept / flags in addition to - flags.
    • Fixed script error in npm.lua if package.json file contains percent signs in certain fields (Open cmder as Tab from the file explorer #197).

v0.6.2

  • [.net] Fixed edge case in dotnet add [PROJECT] package completions.

v0.6.1

  • Updated eza completions.
    • [.net] Updated dotnet add [PROJECT] package completions (Git Not working #192).
    • [git] Fixed git status -uno completion.
    • Turned off debug logging in gh completions by default.

...and 30 more releases. Open the compare link for the full range.


Legend

🚀 Minor version update.
⬆️ Patch version update.

Review note: This update only contains minor or patch changes.

Please verify and then Merge the pull request to apply the updates.

@github-actions
github-actions Bot force-pushed the update-vendor branch 2 times, most recently from 207792c to 9f1d919 Compare June 21, 2026 14:26
@DRSDavidSoft DRSDavidSoft added 👆 Dependencies Pull requests that update a dependency file 🗃️ Vendor Pull requests that update vendored dependencies. labels Jun 30, 2026
@github-actions
github-actions Bot force-pushed the update-vendor branch 3 times, most recently from 3eabf24 to 19d8b60 Compare July 8, 2026 14:27
….31, windows-terminal v1.24.11911.0, clink-completions v0.6.9)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

👆 Dependencies Pull requests that update a dependency file 🗃️ Vendor Pull requests that update vendored dependencies.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] cmd_commands.lua:256: attempt to call method 'setcmdcommand' (a nil value)

1 participant