Skip to content

fix(deps): update rust minor and patch - #7

Open
endform-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/rust-minor-and-patch
Open

endform-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/rust-minor-and-patch

Conversation

@endform-renovate

@endform-renovate endform-renovate Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Pending
anyhow workspace.dependencies patch 1.0.102 → 1.0.104
async-trait workspace.dependencies patch 0.1.86 → 0.1.92
chrono dependencies patch 0.4 → 0.4.45
clap dependencies patch 4.6.1 → 4.6.7
clap_complete dependencies patch 4.6.5 → 4.6.11
env_logger dependencies patch 0.11.10 → 0.11.11
flate2 dependencies patch 1.1.9 → 1.1.10
futures (source) workspace.dependencies patch 0.3.32 → 0.3.34
getrandom dependencies patch 0.4.2 → 0.4.3
hickory-resolver (source) dependencies patch 0.26.1 → 0.26.3
hickory-server (source) dependencies patch 0.26.1 → 0.26.3
http dependencies minor 1 → 1.5.0
http workspace.dependencies minor 1.4.0 → 1.5.0
http-body dependencies minor 1.0.1 → 1.1.0
hyper-rustls dependencies patch 0.27.9 → 0.27.10
hyper-util (source) dependencies patch 0.1.10 → 0.1.21
indicatif dependencies patch 0.18.4 → 0.18.6
log dependencies patch 0.4.29 → 0.4.34
percent-encoding dependencies patch 2.1.0 → 2.3.2
rand (source) workspace.dependencies patch 0.10.1 → 0.10.3
rcgen dependencies patch 0.14.8 → 0.14.10
regex workspace.dependencies minor 1.12.3 → 1.13.1
reqwest workspace.dependencies patch 0.13.2 → 0.13.5
rustls workspace.dependencies patch 0.23.40 → 0.23.45
rustls-native-certs dependencies patch 0.8.3 → 0.8.4
serde (source) dependencies patch 1.0 → 1.0.229
serde (source) workspace.dependencies patch 1.0.228 → 1.0.229
serde_json dependencies patch 1.0 → 1.0.151
serde_json workspace.dependencies patch 1.0.149 → 1.0.151
serde_with dependencies minor 3 → 3.24.0
serde_yaml dependencies patch 0.9.34-deprecated → 0.9.34
sysinfo dependencies patch 0.39.1 → 0.39.6
tar dependencies patch 0.4.45 → 0.4.46
thiserror dependencies patch 2 → 2.0.21
thiserror workspace.dependencies patch 2.0.18 → 2.0.21
tokio (source) workspace.dependencies minor 1.52.3 → 1.53.1 1.53.2
url dependencies patch 2.2 → 2.5.8
uuid dependencies minor 1.23 → 1.26.1 1.27.0

Release Notes

dtolnay/anyhow (anyhow)

v1.0.104

Compare Source

  • Update syn dev-dependency to version 3

v1.0.103

Compare Source

  • Fix Stacked Borrows violation (UB) in Error::downcast_mut (#​451, #​452)
dtolnay/async-trait (async-trait)

v0.1.92

Compare Source

  • Resolve double_must_use clippy lint in generated code (#​303)

v0.1.91

Compare Source

  • Update to syn 3 (#​299)
  • Fix mutability for by-reference receivers (#​301)

v0.1.90

Compare Source

(yanked)

chronotope/chrono (chrono)

v0.4.45: 0.4.45

Compare Source

What's Changed

clap-rs/clap (clap)

v4.6.7

Compare Source

Features
  • (derive) Add #[command(defer = <bool>)] attribute to opt-in to lazy initialisation of subcommands

v4.6.6

Compare Source

Features
  • Add Command::get_overridden_usage

v4.6.5

Compare Source

Fixes
  • (help) Correctly mark which value_names are optional with num_args

v4.6.4

Compare Source

Internal
  • Update to syn v3

v4.6.3

Compare Source

Fixes
  • (derive) Allow "literal".function() as attribute values

v4.6.2

Compare Source

Fixes
  • (help) Say alias when there is only one
rust-cli/env_logger (env_logger)

v0.11.11

Compare Source

Internal
  • Updated env_filter
rust-lang/flate2-rs (flate2)

v1.1.10

Compare Source

What's Changed

New Contributors

Full Changelog: rust-lang/flate2-rs@1.1.9...1.1.10

rust-lang/futures-rs (futures)

v0.3.34

Compare Source

v0.3.33

Compare Source

  • Fix ReadLine's soundness issue regarding to exception safety. (#​3020)
  • Fix unsound Send impl for IterPinRef and Iter. (#​3003)
  • Fix stacked borrows violation in compat01as03 implementation. (#​3012)
  • Fix memory leak in FuturesUnordered::IntoIter. (#​3005)
  • Add portable-atomic-alloc feature and use it in FuturesUnordered. (#​3007)
  • Re-export alloc::task::Wake. (#​3010)
  • Update spin to 0.12. (#​3014)
rust-random/getrandom (getrandom)

v0.4.3

Compare Source

Added
  • wasm64-unknown-unknown target support for wasm_js backend #​848
Changed
  • Drop wasip2 and wasip3 dependencies in favor of manual bindings #​830
hickory-dns/hickory-dns (hickory-resolver)

v0.26.3

Compare Source

This release fixes regressions introduced in v0.26.2 related to DNSSEC verification, QUIC servers, HTTP/3 servers, and minimum dependency versions.

What's Changed

Full Changelog: hickory-dns/hickory-dns@v0.26.2...v0.26.3

v0.26.2

Compare Source

This release fixes a large number of security vulnerabilities. Most of the issues were related to DNSSEC validation, denial of service and resource consumption attacks, and reachable panics in parsers. Other issues were related to UDP spoofing defenses, caching issues, and general DNS protocol correctness issues.

This is our first post-vulnpocalypse release, and most of these vulnerabilities were discovered through LLM-based workflows. The sheer volume of reports has been a challenge for our volunteer maintainers.

Resolved advisories:

Special thanks go out to @​qifan-sailboat and Palo Alto Networks for their research and for reporting the bulk of these vulnerabilities. Thanks to @​ATinyShoe, @​kirk-baird, @​thesmartshadow, @​BeaCox, @​jpds, @​N0zoM1z0, and @​JasonPap for reporting vulnerabilities as well.

If your organization is interested in coordinated disclosure of future security vulnerabilities, please contact @​djc for commercial support.

What's Changed
New Contributors

Full Changelog: hickory-dns/hickory-dns@v0.26.1...v0.26.2

hyperium/http (http)

v1.5.0

Compare Source

  • Add Method::QUERY constant for the new QUERY method defined in RFC 10008.
  • Fix uri::Builder::path_and_query() to allow empty strings to mean no path.
  • Fix uri::PathAndQuery parsing to enforce URI max length.

v1.4.2

Compare Source

  • Fix uri::Builder to allow "*" as the path when scheme and authority are also set, used in HTTP/2 requests.
  • Fix Uri to properly reject DEL characters.

v1.4.1

Compare Source

  • Fix PathAndQuery::from_static() and from_shared() to reject inputs that do not start with /.
  • Fix Extend for HeaderMap to clamp max size hint and not overflow.
  • Fix header::IntoIter that could use-after-free if the generic value type could panic on drop.
  • Fix header::{IterMut, ValuesIterMut} to not violate stacked borrows.
hyperium/http-body (http-body)

v1.1.0

Compare Source

tl;dr

  • Implement Add for SizeHint.
  • Implement Copy for SizeHint.
hyperium/hyper-util (hyper-util)

v0.1.21

Compare Source

This release bumps the minimal supported Rust version (MSRV) from 1.64 to 1.85.

This release bumps the rust edition from 2021 to 2024.

Additions

  • Add crate-level documentation. (#​327)
  • Add client::legacy::Builder::http2_header_table_size() method. (#​274)
  • Add client::legacy::Builder::http2_max_concurrent_streams() method. (#​274)
  • Add client::legacy::Builder::http2_max_local_error_reset_streams() method. (#​277)
  • Add client::legacy::connect::HttpConnector::set_mark() method. (#​303)
  • Add rt::tracing::WithSpanExecutor<E>, hyper_util::rt::tracing::CurrentSpanExecutor<E>, and hyper_util::rt::tracing::MkSpanExecutor<E, F> executors. (#​323)

Fixes

  • Fix client::legacy::Client so that it properly validates CONNECT responses. (#​315)
  • Fix client::legacy::Client to cancel the idle interval once its pool empties. (#​292)
  • Fix client::legacy::Client to properly handle IPv6 addresses when using a SOCKS proxy. (#​302)
  • Fix client::pool::cache to preserve readiness with clones. (#​297)
  • Fix client::pool::cache to wake its waiters in FIFO order. (#​298)
  • Fix client::pool::singleton::Singleton to properly handle cancellation. (#​299)
  • Fix client::pool::singleton::Singleton to share errors with all waiters. (#​296)
  • Fix client::proxy::matcher handling for IP wildcards. (#​309)
  • The tokio/net feature is narrowed to the client-legacy feature flag, from the client feature flag. (#​276)
  • Various fixes to the client::legacy::Client's SOCKS proxying. (#​302) (#​307) (#​308) (#​310)

Changes

This release contains a minor behavioral change for users of the tracing
feature flag to be aware of.

This feature flag was introduced in v0.1.11. When enabled,
rt::TokioExecutor<E> began propagating the currently active tracing::Span
to spawned tasks when hyper::rt::Executor::execute() is called. This caused
issues for some users, due to background tasks keeping a span open for the
duration of a long-lived connection.

This behavior has now been removed from rt::TokioExecutor<E>
(#​322) by default. A
collection of executor wrappers have been added to a new rt::tracing
submodule, to provide facilities for instrumenting a client or server's spawned
tasks. See the module-level documentation of rt::tracing for more
information.

To temporarily preserve the previous rt::TokioExecutor<E> span propagation
behavior, enable the rt-tracing-exec-force feature. Note that this feature
flag will be removed in a future release.

console-rs/indicatif (indicatif)

v0.18.6

Compare Source

What's Changed

v0.18.5

Compare Source

What's Changed

rust-lang/log (log)

v0.4.34

Compare Source

v0.4.33

Compare Source

v0.4.32

Compare Source

What's Changed
  • Support Value -> string conversions with kv + std features instead of kv_std by @​tisonkun in #​729

Full Changelog: rust-lang/log@0.4.31...0.4.32

v0.4.31

Compare Source

What's Changed
  • Support Value -> string conversions with kv + std features instead of kv_std by @​tisonkun in #​729

Full Changelog: rust-lang/log@0.4.31...0.4.32

v0.4.30

Compare Source

What's Changed
New Contributors

Full Changelog: rust-lang/log@0.4.30...0.4.31

rustls/rcgen (rcgen)

v0.14.10: 0.14.10

What's Changed

rust-lang/regex (regex)

v1.13.1

Compare Source

===================
This is a release that fixes a bug where incorrect regex match offsets could be
reported. Note that this doesn't impact whether a match occurs or not, just
where it occurs. The match offsets are still valid for slicing, they just may
not refer to the correct leftmost-first match. See
#​1364 for (many) more details.

Bug fixes:

  • #​1354:
    Fixes previously unsound reverse suffix and inner optimizations.

v1.13.0

Compare Source

===================
This release includes a new API, a regex! macro, for lazy compilation of
a regex from a string literal. If you use regexes a lot, it's likely you've
already written one exactly like it. The new macro can be used like this:

use regex::regex;

fn is_match(line: &str) -> bool {
    // The regex will be compiled approximately once and reused automatically.
    // This avoids the footgun of using `Regex::new` here, which would
    // guarantee that it would be compiled every time this routine is called.
    // This would likely make this routine much slower than it needs to be.
    regex!(r"bar|baz").is_match(line)
}

let hay = "\
path/to/foo:54:Blue Harvest
path/to/bar:90:Something, Something, Something, Dark Side
path/to/baz:3:It's a Trap!
";

let matches = hay.lines().filter(|line| is_match(line)).count();
assert_eq!(matches, 2);

Improvements:

  • #​709:
    Add a new regex! macro for efficient and automatic reuse of a compiled regex.

v1.12.4

Compare Source

===================
This release includes a performance optimization for compilation of regexes
with very large character classes.

Improvements:

  • #​1308:
    Avoid re-canonicalizing the entire interval set when pushing new class ranges.
seanmonstar/reqwest (reqwest)

v0.13.5

Compare Source

  • Add Error::is_dns() to identify errors caused by DNS resolution failures.
  • Add ClientBuilder::http1_max_headers(usize) to configure the maximum number of headers accepted in an HTTP/1 response (default 100).
  • Add TLS version to TlsInfo extension.
  • Fix hickory-dns feature to use Ipv6AndIpv4 strategy to prefer IPv6.
  • Fix sending wrong proxy-auth if multiple proxies intercept a given URL.

v0.13.4

Compare Source

  • Add ClientBuilder::tls_sslkeylogfile(bool) option to allow using the related environment variable.
  • Add ClientBuilder::http2_keep_alive_* options for the blocking client.
  • Add TLS 1.3 support when using native-tls backend.
  • Fix redirect handling to strip sensitive headers when the scheme changes.
  • Fix HTTP/3 happy-eyeball connection creation.
  • Upgrade hickory-resolver to 0.26.

v0.13.3

Compare Source

  • Fix CertificateRevocationList parsing of PEM values.
  • Fix logging in resolver to only show host, not full URL.
  • Fix hickory-dns to fallback to a default if /etc/resolv.conf fails.
  • Fix HTTP/3 to handle STOP_SENDING as not an error.
  • Fix HTTP/3 pool to remove timed out QUIC connections.
  • Fix HTTP/3 connection establishment picking IPv4 and IPv6.
  • Upgrade rustls-platform-verifier.
  • (wasm) Only use wasm-bindgen on unknown-* targets.
serde-rs/serde (serde)

v1.0.229

Compare Source

  • Update to syn 3
serde-rs/json (serde_json)

v1.0.151

Compare Source

v1.0.150

Compare Source

jonasbb/serde_with (serde_with)

v3.24.0: serde_with v3.24.0

Compare Source

Added
  • Implement JsonSchemaAs for NoneAsEmptyString, so fields using it compile with the schemars_* features (#​1014)
Changed
  • Make with_prefix! and with_suffix! available with the alloc feature, instead of only with std (#​1008)
Fixed
  • Handle potential panics in deserialization of chrono and time DateTimes.
    This was privately reported by @​NotAFlightRisk.

v3.23.0: serde_with v3.23.0

Compare Source

Changed
  • Update syn and darling dependencies to use syn v3 (#​992)
  • Update dev-dependencies to newer versions (#​993)
  • Update base64 to a newer version. This should not have any API change, but some error messages might change. (#​993)
  • serde_as can now parse cfg_attr(true, ...) and cfg_attr(false, ...) (#​995)
    true/false are new literals as of Rust 1.88 but need to be parsed explicitly with the syn types.
    This is used when emitting schemars annotations.

v3.22.0: serde_with v3.22.0

Compare Source

Added
  • Add support for jiff v0.2 behind the new jiff_0_2 feature flag (#​936)
    jiff::SignedDuration works with DurationSeconds and its variants.
    jiff::Timestamp, jiff::Zoned, and jiff::civil::DateTime work with TimestampSeconds and its variants.
    Deserializing a jiff::Zoned uses the system time zone, like chrono::DateTime<Local>.
Fixed
  • Extend the GHSA-7gcf-g7xr-8hxj fix to the duplicate-key-prevention collections.
    The rust::sets_duplicate_value_is_error, rust::maps_duplicate_key_is_error, rust::sets_last_value_wins, and rust::maps_first_key_wins adapters created their backing sets/maps with with_capacity_and_hasher using the raw deserializer size_hint, bypassing the size_hint_cautious cap added in #​966 (the clippy.toml disallowed_methods lint only covers Vec::with_capacity, not with_capacity_and_hasher, so these sites were not flagged).
    Attacker-controlled input claiming a huge length could panic with Hash table capacity overflow before a single element was read. All such constructions now route through size_hint_cautious.

v3.21.0: serde_with v3.21.0

Compare Source

Security
  • GHSA-7gcf-g7xr-8hxj: KeyValueMap serialization panics on empty sequence or map entries
    Bad or attacker controlled values could cause a panic while allocating too large values.
    Fixed in #​966 by setting a maximum allocation size during the creation of collections like Vec or sets.

    Thanks to @​7thParkk for reporting the issue.

Added
  • Add NoneAsZero adapter that maps Option<NonZero*> to a plain integer, encoding None as 0 by @​SAY-5 (#​486)
Changed
  • Re-enable link-to-definition on docs.rs (#​964)
Fixed
  • Fix some doc links to point to the correct types (#​963)
  • Re-enable unused_qualifications and fix the resulting findings by @​lms0806 (#​962)
GuillaumeGomez/sysinfo (sysinfo)

v0.39.6

Compare Source

  • NetBSD: Add support for disk I/O usage.
  • NetBSD: Improve retrieval of disk information.

v0.39.5

Compare Source

  • macOS: Fix build for apple app store

v0.39.4

Compare Source

  • Unix: Fix soundness issue when retrieving user's groups.
  • macOS: Add new macOS version name.
  • macOS: Fix inaccurate open_files returned value.

v0.39.3

Compare Source

  • Unix: Fix retrieval of Network::mac_addr.
  • Linux: Improve retrieval of process information if process terminates while doing so.

v0.39.2

Compare Source

  • Windows: Greatly improve performance of System::refresh_cpu_specifics when CPU usage is not requested.
  • iOS: Fix compilation error when user feature is enabled.
  • Linux: Correctly set thread information for processes.
composefs/tar-rs (tar)

v0.4.46

Compare Source

Security

See also GHSA-3cv2-h65g-fgmm

Other changes

✂ Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@endform-renovate

endform-renovate Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update artifacts related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: Cargo.toml
Artifact update for tokio resolved to version 1.53.2, which is a pending version that has not yet passed the Minimum Release Age threshold.
Renovate was attempting to update to 1.53.1
This is (likely) not a bug in Renovate, but due to the way your project pins dependencies, _and_ how Renovate calls your package manager to update them.
Until Renovate supports specifying an exact update to your package manager (https://github.com/renovatebot/renovate/issues/41624), it is recommended to directly pin your dependencies (with `rangeStrategy=pin` for apps, or `rangeStrategy=widen` for libraries)
See also: https://docs.renovatebot.com/dependency-pinning/
File name: cloudflare/Cargo.toml
Artifact update for uuid resolved to version 1.27.0, which is a pending version that has not yet passed the Minimum Release Age threshold.
Renovate was attempting to update to 1.26.1
This is (likely) not a bug in Renovate, but due to the way your project pins dependencies, _and_ how Renovate calls your package manager to update them.
Until Renovate supports specifying an exact update to your package manager (https://github.com/renovatebot/renovate/issues/41624), it is recommended to directly pin your dependencies (with `rangeStrategy=pin` for apps, or `rangeStrategy=widen` for libraries)
See also: https://docs.renovatebot.com/dependency-pinning/

@endform-renovate
endform-renovate Bot force-pushed the renovate/rust-minor-and-patch branch from fa27b60 to ccfdfd5 Compare October 9, 2026 14:13
@endform-renovate
endform-renovate Bot force-pushed the renovate/rust-minor-and-patch branch from ccfdfd5 to 1033e75 Compare October 9, 2026 19:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants