-
-
Notifications
You must be signed in to change notification settings - Fork 395
Bump the cargo group with 12 updates #1977
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Bumps the cargo group with 12 updates: | Package | From | To | | --- | --- | --- | | [clap_complete](https://github.com/clap-rs/clap) | `4.5.47` | `4.5.48` | | [rustix](https://github.com/bytecodealliance/rustix) | `1.0.5` | `1.0.7` | | [syn](https://github.com/dtolnay/syn) | `2.0.100` | `2.0.101` | | [insta](https://github.com/mitsuhiko/insta) | `1.42.2` | `1.43.1` | | [async-executor](https://github.com/smol-rs/async-executor) | `1.13.1` | `1.13.2` | | [openssl-sys](https://github.com/sfackler/rust-openssl) | `0.9.107` | `0.9.108` | | [quinn-udp](https://github.com/quinn-rs/quinn) | `0.5.11` | `0.5.12` | | [synstructure](https://github.com/mystor/synstructure) | `0.13.1` | `0.13.2` | | [toml](https://github.com/toml-rs/toml) | `0.8.20` | `0.8.22` | | [toml_datetime](https://github.com/toml-rs/toml) | `0.6.8` | `0.6.9` | | [toml_edit](https://github.com/toml-rs/toml) | `0.22.24` | `0.22.26` | | [webpki-roots](https://github.com/rustls/webpki-roots) | `0.26.8` | `0.26.10` | Updates `clap_complete` from 4.5.47 to 4.5.48 - [Release notes](https://github.com/clap-rs/clap/releases) - [Changelog](https://github.com/clap-rs/clap/blob/master/CHANGELOG.md) - [Commits](clap-rs/clap@clap_complete-v4.5.47...clap_complete-v4.5.48) Updates `rustix` from 1.0.5 to 1.0.7 - [Release notes](https://github.com/bytecodealliance/rustix/releases) - [Changelog](https://github.com/bytecodealliance/rustix/blob/main/CHANGES.md) - [Commits](bytecodealliance/rustix@v1.0.5...v1.0.7) Updates `syn` from 2.0.100 to 2.0.101 - [Release notes](https://github.com/dtolnay/syn/releases) - [Commits](dtolnay/syn@2.0.100...2.0.101) Updates `insta` from 1.42.2 to 1.43.1 - [Release notes](https://github.com/mitsuhiko/insta/releases) - [Changelog](https://github.com/mitsuhiko/insta/blob/master/CHANGELOG.md) - [Commits](mitsuhiko/insta@1.42.2...1.43.1) Updates `async-executor` from 1.13.1 to 1.13.2 - [Release notes](https://github.com/smol-rs/async-executor/releases) - [Changelog](https://github.com/smol-rs/async-executor/blob/master/CHANGELOG.md) - [Commits](smol-rs/async-executor@v1.13.1...v1.13.2) Updates `openssl-sys` from 0.9.107 to 0.9.108 - [Release notes](https://github.com/sfackler/rust-openssl/releases) - [Commits](rust-openssl/rust-openssl@openssl-sys-v0.9.107...openssl-sys-v0.9.108) Updates `quinn-udp` from 0.5.11 to 0.5.12 - [Release notes](https://github.com/quinn-rs/quinn/releases) - [Commits](quinn-rs/quinn@quinn-udp-0.5.11...quinn-udp-0.5.12) Updates `synstructure` from 0.13.1 to 0.13.2 - [Commits](https://github.com/mystor/synstructure/commits) Updates `toml` from 0.8.20 to 0.8.22 - [Commits](toml-rs/toml@toml-v0.8.20...toml-v0.8.22) Updates `toml_datetime` from 0.6.8 to 0.6.9 - [Commits](toml-rs/toml@toml_datetime-v0.6.8...toml_datetime-v0.6.9) Updates `toml_edit` from 0.22.24 to 0.22.26 - [Commits](toml-rs/toml@v0.22.24...v0.22.26) Updates `webpki-roots` from 0.26.8 to 0.26.10 - [Release notes](https://github.com/rustls/webpki-roots/releases) - [Commits](rustls/webpki-roots@v/0.26.8...v/0.26.10) --- updated-dependencies: - dependency-name: clap_complete dependency-version: 4.5.48 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo - dependency-name: rustix dependency-version: 1.0.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo - dependency-name: syn dependency-version: 2.0.101 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo - dependency-name: insta dependency-version: 1.43.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo - dependency-name: async-executor dependency-version: 1.13.2 dependency-type: indirect update-type: version-update:semver-patch dependency-group: cargo - dependency-name: openssl-sys dependency-version: 0.9.108 dependency-type: indirect update-type: version-update:semver-patch dependency-group: cargo - dependency-name: quinn-udp dependency-version: 0.5.12 dependency-type: indirect update-type: version-update:semver-patch dependency-group: cargo - dependency-name: synstructure dependency-version: 0.13.2 dependency-type: indirect update-type: version-update:semver-patch dependency-group: cargo - dependency-name: toml dependency-version: 0.8.22 dependency-type: indirect update-type: version-update:semver-patch dependency-group: cargo - dependency-name: toml_datetime dependency-version: 0.6.9 dependency-type: indirect update-type: version-update:semver-patch dependency-group: cargo - dependency-name: toml_edit dependency-version: 0.22.26 dependency-type: indirect update-type: version-update:semver-patch dependency-group: cargo - dependency-name: webpki-roots dependency-version: 0.26.10 dependency-type: indirect update-type: version-update:semver-patch dependency-group: cargo ... Signed-off-by: dependabot[bot] <[email protected]>
The newly listed license is permissive. Specifically: - https://cdla.dev/permissive-2-0/ - https://spdx.org/licenses/CDLA-Permissive-2.0.html It is newly used by `webpki-roots` for data that were formerly marked as being licensed under MPL-2.0. For full details, see: - https://github.com/rustls/webpki-roots/releases/tag/v%2F0.26.9 - rustls/webpki-roots#88 - mozilla/www.ccadb.org#188 MPL-2.0 is not delisted, as we still need it at least for `uluru`.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM. The upgrade of webpki-roots, which is a transitive dependency through reqwest and some other packages, carries data that are licensed under CDLA-Permissive-2.0 (rustls/webpki-roots#88), which is a different (more permissive) license than before. The second commit I added here, f3a4ad6, allowlists that license. See the commit message for further details.
|
@dependabot merge |
Bumps the cargo group with 12 updates:
4.5.474.5.481.0.51.0.72.0.1002.0.1011.42.21.43.11.13.11.13.20.9.1070.9.1080.5.110.5.120.13.10.13.20.8.200.8.220.6.80.6.90.22.240.22.260.26.80.26.10Updates
clap_completefrom 4.5.47 to 4.5.48Commits
c3a1ddcchore: Release4460ff4docs: Update changelog54947a1Merge pull request #5981 from mernen/fix-bash-clap-complete-spacefd3f6d2fix(complete): Restore nospace in bash2f6a108test(complete): Demonstrate current behaviorf88be57style: Ensure consistent newlinesf209bcechore: Releasef33ff7fdocs: Update changelogbf06e6fMerge pull request #5974 from kryvashek/support-clearing-args-matches5d357adfeat(parser): Added ArgMatches::try_clear_id()Updates
rustixfrom 1.0.5 to 1.0.7Commits
6883580chore: Release rustix version 1.0.7fc794e9Fix the assertion inPid::from_rawto accept 0. (#1456)5ce17dbchore: Release rustix version 1.0.6cd95201Remove pidfd_send_signal from not_implemented (#1448)4fbc05cAlways castpread,lseeketc. offsets tooff_t. (#1442)4626b69Document that negative pids aren't UB, but may cause unexpected behavior. (#1...ca41f0aAdd trap instructions afternoreturnsyscalls. (#1444)Updates
synfrom 2.0.100 to 2.0.101Release notes
Sourced from syn's releases.
Commits
58336a3Release 2.0.101f1612ccMerge pull request #1861 from JakobDegen/turbofishd04eea1Fix lifetime onas_turbofish432b303Resolve renamed_and_removed_lints warning about match_on_vec_items1353d60Update test suite to nightly-2025-04-083980ff2Improve wording of comment in advance_to implementation8328b52Update test suite to nightly-2025-04-051d2e2beUpdate test suite to nightly-2025-04-032400946Update test suite to nightly-2025-04-02114a629Update test suite to nightly-2025-03-27Updates
instafrom 1.42.2 to 1.43.1Release notes
Sourced from insta's releases.
Changelog
Sourced from insta's changelog.
Commits
82c6224Update runners fordiston musl (#769)c055282Bump versions to 1.43.1 (#767)7335b55Update runners fordist(#768)34196dabump version to 1.43.0 (#763)fd8ec9ffix--unreferenced=autoclearing new pending snapshots (#762)f781958Rename process_snapshots function to review_snapshots for clarity (#761)93b12c6Add pre-commit hook for Rust code formatting (#760)e91a7acfixunreferencednot being read from config file (#759)7aa23e0small simplification of macros (#758)2c30a7fRun with--force-update-snapshots(#749)Updates
async-executorfrom 1.13.1 to 1.13.2Release notes
Sourced from async-executor's releases.
Changelog
Sourced from async-executor's changelog.
Commits
3d912bbRelease 1.13.260a2185ci: Use reusable workflows for fmt and security_audit47739f1Reduce memory footprint76bea84deps: Bump slab to v0.4.70c216e8Ignore poisoning ofactive9335b7eci: Use "v2.0.0" branch for security check0a20bc8Merge pull request #128 from lewiszlw/patch-1fc33b2bFix build badgeUpdates
openssl-sysfrom 0.9.107 to 0.9.108Release notes
Sourced from openssl-sys's releases.
Commits
132418bMerge pull request #2399 from alex/release-sysf7a692bRelease openssl-sys v0.9.1082f9b496Merge pull request #2398 from botovq/libressl-4.1ae9d988Replace LibreSSL 3.8 with 4.1 in CI5292decAllow libressl 4.1.0 (stable release)6a45982Merge pull request #2392 from sfackler/alex-patch-1df0e2f0test against openssl 3.5.0Updates
quinn-udpfrom 0.5.11 to 0.5.12Release notes
Sourced from quinn-udp's releases.
Commits
6b901a3quinn-udp: sanitisesegment_size458295cchore(udp): increase crate patch version to v0.5.1276b8916fix(udp): zero control message array on fast-apple-datapath8936cc0Bump the quinn-proto version to 0.11.11 for releaseb406b98build(deps): bump rand from 0.9.0 to 0.9.137beebfdocs(quinn): Copy edit poll_read(_buf?) docs19a625dfix(quinn-udp): move cmsg-len check to Iterator3f94660ci: runquinn-udpfast-data-path tests107dd92ci: run macOS tests conditionally on runner OSc7687f7refactor(quinn-udp): usematchblocks inrecvUpdates
synstructurefrom 0.13.1 to 0.13.2Commits
Updates
tomlfrom 0.8.20 to 0.8.22Commits
6922da3chore: Releasefbf0a92docs: Update changelog83588b3Merge pull request #878 from epage/w1eeb885cfix(serde): Skip fields with newtypes wrapping None3c305c7test(serde): Show NewType(None) behavior7bd5eaftest(serde): Group None tests388cfa3chore(deps): Update toml-test (#877)a025b84refactor(edit): Change ser none tracking to mut field54666addocs(write): Add guidance13cf518refactor(edit): Bypass a layer of abstraction in serUpdates
toml_datetimefrom 0.6.8 to 0.6.9Commits
4021081chore: Release3312698chore: Releaseb25da32docs: Update changelog8844949docs(write): Update base commit5406815Merge pull request #875 from epage/wc6479a2refactor(toml): Pull out ValueSerializer for easier comparison8c43cf8refactor(toml): Remove redundant non_exhaustive268a1f8Merge pull request #874 from epage/we406f94refactor(toml): Split ser module4d782f8refactor(edit): Rely on type alias in serUpdates
toml_editfrom 0.22.24 to 0.22.26Commits
6922da3chore: Releasefbf0a92docs: Update changelog83588b3Merge pull request #878 from epage/w1eeb885cfix(serde): Skip fields with newtypes wrapping None3c305c7test(serde): Show NewType(None) behavior7bd5eaftest(serde): Group None tests388cfa3chore(deps): Update toml-test (#877)a025b84refactor(edit): Change ser none tracking to mut field54666addocs(write): Add guidance13cf518refactor(edit): Bypass a layer of abstraction in serUpdates
webpki-rootsfrom 0.26.8 to 0.26.10Release notes
Sourced from webpki-roots's releases.
Commits
e37165dwebpki-(roots|root-certs): v0.26.9 -> v0.26.104a4e2aaApril CCADB updates:82c433ewebpki-ccadb: support placeholder absent trust bits5b76d00Address new nightly clippy lints7c4a882Move to 2021 edition575994bwebpki-(roots|root-certs): v0.26.8 -> v0.26.9f9f5789manual_ok_errclippy fixfce41f7Support code-signing trust bitf19c83fRun CI on ubuntu-latest90c48f3Adjust license of mechanically-reformed cratesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot will merge this PR once CI passes on it, as requested by @EliahKagan.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions