chore(deps): bump the cargo group across 1 directory with 4 updates - #827
Open
dependabot[bot] wants to merge 1 commit into
Open
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the cargo group with 4 updates in the / directory: [quinn-proto](https://github.com/quinn-rs/quinn), [rustls-webpki](https://github.com/rustls/webpki), [serde_with](https://github.com/jonasbb/serde_with) and [tar](https://github.com/composefs/tar-rs). Updates `quinn-proto` from 0.11.14 to 0.11.17 - [Release notes](https://github.com/quinn-rs/quinn/releases) - [Commits](quinn-rs/quinn@quinn-proto-0.11.14...quinn-proto-0.11.17) Updates `rustls-webpki` from 0.103.9 to 0.103.15 - [Release notes](https://github.com/rustls/webpki/releases) - [Commits](rustls/webpki@v/0.103.9...v/0.103.15) Updates `serde_with` from 3.16.1 to 3.17.0 - [Release notes](https://github.com/jonasbb/serde_with/releases) - [Commits](jonasbb/serde_with@v3.16.1...v3.17.0) Updates `tar` from 0.4.45 to 0.4.46 - [Release notes](https://github.com/composefs/tar-rs/releases) - [Commits](composefs/tar-rs@0.4.45...0.4.46) --- updated-dependencies: - dependency-name: quinn-proto dependency-version: 0.11.17 dependency-type: indirect dependency-group: cargo - dependency-name: rustls-webpki dependency-version: 0.103.15 dependency-type: indirect dependency-group: cargo - dependency-name: serde_with dependency-version: 3.17.0 dependency-type: indirect dependency-group: cargo - dependency-name: tar dependency-version: 0.4.46 dependency-type: indirect dependency-group: cargo ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
The undocumented rand 0.10 upgrade must be reverted or explicitly scoped and validated.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Updates Cargo dependencies, including security fixes for networking, certificate validation, and archive parsing.
Changes:
- Updates four declared dependencies and related lockfile entries.
- Also upgrades the undocumented
randdev-dependency from 0.9 to 0.10.
File summaries
| File | Description |
|---|---|
nusamai/Cargo.toml |
Contains an unannounced major-version rand upgrade requiring reversal or explicit validation. |
Cargo.lock |
Records updated direct and transitive dependencies. |
Review details
- Files reviewed: 1/2 changed files
- Comments generated: 1
- Review effort level: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
|
||
| [dev-dependencies] | ||
| rand = "0.9.3" | ||
| rand = "0.10.1" |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files
📢 Thoughts on this report? Let us know! 🚀 New features to boost your workflow:
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the cargo group with 4 updates in the / directory: quinn-proto, rustls-webpki, serde_with and tar.
Updates
quinn-protofrom 0.11.14 to 0.11.17Release notes
Sourced from quinn-proto's releases.
Commits
0343120proto: bump version to 0.11.17d7bf3d0Limit total memory used to buffer outgoing datagrams31ca5d2Limit total memory used to buffer incoming datagrams3a78b60Factor out DatagramBuffer for queues in either directionb37ced3proto: check limits when processing already retired CIDs6a984b8proto: extract method for checking CID retirements499dba8proto: bound assembler chunk count regardless of over-allocation33ce0c2congestion: saturate CUBIC window increment to avoid overflowc8ad7e6fix(ci): fix clippy lintsa96949fTake semver-compatible update for anyhowUpdates
rustls-webpkifrom 0.103.9 to 0.103.15Release notes
Sourced from rustls-webpki's releases.
... (truncated)
Commits
c14836dCargo: version 0.103.14 -> 0.103.155c92308Cargo: avoid all-features in docs.rs10a1514Mark ML-DSA algorithms as FIPS submitted14cbaa1Bump version to 0.103.14cbb868aSupport stable ML-DSA with aws-lc-rsc782fd1Update to aws-lc-rs 1.18b250e31Upgrade to base64 0.2399115b2ci: sync cargo-check-external-types nightlya82bfaecrl: fix clippy::question_mark finding2879b2cPrepare 0.103.13Updates
serde_withfrom 3.16.1 to 3.17.0Release notes
Sourced from serde_with's releases.
Commits
4031878Bump version to v3.17.0 (#924)204ae56Bump version to v3.17.07812b5aserde_yaml 0.9 to yaml_serde 0.10 (#921)614bd89Bump MSRV to 1.82 as required by yaml_serde518d0edSuppress RUSTSEC-2026-0009 since we don't have untrusted time input in tests ...a6579a8Suppress RUSTSEC-2026-0009 since we don't have untrusted time input in tests9d4d069Implement OneOrMany for smallvec_1::SmallVec (#922)fc78243Add changelog2b8c30bImplement OneOrMany for smallvec_1::SmallVec2d9b9a1Carg.lock updateUpdates
tarfrom 0.4.45 to 0.4.46Release notes
Sourced from tar's releases.
Commits
fc459c1Release 0.4.4643e05a8ci: Add crates.io trusted publishing workflowbba5666Update repo linkscd94c46docs: Document TOCTOU / concurrent-mutation threat model1b4997cbuilder: Expand docs for follow_symlinks and append_dir_allbab14ddarchive: Fix another PAX header desync (GHSA-3cv2-h65g-fgmm)2349b49Add support of absolute paths39d0311Update some links59d803eUpdate astral-tokio-tar requirement from 0.5 to 0.68296b9aci: Fix and re-enable reverse dependency testing (#444)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.