Bump the cargo group across 1 directory with 14 updates - #36
Open
dependabot[bot] wants to merge 1 commit into
Open
Bump the cargo group across 1 directory with 14 updates#36dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the cargo group with 14 updates in the /rust directory: | Package | From | To | | --- | --- | --- | | [diesel](https://github.com/diesel-rs/diesel) | `2.1.4` | `2.1.6` | | [tracing-subscriber](https://github.com/tokio-rs/tracing) | `0.3.17` | `0.3.20` | | [tokio](https://github.com/tokio-rs/tokio) | `1.38.1` | `1.38.2` | | [bytes](https://github.com/tokio-rs/bytes) | `1.5.0` | `1.11.1` | | [keccak](https://github.com/RustCrypto/sponges) | `0.1.4` | `0.1.6` | | [lz4_flex](https://github.com/pseitz/lz4_flex) | `0.11.3` | `0.11.6` | | [mio](https://github.com/tokio-rs/mio) | `0.8.10` | `0.8.11` | | [openssl](https://github.com/rust-openssl/rust-openssl) | `0.10.62` | `0.10.80` | | [rand](https://github.com/rust-random/rand) | `0.8.5` | `0.8.6` | | [rustix](https://github.com/bytecodealliance/rustix) | `0.37.23` | `0.37.28` | | [rustls-webpki](https://github.com/rustls/webpki) | `0.100.1` | `0.100.3` | | [time](https://github.com/time-rs/time) | `0.3.36` | `0.3.44` | | [webpki](https://github.com/briansmith/webpki) | `0.22.0` | `0.22.4` | | [whoami](https://github.com/ardaku/whoami) | `1.4.1` | `1.6.1` | Updates `diesel` from 2.1.4 to 2.1.6 - [Release notes](https://github.com/diesel-rs/diesel/releases) - [Changelog](https://github.com/diesel-rs/diesel/blob/main/CHANGELOG.md) - [Commits](diesel-rs/diesel@v2.1.4...v2.1.6) Updates `tracing-subscriber` from 0.3.17 to 0.3.20 - [Release notes](https://github.com/tokio-rs/tracing/releases) - [Commits](tokio-rs/tracing@tracing-subscriber-0.3.17...tracing-subscriber-0.3.20) Updates `tokio` from 1.38.1 to 1.38.2 - [Release notes](https://github.com/tokio-rs/tokio/releases) - [Commits](tokio-rs/tokio@tokio-1.38.1...tokio-1.38.2) Updates `bytes` from 1.5.0 to 1.11.1 - [Release notes](https://github.com/tokio-rs/bytes/releases) - [Changelog](https://github.com/tokio-rs/bytes/blob/master/CHANGELOG.md) - [Commits](tokio-rs/bytes@v1.5.0...v1.11.1) Updates `keccak` from 0.1.4 to 0.1.6 - [Commits](RustCrypto/sponges@keccak/v0.1.4...keccak-v0.1.6) Updates `lz4_flex` from 0.11.3 to 0.11.6 - [Release notes](https://github.com/pseitz/lz4_flex/releases) - [Changelog](https://github.com/PSeitz/lz4_flex/blob/main/CHANGELOG.md) - [Commits](https://github.com/pseitz/lz4_flex/commits/0.11.6) Updates `mio` from 0.8.10 to 0.8.11 - [Release notes](https://github.com/tokio-rs/mio/releases) - [Changelog](https://github.com/tokio-rs/mio/blob/master/CHANGELOG.md) - [Commits](tokio-rs/mio@v0.8.10...v0.8.11) Updates `openssl` from 0.10.62 to 0.10.80 - [Release notes](https://github.com/rust-openssl/rust-openssl/releases) - [Commits](rust-openssl/rust-openssl@openssl-v0.10.62...openssl-v0.10.80) Updates `rand` from 0.8.5 to 0.8.6 - [Release notes](https://github.com/rust-random/rand/releases) - [Changelog](https://github.com/rust-random/rand/blob/0.8.6/CHANGELOG.md) - [Commits](rust-random/rand@0.8.5...0.8.6) Updates `rustix` from 0.37.23 to 0.37.28 - [Release notes](https://github.com/bytecodealliance/rustix/releases) - [Changelog](https://github.com/bytecodealliance/rustix/blob/main/CHANGES.md) - [Commits](bytecodealliance/rustix@v0.37.23...v0.37.28) Updates `rustls-webpki` from 0.100.1 to 0.100.3 - [Release notes](https://github.com/rustls/webpki/releases) - [Commits](rustls/webpki@v/0.100.1...v/0.100.3) Updates `time` from 0.3.36 to 0.3.44 - [Release notes](https://github.com/time-rs/time/releases) - [Changelog](https://github.com/time-rs/time/blob/main/CHANGELOG.md) - [Commits](time-rs/time@v0.3.36...v0.3.44) Updates `webpki` from 0.22.0 to 0.22.4 - [Commits](https://github.com/briansmith/webpki/commits) Updates `whoami` from 1.4.1 to 1.6.1 - [Release notes](https://github.com/ardaku/whoami/releases) - [Commits](https://github.com/ardaku/whoami/commits) --- updated-dependencies: - dependency-name: diesel dependency-version: 2.1.6 dependency-type: direct:production dependency-group: cargo - dependency-name: tracing-subscriber dependency-version: 0.3.20 dependency-type: direct:production dependency-group: cargo - dependency-name: tokio dependency-version: 1.38.2 dependency-type: direct:production dependency-group: cargo - dependency-name: bytes dependency-version: 1.11.1 dependency-type: indirect dependency-group: cargo - dependency-name: keccak dependency-version: 0.1.6 dependency-type: indirect dependency-group: cargo - dependency-name: lz4_flex dependency-version: 0.11.6 dependency-type: indirect dependency-group: cargo - dependency-name: mio dependency-version: 0.8.11 dependency-type: indirect dependency-group: cargo - dependency-name: openssl dependency-version: 0.10.80 dependency-type: indirect dependency-group: cargo - dependency-name: rand dependency-version: 0.8.6 dependency-type: indirect dependency-group: cargo - dependency-name: rustix dependency-version: 0.37.28 dependency-type: indirect dependency-group: cargo - dependency-name: rustls-webpki dependency-version: 0.100.3 dependency-type: indirect dependency-group: cargo - dependency-name: time dependency-version: 0.3.44 dependency-type: indirect dependency-group: cargo - dependency-name: webpki dependency-version: 0.22.4 dependency-type: indirect dependency-group: cargo - dependency-name: whoami dependency-version: 1.6.1 dependency-type: indirect dependency-group: cargo ... Signed-off-by: dependabot[bot] <support@github.com>
Wiz Scan Summary
To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the cargo group with 14 updates in the /rust directory:
2.1.42.1.60.3.170.3.201.38.11.38.21.5.01.11.10.1.40.1.60.11.30.11.60.8.100.8.110.10.620.10.800.8.50.8.60.37.230.37.280.100.10.100.30.3.360.3.440.22.00.22.41.4.11.6.1Updates
dieselfrom 2.1.4 to 2.1.6Changelog
Sourced from diesel's changelog.
Commits
26c6be4Preapare a diesel 2.1.6 patch release2dc6cc1Merge pull request #3956 from Tanguille/docs/clarify-as-expression-to-sqlca66173Merge pull request #3980 from kornelski/dev-cycle45915acMerge pull request #3971 from Ten0/fix_missing_skip_insertion_attribute_in_un...26b8803Merge pull request #3979 from formlogic-kirk/alias_op_impls6a9bfdfFix the having clause tests + add a test for normal select queries0799a44Add ValidGrouping to boxed having expression5d6637fTry explicitly implementing FromClause<F> for HavingDsl<Predicate>b4776a3Add testc96c870Merge pull request #3959 from 1Dragoon/backports/2.1.4Updates
tracing-subscriberfrom 0.3.17 to 0.3.20Release notes
Sourced from tracing-subscriber's releases.
... (truncated)
Commits
4c52ca5fmt: fix ANSI escape sequence injection vulnerability (#3368)f71cebesubscriber: impl Clone for EnvFilter (#3360)3a1f571Fix CI (#3361)e63ef57chore: prepare tracing-attributes 0.1.30 (#3316)6e59a13attributes: fix tracing::instrument regression around shadowing (#3311)e4df761tracing: update core to 0.1.34 and attributes to 0.1.29 (#3305)643f392chore: prepare tracing-attributes 0.1.29 (#3304)d08e7a6chore: prepare tracing-core 0.1.34 (#3302)6e70c57tracing-subscriber: count numbers of enters inTimings(#2944)c01d4fdfix docs and enable CI onmainbranch (#3295)Updates
tokiofrom 1.38.1 to 1.38.2Release notes
Sourced from tokio's releases.
Commits
aa303bcchore: prepare Tokio v1.38.2 release7b6ccb5chore: backport CI fixes4b174cesync: fix cloning value when receiving from broadcast channel9681ce2chore: make 1.38 an LTS (#6706)Updates
bytesfrom 1.5.0 to 1.11.1Release notes
Sourced from bytes's releases.
... (truncated)
Changelog
Sourced from bytes's changelog.
... (truncated)
Commits
417dccdRelease bytes v1.11.1 (#820)d0293b0Merge commit from forka7952fbchore: prepare bytes v1.11.0 (#804)60cbb77fix:BytesMutonly reuse if src has remaining (#803)7ce330fMove drop_fn of from_owner into vtable (#801)4b53a29Tweak BytesMut::remaining_mut (#795)016fdbdReserve capacity in BytesMut::put (#794)ef7f257Specialize BytesMut::put::<Bytes> (#793)8b4f54dIgnore BytesMut::freeze doctest on wasm (#790)16132adFix latest clippy warnings (#787)Updates
keccakfrom 0.1.4 to 0.1.6Commits
a8936d9keccak v0.1.640c50c1keccak v0.1.5 (#69)2dc13bfkeccak: enable asm backend for p1600 (#68)a3a4e01Revert "Update Cargo.lock" (#67)3a9a29eUpdate Cargo.lock9e4f6bckeccak: don't testsimdfeature inminimal-versionsworkflow (#66)329d4cdReplace cross tests with MIRI (#63)48cc4acbuild(deps): bump actions/checkout from 3 to 4 (#61)651a34ekeccak: replace CI tests on MIPS with PPC32 (#62)4730c6fbenches: remove criterion deps workaround (#60)Updates
lz4_flexfrom 0.11.3 to 0.11.6Changelog
Sourced from lz4_flex's changelog.
Commits
Updates
miofrom 0.8.10 to 0.8.11Changelog
Sourced from mio's changelog.
Commits
0328bdeRelease v0.8.117084498Fix warnings90d4fe0named-pipes: fix receiving IOCP events after deregisterc710a30Add v0.8.x to the CIc29e21cRelease v0.8.10Updates
opensslfrom 0.10.62 to 0.10.80Release notes
Sourced from openssl's releases.
... (truncated)
Commits
35be7aeRelease openssl 0.10.80 and openssl-sys 0.9.116 (#2639)19eceb2Fix output buffer overflow in cipher_update_inplace for AES key-wrap-with-pad...b460eb3Prefer Homebrew openssl@4 and stop looking for openssl@1.1 (#2633)649f2d9Release openssl 0.10.79 and openssl-sys 0.9.115 (#2632)257f9b2Fix output buffer overflow for AES key-wrap-with-padding ciphers (#2630)d43e917Reject non-UTF-8 OCSP responder URLs in X509Ref::ocsp_responders (#2631)f46519cAdd PkeyCtxRef::set_context_string for ML-DSA (#2629)ad9ae31Bind OSSL_PARAM_modified and use it for seed_into (#2628)4e25c9bFix process abort when verify/PSK callbacks fire after SSL_CTX swap (#2624)3dd8f42Add PKeyRef::seed_into for ML-DSA/ML-KEM seed extraction (#2626)Updates
randfrom 0.8.5 to 0.8.6Changelog
Sourced from rand's changelog.
Commits
5309f250.8.6 (#1772): update for recent nightly rustc and backport #17641126d03When testing rustc 1.36, use compatible dependencies.143b602Add Cargo.lock.msrv.9be86f2Fix cross build test.5e0d50dDrop simd_support.8ff02f0Upgrade cache action.4ad0cc3Don't test for unsupported target architecture.258e6d0Address warning.9f0e676Mark some internal traits as potentially unused.6f123c1Workaround never constructed and never used warning.Updates
rustixfrom 0.37.23 to 0.37.28Commits
89b7a8dchore: Release rustix version 0.37.28f51ecb1Check for a missingDT_HASHsection in the VDSO parser (#1254) (#1257)b720e07Remove naked_functions feature usage for x86 (#722) (#1182)b38dc51chore: Release rustix version 0.37.27a2d9c8eFix p{read,write}v{,v2}'s encoding of the offset argument on Linux. (#896) (#...dce2777chore: Release rustix version 0.37.2606dbe83Fixsendmsg_unix's address encoding. (#885) (#886)00b84d6chore: Release rustix version 0.37.25cad15a7Fixes forDiron macOS, FreeBSD, and WASI.df3c3a1Merge pull request from GHSA-c827-hfw6-qwvmUpdates
rustls-webpkifrom 0.100.1 to 0.100.3Release notes
Sourced from rustls-webpki's releases.
Commits
5649c6aCargo: bump version 0.100.2 -> 0.100.3.86f4cb2verify_cert: use enum for build chain error50a2930verify_cert: correct handling of fatal errors0651f72error: add is_fatal helper, use in verify_cert0598dd2verify_cert: optionalBudgetarg forverify_chainhelper277fb4bverify_cert: take references in verify_chain helper63f78e0verify_cert: name constraint checking on verified chainf55622averify_cert: budget for name constraint comparisons141ddcbverify_cert: pull outverify_chaintest helpereb07f2fverify_cert: pull outmake_end_entitytest helperUpdates
timefrom 0.3.36 to 0.3.44Release notes
Sourced from time's releases.
Changelog
Sourced from time's changelog.
... (truncated)
Commits
04c0ef2v0.3.44 releaseb942063Compare datetimes with signed integersdcdfbf6Add explicit type to avoid inference errorsf203852Revert "Remove dependency onitoa"45b9932v0.3.43 release8cbf0dbFix bug withconvert3343e85Add support for rand 0.9afb2574Add note about MSRVed2852ev0.3.42 release1067543Fix copied commentUpdates
webpkifrom 0.22.0 to 0.22.4Commits
Updates
whoamifrom 1.4.1 to 1.6.1Release notes
Sourced from whoami's releases.
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.