Security update for nghttp2

This update for nghttp2 fixes the following issues:

nghttp2 was update to version 1.40.0 (bsc#1166481)

- lib: Add nghttp2_check_authority as public API
- lib: Fix the bug that stream is closed with wrong error code
- lib: Faster huffman encoding and decoding
- build: Avoid filename collision of static and dynamic lib
- build: Add new flag ENABLE_STATIC_CRT for Windows
- build: cmake: Support building nghttpx with systemd
- third-party: Update neverbleed to fix memory leak
- nghttpx: Fix bug that mruby is incorrectly shared between backends
- nghttpx: Reconnect h1 backend if it lost connection before sending headers
- nghttpx: Returns 408 if backend timed out before sending headers
- nghttpx: Fix request stal

This update was imported from the SUSE:SLE-15:Update update project.

Fixed bugs
bnc#1166481
envoy-proxy and cilium-proxy (CaaSP) need nghttp2 1.40 for their CVE-2019-18802 fix
bnc#1159003
VUL-0: CVE-2019-18802: cilium-proxy: malformed request header may cause bypass of route matchers resulting in escalation of privileges or information disclosure
Selected Binaries
openSUSE Build Service is sponsored by