Bump the cargo group across 1 directory with 14 updates#2275
Bump the cargo group across 1 directory with 14 updates#2275Eliah Kagan (EliahKagan) merged 1 commit intomainfrom
Conversation
Bumps the cargo group with 13 updates in the / directory: | Package | From | To | | --- | --- | --- | | [tracing-forest](https://github.com/QnnOkabayashi/tracing-forest) | `0.1.6` | `0.2.0` | | [winnow](https://github.com/winnow-rs/winnow) | `0.7.13` | `0.7.14` | | [bytesize](https://github.com/bytesize-rs/bytesize) | `2.3.0` | `2.3.1` | | [tracing-core](https://github.com/tokio-rs/tracing) | `0.1.34` | `0.1.35` | | [insta](https://github.com/mitsuhiko/insta) | `1.44.1` | `1.44.3` | | [zip](https://github.com/zip-rs/zip2) | `5.1.1` | `6.0.0` | | [crc](https://github.com/mrhooray/crc-rs) | `3.3.0` | `3.4.0` | | [cc](https://github.com/rust-lang/cc-rs) | `1.2.47` | `1.2.48` | | [http](https://github.com/hyperium/http) | `1.3.1` | `1.4.0` | | [rustls-pki-types](https://github.com/rustls/pki-types) | `1.13.0` | `1.13.1` | | [tower-http](https://github.com/tower-rs/tower-http) | `0.6.6` | `0.6.7` | | [tracing-attributes](https://github.com/tokio-rs/tracing) | `0.1.30` | `0.1.31` | | [zerocopy](https://github.com/google/zerocopy) | `0.8.28` | `0.8.30` | Updates `tracing-forest` from 0.1.6 to 0.2.0 - [Commits](https://github.com/QnnOkabayashi/tracing-forest/commits) Updates `winnow` from 0.7.13 to 0.7.14 - [Changelog](https://github.com/winnow-rs/winnow/blob/main/CHANGELOG.md) - [Commits](winnow-rs/winnow@v0.7.13...v0.7.14) Updates `bytesize` from 2.3.0 to 2.3.1 - [Release notes](https://github.com/bytesize-rs/bytesize/releases) - [Changelog](https://github.com/bytesize-rs/bytesize/blob/master/CHANGELOG.md) - [Commits](bytesize-rs/bytesize@bytesize-v2.3.0...bytesize-v2.3.1) Updates `tracing-core` from 0.1.34 to 0.1.35 - [Release notes](https://github.com/tokio-rs/tracing/releases) - [Commits](tokio-rs/tracing@tracing-core-0.1.34...tracing-core-0.1.35) Updates `insta` from 1.44.1 to 1.44.3 - [Release notes](https://github.com/mitsuhiko/insta/releases) - [Changelog](https://github.com/mitsuhiko/insta/blob/master/CHANGELOG.md) - [Commits](mitsuhiko/insta@1.44.1...1.44.3) Updates `zip` from 5.1.1 to 6.0.0 - [Release notes](https://github.com/zip-rs/zip2/releases) - [Changelog](https://github.com/zip-rs/zip2/blob/master/CHANGELOG.md) - [Commits](zip-rs/zip2@v5.1.1...v6.0.0) Updates `crc` from 3.3.0 to 3.4.0 - [Commits](mrhooray/crc-rs@3.3.0...3.4.0) Updates `cc` from 1.2.47 to 1.2.48 - [Release notes](https://github.com/rust-lang/cc-rs/releases) - [Changelog](https://github.com/rust-lang/cc-rs/blob/main/CHANGELOG.md) - [Commits](rust-lang/cc-rs@cc-v1.2.47...cc-v1.2.48) Updates `http` from 1.3.1 to 1.4.0 - [Release notes](https://github.com/hyperium/http/releases) - [Changelog](https://github.com/hyperium/http/blob/master/CHANGELOG.md) - [Commits](hyperium/http@v1.3.1...v1.4.0) Updates `rustls-pki-types` from 1.13.0 to 1.13.1 - [Release notes](https://github.com/rustls/pki-types/releases) - [Commits](rustls/pki-types@v/1.13.0...v/1.13.1) Updates `tower-http` from 0.6.6 to 0.6.7 - [Release notes](https://github.com/tower-rs/tower-http/releases) - [Commits](tower-rs/tower-http@tower-http-0.6.6...tower-http-0.6.7) Updates `tracing-attributes` from 0.1.30 to 0.1.31 - [Release notes](https://github.com/tokio-rs/tracing/releases) - [Commits](tokio-rs/tracing@tracing-attributes-0.1.30...tracing-attributes-0.1.31) Updates `zerocopy` from 0.8.28 to 0.8.30 - [Release notes](https://github.com/google/zerocopy/releases) - [Changelog](https://github.com/google/zerocopy/blob/main/CHANGELOG.md) - [Commits](google/zerocopy@v0.8.28...v0.8.30) Updates `zerocopy-derive` from 0.8.28 to 0.8.30 - [Release notes](https://github.com/google/zerocopy/releases) - [Changelog](https://github.com/google/zerocopy/blob/main/CHANGELOG.md) - [Commits](google/zerocopy@v0.8.28...v0.8.30) --- updated-dependencies: - dependency-name: tracing-forest dependency-version: 0.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo - dependency-name: winnow dependency-version: 0.7.14 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo - dependency-name: bytesize dependency-version: 2.3.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo - dependency-name: tracing-core dependency-version: 0.1.35 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo - dependency-name: insta dependency-version: 1.44.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo - dependency-name: zip dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: cargo - dependency-name: crc dependency-version: 3.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo - dependency-name: cc dependency-version: 1.2.48 dependency-type: indirect update-type: version-update:semver-patch dependency-group: cargo - dependency-name: http dependency-version: 1.4.0 dependency-type: indirect update-type: version-update:semver-minor dependency-group: cargo - dependency-name: rustls-pki-types dependency-version: 1.13.1 dependency-type: indirect update-type: version-update:semver-patch dependency-group: cargo - dependency-name: tower-http dependency-version: 0.6.7 dependency-type: indirect update-type: version-update:semver-patch dependency-group: cargo - dependency-name: tracing-attributes dependency-version: 0.1.31 dependency-type: indirect update-type: version-update:semver-patch dependency-group: cargo - dependency-name: zerocopy dependency-version: 0.8.30 dependency-type: indirect update-type: version-update:semver-patch dependency-group: cargo - dependency-name: zerocopy-derive dependency-version: 0.8.30 dependency-type: indirect update-type: version-update:semver-patch dependency-group: cargo ... Signed-off-by: dependabot[bot] <support@github.com>
Eliah Kagan (EliahKagan)
left a comment
There was a problem hiding this comment.
This looks fine to me. (It does have the same tracing-forest and windows-sys oddities as in #2270.)
|
Fascinatingly, when run again, Dependabot would upgrade to some
So my inclination is to do as usual and not manually trigger it here to get the extra updates at this time. However, I'd be pleased to do so if preferred. |
|
I just trust your judgement there, and am glad you are on top of all this. Maybe it's something to rethink, especially in the current environment. Would it be possible to rely on |
Yes, my original rationale for returning to using Dependabot version updates for our However, there is a newly emerged rationale that I think justifies its continued use--and even expanded use, such as in There's actually a further small benefit of Dependabot over most ways of manually updating dependencies--which I am inclined to think makes it worthwhile even separately from Renovatebot can be used via Forking Renovate, which confers analogous protections by actually operating from a fork. So this is not a reason to prefer Dependabot over Renovatebot (so long as one would use the Forking Renovate integration rather than the Renovate integration for Renovatebot). But I see it as a small reason to prefer Dependabot over local operations, for routine dependency upgrades. This is only a small benefit, because it doesn't inherently prevent a malicious dependency from merged in. But it offers some protection as proposed dependencies are tested and as they are being reviewed.
Regardless of what else we do, we should continue to use I don't recommend that we rely solely on But this is independent of Dependabot version updates. So long as we keep both Dependabot alerts and Dependabot security updates, we'll have the full advantage as far as it relates to responding to the availability of new versions that fix bugs for which an advisory exists. Thus it is instead for the above reasons that I recommend we continue to use Dependabot version updates, and that if this becomes more difficult or frustrating then we look at Reovatebot (via the Forking Renovate integration) as an alternative, rather than immediately falling back to manual updating. Like Dependabot, Renovatebot supports cooldown periods, configured via its |
|
Thanks a lot, let's keep using dependabot for its features, and overall, positive balance.
Yes, I agree that In any case, I am glad that you are maintaining it, and that you keep experimenting with alternative solutions as time permits so we can keep using the best possible tool for the job. |
Bumps the cargo group with 13 updates in the / directory:
0.1.60.2.00.7.130.7.142.3.02.3.10.1.340.1.351.44.11.44.35.1.16.0.03.3.03.4.01.2.471.2.481.3.11.4.01.13.01.13.10.6.60.6.70.1.300.1.310.8.280.8.30Updates
tracing-forestfrom 0.1.6 to 0.2.0Commits
Updates
winnowfrom 0.7.13 to 0.7.14Changelog
Sourced from winnow's changelog.
Commits
faa6214chore: Release5b3b7a9docs: Update changelogfca75c5Merge pull request #804 from ssmendon/ssmendon-pratt-pr9aef8d2feat: Add a Pratt parser716ff2eMerge pull request #846 from clint-white/fix-typos-in-docs3040b97docs(tutorial): Add missing word1b50ab4docs(ref): Fix typo: add missing periodc56d4fbMerge pull request #841 from winnow-rs/renovate/actions-checkout-5.xffb90adchore(deps): Update actions/checkout action to v5de4f84bMerge pull request #842 from winnow-rs/renovate/actions-setup-python-6.xUpdates
bytesizefrom 2.3.0 to 2.3.1Release notes
Sourced from bytesize's releases.
Changelog
Sourced from bytesize's changelog.
Commits
0121741chore: release v2.3.1 (#126)fb35f2dfix: error string when unit is too long (#125)Updates
tracing-corefrom 0.1.34 to 0.1.35Release notes
Sourced from tracing-core's releases.
Commits
d92b4c0chore: prepare tracing-core 0.1.35 (#3414)9751b6echore: runtracing-subscribertests with all features (#3412)efa0169mock: add doctests foron_register_dispatchnegative cases (#3416)a093858docs: fix link inFmtSpandocs (#3411)976fa55mock: add test case for layer not calling on_register_dispatch (#3415)8bc008cfix(subscriber): make Layered propagate on_register_dispatch (#3379)adbd8a4appender: fixmax_filesinteger underflow when set to zero (#3348)2a8b040chore: add Hayden (@hds) to codeowners (#3410)cf5c2bdsubscriber: remove clone_span on enter (#3289)c287c84subscriber: change registry exit to decrement local span ref only (#3331)Updates
instafrom 1.44.1 to 1.44.3Release notes
Sourced from insta's releases.
... (truncated)
Changelog
Sourced from insta's changelog.
Commits
dcbb11fPrepare release 1.44.3 (#838)3b9ec12Refine test name & description (#837)ee4e1eaHandle unparsable snapshot files gracefully (#836)778f733Fix for code before macros, such aslet foo = assert_snapshot!(#835)6cb41afPrepare release 1.44.2 (#831)8838b2fHandle merge conflicts in snapshot files gracefully (#829)e55ce99Fix backward compatibility for legacy inline snapshot format (#830)d44dd42Skip nextest_doctest tests when cargo-nextest is not installed (#826)a711bafFix functional tests failing under nextest (#824)Updates
zipfrom 5.1.1 to 6.0.0Release notes
Sourced from zip's releases.
Changelog
Sourced from zip's changelog.
Commits
abfc23dfeat: Upgrade [Extended]FileOptions::add_extra_data() data from Box<[u8]> to ...eb1b586docs: Update zip_writer documentation example (#431)26e6e08feat: Add by_index_with_options() for ignoring encryption (#439)165415dchore(deps): update nt-time requirement from 0.10.6 to 0.12.1 (#429)1d5d4edchore(deps): update lzma-rust2 requirement from 0.13 to 0.14 (#432)72cce40chore(deps): update nt-time requirement from 0.10.6 to 0.12.1 (#428)2ef4d3echore(deps): update nt-time requirement from 0.10.6 to 0.12.1 (#427)9cf28cbtest(ci): Fix:renamecan't be skipped5987cddtest(ci): Fix: need recursive rename74f8a3ctest(ci): Need to rename more files during fuzz runsUpdates
crcfrom 3.3.0 to 3.4.0Commits
2c8fd96Prepare 3.4.0 release24e8317Fix clippy lints6826e6bUpdate CI to MSRV 1.832cee16fBump MSRV to 1.83 (2024-11-28)71fc292Make Digest 'update' method constUpdates
ccfrom 1.2.47 to 1.2.48Release notes
Sourced from cc's releases.
Changelog
Sourced from cc's changelog.
Commits
324a8eachore(cc): release v1.2.48 (#1621)ecf6fe9Regenerate target info (#1620)70fbb42Add publish environment for publishing crate (#1619)Updates
httpfrom 1.3.1 to 1.4.0Release notes
Sourced from http's releases.
Changelog
Sourced from http's changelog.
Commits
b9625d8v1.4.050b009crefactor(header): inline FNV hasher to reduce dependencies (#796)b370d36feat(uri): makeAuthority/PathAndQuery::from_staticconst (#786)0d74251chore(ci): update to actions/checkout@v5 (#800)a760767docs: remove unnecessary extern crate sentence (#799)fb1d457refactor(header): use better panic message in const HeaderName and HeaderValu...20dbd6efeat(status): Add 103 EARLY_HINTS status code (#758)e7a7337chore: bump MSRV to 1.571888e28tests: downgrade rand back to 0.8 for now918bbc3chore: minor improvement for docs (#790)Updates
rustls-pki-typesfrom 1.13.0 to 1.13.1Release notes
Sourced from rustls-pki-types's releases.
Commits
bbffac9Bump version to 1.13.1c0db55fRemove use of doc_auto_cfgf9faeb7Privatize docsrs cfg flag779560dAdd a check if all files are includedd46eb64Exclude test keys from published packageUpdates
tower-httpfrom 0.6.6 to 0.6.7Release notes
Sourced from tower-http's releases.
Commits
3bf1ba7v0.6.7723ca9afix(decompression): Suppress EOF errors caused by decompressing empty body (#...8ab9f82chore(ci): use newer cargo-public-api-crates job (#619)7cfdf76doc: Replace doc_auto_cfg with doc_cfg (#609)50beeafAdd support for custom status code in TimeoutLayer (#599)35740dedeps: Remove unnecessary dev-dependencies (#606)a7eefaeci: Re-enable ci on default branch (#605)12a5b33tests: Update to brotli 8 (#603)0195198ci: Update to actions/checkout v5 (#604)c757491examples: Update to axum 0.8 (#602)Updates
tracing-attributesfrom 0.1.30 to 0.1.31Release notes
Sourced from tracing-attributes's releases.
Commits
5508623chore: prepare tracing-attributes 0.1.31 (#3417)d92b4c0chore: prepare tracing-core 0.1.35 (#3414)9751b6echore: runtracing-subscribertests with all features (#3412)efa0169mock: add doctests foron_register_dispatchnegative cases (#3416)a093858docs: fix link inFmtSpandocs (#3411)976fa55mock: add test case for layer not calling on_register_dispatch (#3415)8bc008cfix(subscriber): make Layered propagate on_register_dispatch (#3379)adbd8a4appender: fixmax_filesinteger underflow when set to zero (#3348)2a8b040chore: add Hayden (@hds) to codeowners (#3410)cf5c2bdsubscriber: remove clone_span on enter (#3289)Updates
zerocopyfrom 0.8.28 to 0.8.30Release notes
Sourced from zerocopy's releases.
Commits
aa09c4fRelease 0.8.30 (#2816)31a2dfa[ci] Integrate action-validator into CI and pre-push hooks (#2811)738e3f2Invert build.rs version detection flags and update CI (#2804)16d065dFix safety comment citations (#2800)9483f7dSuppress deprecation warnings in generated code (#2797)c2e43ce[ci] Add MSRV minimality check (#2812)360bb2b[ci] Roll pinned nightly toolchain (#2814)f65c938Add missing copyright headers and audit instructions (#2795)cd0dcd0docs: Update AGENTS.md to mandate 'yes | ./cargo.sh' (#2799)ddcf94cFix Miri symbolic alignment check failures (#2798)Updates
zerocopy-derivefrom 0.8.28 to 0.8.30Release notes
Sourced from zerocopy-derive's releases.
Commits
aa09c4fRelease 0.8.30 (#2816)31a2dfa[ci] Integrate action-validator into CI and pre-push hooks (#2811)738e3f2Invert build.rs version detection flags and update CI (#2804)16d065dFix safety comment citations (#2800)9483f7dSuppress deprecation warnings in generated code (#2797)c2e43ce[ci] Add MSRV minimality check (#2812)360bb2b[ci] Roll pinned nightly toolchain (#2814)f65c938Add missing copyright headers and audit instructions (#2795)cd0dcd0docs: Update AGENTS.md to mandate 'yes | ./cargo.sh' (#2799)ddcf94cFix Miri symbolic alignment check failures (#2798)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions