Skip to content

build(deps): bump https://github.com/microsoft/vcpkg from HEAD to 2026.03.18#851

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/vcpkg/https-/github.com/microsoft/vcpkg-2026.03.18
Open

build(deps): bump https://github.com/microsoft/vcpkg from HEAD to 2026.03.18#851
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/vcpkg/https-/github.com/microsoft/vcpkg-2026.03.18

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 23, 2026

Bumps https://github.com/microsoft/vcpkg from HEAD to 2026.03.18. This release includes the previously tagged commit.

Release notes

Sourced from https://github.com/microsoft/vcpkg's releases.

2026.03.18 Release

This release contains a fix for a vulnerability in how vcpkg packaged OpenSSL on Windows: microsoft/vcpkg#50518

The vulnerability was originally reported by TrendAI Zero Day Initiative and assigned ZDI-CAN-29616 (visible at the time of this writing on https://www.zerodayinitiative.com/advisories/upcoming/ ).

If you only want to update OpenSSL you should be able to override the selected version to 3.6.1#3 or later.

Total port count: 2773

Total port count per triplet (tested): https://dev.azure.com/vcpkg/public/_build/results?buildId=128681&view=results

triplet ports available
x86-windows 2583
x64-windows 2714
x64-windows-release 2714
x64-windows-static 2594
x64-windows-static-md (infrastructure failed... 2 days earlier build result was 2648)
arm64-windows 2346
arm64-windows-static-md 2329
arm64-osx 2528
x64-linux 2725
arm64-linux 2091
arm-neon-android 2135
x64-android 2197
arm64-android 2144

The following vcpkg-tool releases have occurred since the last registry release:

In those tool releases, the following changes are particularly meaningful:

port version
ddtdanilo-lmdb-wrapper 1.0.1
frei0r 2.5.4
hesphoros-uniconv 3.3.2
libdxfrw 2025-09-25
libsharp 1.0.0
obfuscxx 1.3.1
sdl3-mixer 3.2.0
spine-c 4.2.20260227
spine-cpp 4.2.20260227
stillwater-universal 3.96

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Bumps [https://github.com/microsoft/vcpkg](https://github.com/microsoft/vcpkg) from HEAD to 2026.03.18. This release includes the previously tagged commit. - [Release notes](https://github.com/microsoft/vcpkg/releases) - [Commits](microsoft/vcpkg@66c0373...c3867e7) --- updated-dependencies: - dependency-name: https://github.com/microsoft/vcpkg dependency-version: 2026.03.18 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file vcpkg_package_manager Pull requests that update vcpkg_package_manager code labels Mar 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file vcpkg_package_manager Pull requests that update vcpkg_package_manager code

0 participants