Skip to content

chore(deps): bump the cargo group across 9 directories with 1 update - #531

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-469f54249d
Closed

chore(deps): bump the cargo group across 9 directories with 1 update#531
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-469f54249d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 27, 2026

Copy link
Copy Markdown
Contributor

Bumps the cargo group with 1 update in the / directory: quinn-proto.
Bumps the cargo group with 1 update in the /benches directory: quinn-proto.
Bumps the cargo group with 1 update in the /benches/comparisons/apalis directory: quinn-proto.
Bumps the cargo group with 1 update in the /benches/comparisons/baseline directory: quinn-proto.
Bumps the cargo group with 1 update in the /benches/comparisons/faktory directory: quinn-proto.
Bumps the cargo group with 1 update in the /benches/comparisons/ferriskey-baseline directory: quinn-proto.
Bumps the cargo group with 1 update in the /benches/comparisons/wider directory: quinn-proto.
Bumps the cargo group with 1 update in the /examples/coding-agent directory: quinn-proto.
Bumps the cargo group with 1 update in the /examples/media-pipeline directory: quinn-proto.

Updates quinn-proto from 0.11.14 to 0.11.16

Release notes

Sourced from quinn-proto's releases.

quinn-proto-0.11.16

What's Changed

Commits
  • a96949f Take semver-compatible update for anyhow
  • 5429f60 udp: bump version to 0.5.15
  • 262a493 proto: bump version to 0.11.16
  • c19b63a Upgrade rustls-platform-verifier to 0.7
  • aff3652 Disable default features for fastbloom
  • 01b2eee Upgrade fastbloom to 0.17
  • 2c82013 Switch BBR RNG to PCG
  • 544dd9e Upgrade to rand 0.10.1
  • a7499b8 Bump versions for release
  • 7c1970f proto: yield error on too many gaps in assembler
  • Additional commits viewable in compare view

Updates quinn-proto from 0.11.14 to 0.11.16

Release notes

Sourced from quinn-proto's releases.

quinn-proto-0.11.16

What's Changed

Commits
  • a96949f Take semver-compatible update for anyhow
  • 5429f60 udp: bump version to 0.5.15
  • 262a493 proto: bump version to 0.11.16
  • c19b63a Upgrade rustls-platform-verifier to 0.7
  • aff3652 Disable default features for fastbloom
  • 01b2eee Upgrade fastbloom to 0.17
  • 2c82013 Switch BBR RNG to PCG
  • 544dd9e Upgrade to rand 0.10.1
  • a7499b8 Bump versions for release
  • 7c1970f proto: yield error on too many gaps in assembler
  • Additional commits viewable in compare view

Updates quinn-proto from 0.11.14 to 0.11.16

Release notes

Sourced from quinn-proto's releases.

quinn-proto-0.11.16

What's Changed

Commits
  • a96949f Take semver-compatible update for anyhow
  • 5429f60 udp: bump version to 0.5.15
  • 262a493 proto: bump version to 0.11.16
  • c19b63a Upgrade rustls-platform-verifier to 0.7
  • aff3652 Disable default features for fastbloom
  • 01b2eee Upgrade fastbloom to 0.17
  • 2c82013 Switch BBR RNG to PCG
  • 544dd9e Upgrade to rand 0.10.1
  • a7499b8 Bump versions for release
  • 7c1970f proto: yield error on too many gaps in assembler
  • Additional commits viewable in compare view

Updates quinn-proto from 0.11.14 to 0.11.16

Release notes

Sourced from quinn-proto's releases.

quinn-proto-0.11.16

What's Changed

Commits
  • a96949f Take semver-compatible update for anyhow
  • 5429f60 udp: bump version to 0.5.15
  • 262a493 proto: bump version to 0.11.16
  • c19b63a Upgrade rustls-platform-verifier to 0.7
  • aff3652 Disable default features for fastbloom
  • 01b2eee Upgrade fastbloom to 0.17
  • 2c82013 Switch BBR RNG to PCG
  • 544dd9e Upgrade to rand 0.10.1
  • a7499b8 Bump versions for release
  • 7c1970f proto: yield error on too many gaps in assembler
  • Additional commits viewable in compare view

Updates quinn-proto from 0.11.14 to 0.11.16

Release notes

Sourced from quinn-proto's releases.

quinn-proto-0.11.16

What's Changed

Commits
  • a96949f Take semver-compatible update for anyhow
  • 5429f60 udp: bump version to 0.5.15
  • 262a493 proto: bump version to 0.11.16
  • c19b63a Upgrade rustls-platform-verifier to 0.7
  • aff3652 Disable default features for fastbloom
  • 01b2eee Upgrade fastbloom to 0.17
  • 2c82013 Switch BBR RNG to PCG
  • 544dd9e Upgrade to rand 0.10.1
  • a7499b8 Bump versions for release
  • 7c1970f proto: yield error on too many gaps in assembler
  • Additional commits viewable in compare view

Updates quinn-proto from 0.11.14 to 0.11.16

Release notes

Sourced from quinn-proto's releases.

quinn-proto-0.11.16

What's Changed

Commits
  • a96949f Take semver-compatible update for anyhow
  • 5429f60 udp: bump version to 0.5.15
  • 262a493 proto: bump version to 0.11.16
  • c19b63a Upgrade rustls-platform-verifier to 0.7
  • aff3652 Disable default features for fastbloom
  • 01b2eee Upgrade fastbloom to 0.17
  • 2c82013 Switch BBR RNG to PCG
  • 544dd9e Upgrade to rand 0.10.1
  • a7499b8 Bump versions for release
  • 7c1970f proto: yield error on too many gaps in assembler
  • Additional commits viewable in compare view

Updates quinn-proto from 0.11.14 to 0.11.16

Release notes

Sourced from quinn-proto's releases.

quinn-proto-0.11.16

What's Changed

Commits
  • a96949f Take semver-compatible update for anyhow
  • 5429f60 udp: bump version to 0.5.15
  • 262a493 proto: bump version to 0.11.16
  • c19b63a Upgrade rustls-platform-verifier to 0.7
  • aff3652 Disable default features for fastbloom
  • 01b2eee Upgrade fastbloom to 0.17
  • 2c82013 Switch BBR RNG to PCG
  • 544dd9e Upgrade to rand 0.10.1
  • a7499b8 Bump versions for release
  • 7c1970f proto: yield error on too many gaps in assembler
  • Additional commits viewable in compare view

Updates quinn-proto from 0.11.14 to 0.11.16

Release notes

Sourced from quinn-proto's releases.

quinn-proto-0.11.16

What's Changed

Commits
  • a96949f Take semver-compatible update for anyhow
  • 5429f60 udp: bump version to 0.5.15
  • 262a493 proto: bump version to 0.11.16
  • c19b63a Upgrade rustls-platform-verifier to 0.7
  • aff3652 Disable default features for fastbloom
  • 01b2eee Upgrade fastbloom to 0.17
  • 2c82013 Switch BBR RNG to PCG
  • 544dd9e Upgrade to rand 0.10.1
  • a7499b8 Bump versions for release
  • 7c1970f proto: yield error on too many gaps in assembler
  • Additional commits viewable in compare view

Updates quinn-proto from 0.11.14 to 0.11.16

Release notes

Sourced from quinn-proto's releases.

quinn-proto-0.11.16

What's Changed

Commits
  • a96949f Take semver-compatible update for anyhow
  • 5429f60 udp: bump version to 0.5.15
  • 262a493 proto: bump version to 0.11.16
  • c19b63a Upgrade rustls-platform-verifier to 0.7
  • aff3652 Disable default features for fastbloom
  • 01b2eee Upgrade fastbloom to 0.17
  • 2c82013 Switch BBR RNG to PCG
  • 544dd9e Upgrade to rand 0.10.1
  • a7499b8 Bump versions for release
  • 7c1970f proto: yield error on too many gaps in assembler
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the cargo group with 1 update in the / directory: [quinn-proto](https://github.com/quinn-rs/quinn).
Bumps the cargo group with 1 update in the /benches directory: [quinn-proto](https://github.com/quinn-rs/quinn).
Bumps the cargo group with 1 update in the /benches/comparisons/apalis directory: [quinn-proto](https://github.com/quinn-rs/quinn).
Bumps the cargo group with 1 update in the /benches/comparisons/baseline directory: [quinn-proto](https://github.com/quinn-rs/quinn).
Bumps the cargo group with 1 update in the /benches/comparisons/faktory directory: [quinn-proto](https://github.com/quinn-rs/quinn).
Bumps the cargo group with 1 update in the /benches/comparisons/ferriskey-baseline directory: [quinn-proto](https://github.com/quinn-rs/quinn).
Bumps the cargo group with 1 update in the /benches/comparisons/wider directory: [quinn-proto](https://github.com/quinn-rs/quinn).
Bumps the cargo group with 1 update in the /examples/coding-agent directory: [quinn-proto](https://github.com/quinn-rs/quinn).
Bumps the cargo group with 1 update in the /examples/media-pipeline directory: [quinn-proto](https://github.com/quinn-rs/quinn).


Updates `quinn-proto` from 0.11.14 to 0.11.16
- [Release notes](https://github.com/quinn-rs/quinn/releases)
- [Commits](quinn-rs/quinn@quinn-proto-0.11.14...quinn-proto-0.11.16)

Updates `quinn-proto` from 0.11.14 to 0.11.16
- [Release notes](https://github.com/quinn-rs/quinn/releases)
- [Commits](quinn-rs/quinn@quinn-proto-0.11.14...quinn-proto-0.11.16)

Updates `quinn-proto` from 0.11.14 to 0.11.16
- [Release notes](https://github.com/quinn-rs/quinn/releases)
- [Commits](quinn-rs/quinn@quinn-proto-0.11.14...quinn-proto-0.11.16)

Updates `quinn-proto` from 0.11.14 to 0.11.16
- [Release notes](https://github.com/quinn-rs/quinn/releases)
- [Commits](quinn-rs/quinn@quinn-proto-0.11.14...quinn-proto-0.11.16)

Updates `quinn-proto` from 0.11.14 to 0.11.16
- [Release notes](https://github.com/quinn-rs/quinn/releases)
- [Commits](quinn-rs/quinn@quinn-proto-0.11.14...quinn-proto-0.11.16)

Updates `quinn-proto` from 0.11.14 to 0.11.16
- [Release notes](https://github.com/quinn-rs/quinn/releases)
- [Commits](quinn-rs/quinn@quinn-proto-0.11.14...quinn-proto-0.11.16)

Updates `quinn-proto` from 0.11.14 to 0.11.16
- [Release notes](https://github.com/quinn-rs/quinn/releases)
- [Commits](quinn-rs/quinn@quinn-proto-0.11.14...quinn-proto-0.11.16)

Updates `quinn-proto` from 0.11.14 to 0.11.16
- [Release notes](https://github.com/quinn-rs/quinn/releases)
- [Commits](quinn-rs/quinn@quinn-proto-0.11.14...quinn-proto-0.11.16)

Updates `quinn-proto` from 0.11.14 to 0.11.16
- [Release notes](https://github.com/quinn-rs/quinn/releases)
- [Commits](quinn-rs/quinn@quinn-proto-0.11.14...quinn-proto-0.11.16)

---
updated-dependencies:
- dependency-name: quinn-proto
  dependency-version: 0.11.16
  dependency-type: indirect
  dependency-group: cargo
- dependency-name: quinn-proto
  dependency-version: 0.11.16
  dependency-type: indirect
  dependency-group: cargo
- dependency-name: quinn-proto
  dependency-version: 0.11.16
  dependency-type: indirect
  dependency-group: cargo
- dependency-name: quinn-proto
  dependency-version: 0.11.16
  dependency-type: indirect
  dependency-group: cargo
- dependency-name: quinn-proto
  dependency-version: 0.11.16
  dependency-type: indirect
  dependency-group: cargo
- dependency-name: quinn-proto
  dependency-version: 0.11.16
  dependency-type: indirect
  dependency-group: cargo
- dependency-name: quinn-proto
  dependency-version: 0.11.16
  dependency-type: indirect
  dependency-group: cargo
- dependency-name: quinn-proto
  dependency-version: 0.11.16
  dependency-type: indirect
  dependency-group: cargo
- dependency-name: quinn-proto
  dependency-version: 0.11.16
  dependency-type: indirect
  dependency-group: cargo
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Jul 27, 2026
@avifenesh

Copy link
Copy Markdown
Owner

Closing this partial Dependabot batch rather than merging it with known failures. The branch was generated while additional advisories were still arriving and does not cover all affected manifests. After #532 and #533 land, Dependabot should recreate the cargo group against the clean base and verify every remaining alert.

@avifenesh avifenesh closed this Jul 30, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jul 30, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/cargo/cargo-469f54249d branch July 30, 2026 21:46
avifenesh added a commit that referenced this pull request Jul 30, 2026
* security: clear all open RUSTSEC findings (quinn-proto, anyhow, scc, spin)

cargo audit --deny warnings was failing on main with 3 denied warnings,
which blocked the cargo-group Dependabot PR (#531) carrying the
quinn-proto security bump. Resolves all four in one lockfile update:

  quinn-proto 0.11.14 -> 0.11.16  RUSTSEC-2026-0185 (7.5 high)
      remote memory exhaustion via unbounded out-of-order stream
      reassembly — the actual vulnerability, superset of #531
  anyhow      1.0.102 -> 1.0.104  RUSTSEC-2026-0190 (unsound)
      unsoundness in Error::downcast_mut(); patched >= 1.0.103
  scc         2.4.0   -> removed  RUSTSEC-2026-0205 (unsound)
      Array::insert exception-safety / potential double-free. Reached
      only as a dev-dependency via serial_test 3.4; serial_test 3.5.0
      drops the scc dependency entirely, so no major bump is needed
      (scc's own fix is 3.8.4, a major jump).
  spin        0.9.8   -> 0.9.9    yanked-crate warning
      transitive under sqlx-sqlite -> flume; 0.9.9 is not yanked.

Lockfile only — no manifest ranges changed, no majors introduced, and
no new entries added to the .cargo/audit.toml / deny.toml ignore lists.

Verified: cargo audit --deny warnings exits 0 (468 deps scanned, zero
findings); cargo check --workspace --all-targets succeeds.

* fix(ferriskey): clear two clippy lib errors blocking every matrix job

cargo clippy -D warnings fails on main in the ferriskey lib, which takes
down all three clippy invocations in matrix.yml / release.yml (the scoped
workspace job compiles ferriskey as a dependency, so it fails there too)
and with it every `valkey N · standalone|cluster` matrix leg.

  cluster/routing.rs:552  clippy::for_kv_map
      `for (_, arg_indices) in routes.iter_mut()` -> `routes.values_mut()`
  cmd.rs:74               clippy::question_mark
      collapse the if-let/else-return into `self.cmd.cursor?`; next_item
      already returns Option<T> and uses `?` further down, so this is the
      idiom the surrounding code already follows

Pre-existing debt, not a regression: verified identical failures on a
clean checkout of main at 0def596 with no local changes.

Verified all three CI clippy invocations now exit 0:
  cargo clippy -p ff-core -p ff-script -p ff-engine -p ff-scheduler \
    -p ff-sdk -p ff-server -p ff-test -p ff-backend-sqlite \
    --features ff-sdk/direct-valkey-claim -- -D warnings
  cargo clippy -p ferriskey --all-targets -- -D warnings
  cargo clippy -p ferriskey --all-targets --features iam -- -D warnings
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant