Repository navigation
fix(deps): update rust minor and patch - #7
Open
endform-renovate[bot] wants to merge 1 commit into
Open
endform-renovate[bot] wants to merge 1 commit into
endform-renovate[bot] wants to merge 1 commit into
Conversation
Contributor
Author
|
endform-renovate
Bot
force-pushed
the
renovate/rust-minor-and-patch
branch
from
October 9, 2026 14:13
fa27b60 to
ccfdfd5
Compare
endform-renovate
Bot
force-pushed
the
renovate/rust-minor-and-patch
branch
from
October 9, 2026 19:36
ccfdfd5 to
1033e75
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.0.102→1.0.1040.1.86→0.1.920.4→0.4.454.6.1→4.6.74.6.5→4.6.110.11.10→0.11.111.1.9→1.1.100.3.32→0.3.340.4.2→0.4.30.26.1→0.26.30.26.1→0.26.31→1.5.01.4.0→1.5.01.0.1→1.1.00.27.9→0.27.100.1.10→0.1.210.18.4→0.18.60.4.29→0.4.342.1.0→2.3.20.10.1→0.10.30.14.8→0.14.101.12.3→1.13.10.13.2→0.13.50.23.40→0.23.450.8.3→0.8.41.0→1.0.2291.0.228→1.0.2291.0→1.0.1511.0.149→1.0.1513→3.24.00.9.34-deprecated→0.9.340.39.1→0.39.60.4.45→0.4.462→2.0.212.0.18→2.0.211.52.3→1.53.11.53.22.2→2.5.81.23→1.26.11.27.0Release Notes
dtolnay/anyhow (anyhow)
v1.0.104Compare Source
syndev-dependency to version 3v1.0.103Compare Source
Error::downcast_mut(#451, #452)dtolnay/async-trait (async-trait)
v0.1.92Compare Source
v0.1.91Compare Source
v0.1.90Compare Source
(yanked)
chronotope/chrono (chrono)
v0.4.45: 0.4.45Compare Source
What's Changed
clap-rs/clap (clap)
v4.6.7Compare Source
Features
#[command(defer = <bool>)]attribute to opt-in to lazy initialisation of subcommandsv4.6.6Compare Source
Features
Command::get_overridden_usagev4.6.5Compare Source
Fixes
value_namesare optional withnum_argsv4.6.4Compare Source
Internal
v4.6.3Compare Source
Fixes
"literal".function()as attribute valuesv4.6.2Compare Source
Fixes
aliaswhen there is only onerust-cli/env_logger (env_logger)
v0.11.11Compare Source
Internal
env_filterrust-lang/flate2-rs (flate2)
v1.1.10Compare Source
What's Changed
Crcstruct by @MikkelPaulson in #540README.mdin a private module by @bushrat011899 in #562no_stdsupport using nightlyalloc_ioby @bushrat011899 in #559get_mut()documentation to make clear how 'inner` can be used by @Byron in #558New Contributors
Full Changelog: rust-lang/flate2-rs@1.1.9...1.1.10
rust-lang/futures-rs (futures)
v0.3.34Compare Source
synto 3. (#3028)v0.3.33Compare Source
ReadLine's soundness issue regarding to exception safety. (#3020)Sendimpl forIterPinRefandIter. (#3003)compat01as03implementation. (#3012)FuturesUnordered::IntoIter. (#3005)portable-atomic-allocfeature and use it inFuturesUnordered. (#3007)alloc::task::Wake. (#3010)spinto 0.12. (#3014)rust-random/getrandom (getrandom)
v0.4.3Compare Source
Added
wasm64-unknown-unknowntarget support forwasm_jsbackend #848Changed
wasip2andwasip3dependencies in favor of manual bindings #830hickory-dns/hickory-dns (hickory-resolver)
v0.26.3Compare Source
This release fixes regressions introduced in v0.26.2 related to DNSSEC verification, QUIC servers, HTTP/3 servers, and minimum dependency versions.
What's Changed
Full Changelog: hickory-dns/hickory-dns@v0.26.2...v0.26.3
v0.26.2Compare Source
This release fixes a large number of security vulnerabilities. Most of the issues were related to DNSSEC validation, denial of service and resource consumption attacks, and reachable panics in parsers. Other issues were related to UDP spoofing defenses, caching issues, and general DNS protocol correctness issues.
This is our first post-vulnpocalypse release, and most of these vulnerabilities were discovered through LLM-based workflows. The sheer volume of reports has been a challenge for our volunteer maintainers.
Resolved advisories:
TrustAnchorsdoes not check name of DNSKEYName::hashdiscards label boundaries;ValidationCacheKey(u64)reuses the digest inEqimplementation, leaking an Insecure DNSSEC verdict across distinct owner namesNameServerPool::try_send(resource-exhaustion DoS)Special thanks go out to @qifan-sailboat and Palo Alto Networks for their research and for reporting the bulk of these vulnerabilities. Thanks to @ATinyShoe, @kirk-baird, @thesmartshadow, @BeaCox, @jpds, @N0zoM1z0, and @JasonPap for reporting vulnerabilities as well.
If your organization is interested in coordinated disclosure of future security vulnerabilities, please contact @djc for commercial support.
What's Changed
Ed25519key encoding (0.26 backport) by @djc in #3772New Contributors
Full Changelog: hickory-dns/hickory-dns@v0.26.1...v0.26.2
hyperium/http (http)
v1.5.0Compare Source
Method::QUERYconstant for the new QUERY method defined in RFC 10008.uri::Builder::path_and_query()to allow empty strings to mean no path.uri::PathAndQueryparsing to enforce URI max length.v1.4.2Compare Source
uri::Builderto allow"*"as the path when scheme and authority are also set, used in HTTP/2 requests.Urito properly rejectDELcharacters.v1.4.1Compare Source
PathAndQuery::from_static()andfrom_shared()to reject inputs that do not start with/.ExtendforHeaderMapto clamp max size hint and not overflow.header::IntoIterthat could use-after-free if the generic value type could panic on drop.header::{IterMut, ValuesIterMut}to not violate stacked borrows.hyperium/http-body (http-body)
v1.1.0Compare Source
tl;dr
AddforSizeHint.CopyforSizeHint.hyperium/hyper-util (hyper-util)
v0.1.21Compare Source
This release bumps the minimal supported Rust version (MSRV) from 1.64 to 1.85.
This release bumps the rust edition from 2021 to 2024.
Additions
client::legacy::Builder::http2_header_table_size()method. (#274)client::legacy::Builder::http2_max_concurrent_streams()method. (#274)client::legacy::Builder::http2_max_local_error_reset_streams()method. (#277)client::legacy::connect::HttpConnector::set_mark()method. (#303)rt::tracing::WithSpanExecutor<E>,hyper_util::rt::tracing::CurrentSpanExecutor<E>, andhyper_util::rt::tracing::MkSpanExecutor<E, F>executors. (#323)Fixes
client::legacy::Clientso that it properly validates CONNECT responses. (#315)client::legacy::Clientto cancel the idle interval once its pool empties. (#292)client::legacy::Clientto properly handle IPv6 addresses when using a SOCKS proxy. (#302)client::pool::cacheto preserve readiness with clones. (#297)client::pool::cacheto wake its waiters in FIFO order. (#298)client::pool::singleton::Singletonto properly handle cancellation. (#299)client::pool::singleton::Singletonto share errors with all waiters. (#296)client::proxy::matcherhandling for IP wildcards. (#309)tokio/netfeature is narrowed to theclient-legacyfeature flag, from theclientfeature flag. (#276)client::legacy::Client's SOCKS proxying. (#302) (#307) (#308) (#310)Changes
This release contains a minor behavioral change for users of the
tracingfeature flag to be aware of.
This feature flag was introduced in v0.1.11. When enabled,
rt::TokioExecutor<E>began propagating the currently activetracing::Spanto spawned tasks when
hyper::rt::Executor::execute()is called. This causedissues for some users, due to background tasks keeping a span open for the
duration of a long-lived connection.
This behavior has now been removed from
rt::TokioExecutor<E>(#322) by default. A
collection of executor wrappers have been added to a new
rt::tracingsubmodule, to provide facilities for instrumenting a client or server's spawned
tasks. See the module-level documentation of
rt::tracingfor moreinformation.
To temporarily preserve the previous
rt::TokioExecutor<E>span propagationbehavior, enable the
rt-tracing-exec-forcefeature. Note that this featureflag will be removed in a future release.
console-rs/indicatif (indicatif)
v0.18.6Compare Source
What's Changed
v0.18.5Compare Source
What's Changed
div_duration_f64by @ChrisDenton in #792ProgressDrawTarget.is_stderr()forMultiProgressby @kojiishi in #803rust-lang/log (log)
v0.4.34Compare Source
v0.4.33Compare Source
v0.4.32Compare Source
What's Changed
Value-> string conversions withkv+stdfeatures instead ofkv_stdby @tisonkun in #729Full Changelog: rust-lang/log@0.4.31...0.4.32
v0.4.31Compare Source
What's Changed
Value-> string conversions withkv+stdfeatures instead ofkv_stdby @tisonkun in #729Full Changelog: rust-lang/log@0.4.31...0.4.32
v0.4.30Compare Source
What's Changed
New Contributors
Full Changelog: rust-lang/log@0.4.30...0.4.31
rustls/rcgen (rcgen)
v0.14.10: 0.14.10What's Changed
rust-lang/regex (regex)
v1.13.1Compare Source
===================
This is a release that fixes a bug where incorrect regex match offsets could be
reported. Note that this doesn't impact whether a match occurs or not, just
where it occurs. The match offsets are still valid for slicing, they just may
not refer to the correct leftmost-first match. See
#1364 for (many) more details.
Bug fixes:
Fixes previously unsound reverse suffix and inner optimizations.
v1.13.0Compare Source
===================
This release includes a new API, a
regex!macro, for lazy compilation ofa regex from a string literal. If you use regexes a lot, it's likely you've
already written one exactly like it. The new macro can be used like this:
Improvements:
Add a new
regex!macro for efficient and automatic reuse of a compiled regex.v1.12.4Compare Source
===================
This release includes a performance optimization for compilation of regexes
with very large character classes.
Improvements:
Avoid re-canonicalizing the entire interval set when pushing new class ranges.
seanmonstar/reqwest (reqwest)
v0.13.5Compare Source
Error::is_dns()to identify errors caused by DNS resolution failures.ClientBuilder::http1_max_headers(usize)to configure the maximum number of headers accepted in an HTTP/1 response (default 100).TlsInfoextension.Ipv6AndIpv4strategy to prefer IPv6.v0.13.4Compare Source
ClientBuilder::tls_sslkeylogfile(bool)option to allow using the related environment variable.ClientBuilder::http2_keep_alive_*options for theblockingclient.native-tlsbackend.v0.13.3Compare Source
/etc/resolv.conffails.STOP_SENDINGas not an error.serde-rs/serde (serde)
v1.0.229Compare Source
serde-rs/json (serde_json)
v1.0.151Compare Source
v1.0.150Compare Source
jonasbb/serde_with (serde_with)
v3.24.0: serde_with v3.24.0Compare Source
Added
JsonSchemaAsforNoneAsEmptyString, so fields using it compile with theschemars_*features (#1014)Changed
with_prefix!andwith_suffix!available with theallocfeature, instead of only withstd(#1008)Fixed
This was privately reported by @NotAFlightRisk.
v3.23.0: serde_with v3.23.0Compare Source
Changed
synanddarlingdependencies to usesynv3 (#992)base64to a newer version. This should not have any API change, but some error messages might change. (#993)serde_ascan now parsecfg_attr(true, ...)andcfg_attr(false, ...)(#995)true/falseare new literals as of Rust 1.88 but need to be parsed explicitly with thesyntypes.This is used when emitting
schemarsannotations.v3.22.0: serde_with v3.22.0Compare Source
Added
jiffv0.2 behind the newjiff_0_2feature flag (#936)jiff::SignedDurationworks withDurationSecondsand its variants.jiff::Timestamp,jiff::Zoned, andjiff::civil::DateTimework withTimestampSecondsand its variants.Deserializing a
jiff::Zoneduses the system time zone, likechrono::DateTime<Local>.Fixed
The
rust::sets_duplicate_value_is_error,rust::maps_duplicate_key_is_error,rust::sets_last_value_wins, andrust::maps_first_key_winsadapters created their backing sets/maps withwith_capacity_and_hasherusing the raw deserializersize_hint, bypassing thesize_hint_cautiouscap added in #966 (theclippy.tomldisallowed_methodslint only coversVec::with_capacity, notwith_capacity_and_hasher, so these sites were not flagged).Attacker-controlled input claiming a huge length could panic with
Hash table capacity overflowbefore a single element was read. All such constructions now route throughsize_hint_cautious.v3.21.0: serde_with v3.21.0Compare Source
Security
GHSA-7gcf-g7xr-8hxj: KeyValueMap serialization panics on empty sequence or map entries
Bad or attacker controlled values could cause a panic while allocating too large values.
Fixed in #966 by setting a maximum allocation size during the creation of collections like
Vecor sets.Thanks to @7thParkk for reporting the issue.
Added
NoneAsZeroadapter that mapsOption<NonZero*>to a plain integer, encodingNoneas0by @SAY-5 (#486)Changed
Fixed
unused_qualificationsand fix the resulting findings by @lms0806 (#962)GuillaumeGomez/sysinfo (sysinfo)
v0.39.6Compare Source
v0.39.5Compare Source
v0.39.4Compare Source
open_filesreturned value.v0.39.3Compare Source
Network::mac_addr.v0.39.2Compare Source
System::refresh_cpu_specificswhen CPU usage is not requested.userfeature is enabled.composefs/tar-rs (tar)
v0.4.46Compare Source
Security
See also GHSA-3cv2-h65g-fgmm
Other changes
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.