Skip to content

ci(deps): bump the cargo-minor-patch group across 1 directory with 7 updates - #152

Merged
tonibergholm merged 2 commits into
mainfrom
dependabot/cargo/cargo-minor-patch-e46a95acce
Sep 24, 2026
Merged

tonibergholm merged 2 commits into
mainfrom
dependabot/cargo/cargo-minor-patch-e46a95acce

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026

Copy link
Copy Markdown
Contributor

Bumps the cargo-minor-patch group with 7 updates in the / directory:

Package From To
toml 1.1.4+spec-1.1.0 1.1.6+spec-1.1.0
clap 4.6.6 4.6.7
rustls 0.23.43 0.23.45
aws-config 1.11.0 1.12.0
aws-sdk-s3 1.144.0 1.146.1
tauri 2.11.5 2.11.6
tauri-plugin-dialog 2.7.2 2.7.3

Updates toml from 1.1.4+spec-1.1.0 to 1.1.6+spec-1.1.0

Commits
  • 572c005 chore: Release
  • 66d0c53 docs: Update changelog
  • 07af4e7 perf: Reduce allocations in toml_edit parsing and dumping (#1215)
  • 0ff90db perf(display): Write encoded strings directly
  • efb2536 perf(display): Move generated representation strings
  • 075c444 refactor(display): Consolidate key-path encoding
  • b48f338 perf(display): Borrow table keys during document output
  • c6c1de3 perf(parser): Move completed table header keys
  • ec90463 perf(parser): Borrow input when creating editable documents
  • d76a48a test: Benchmark rendering generated keys and values
  • Additional commits viewable in compare view

Updates clap from 4.6.6 to 4.6.7

Release notes

Sourced from clap's releases.

v4.6.7

[4.6.7] - 2026-09-14

Features

  • (derive) Add #[command(defer = <bool>)] attribute to opt-in to lazy initialisation of subcommands
Changelog

Sourced from clap's changelog.

[4.6.7] - 2026-09-14

Features

  • (derive) Add #[command(defer = <bool>)] attribute to opt-in to lazy initialisation of subcommands
Commits
  • d3e59a9 chore: Release
  • d997f87 docs: Update changelog
  • fb6058c Merge pull request #6409 from heaths/pwsh-support
  • 2310870 test(complete): Add tests for completer_for_path
  • 5967c17 refactor(complete): Move shell detection to Shells
  • 594602b fix(complete): Detect pwsh for PowerShell
  • 3a4f2d0 Merge pull request #6427 from clap-rs/renovate/shlex-2.x
  • 67ebaed Merge pull request #6426 from clap-rs/renovate/actions-checkout-7.x
  • c968b13 chore(deps): Update Rust crate shlex to v2
  • 8f247cb chore(deps): Update actions/checkout action to v7
  • Additional commits viewable in compare view

Updates rustls from 0.23.43 to 0.23.45

Commits
  • 2976d90 Prepare 0.23.45
  • f9d4ee9 Handshake "alignment" check covers previously-received messages
  • c4e92e8 Keep data needed for HRR processing together
  • e553a7a server: TLS1.2 is not available after a HRR
  • 5dff9da Test whether server negotiates TLS1.2 after HRR
  • 185a063 reject a second ClientHello that changes the cipher suite
  • 9fafe6d reject a second ClientHello that drops pre_shared_key
  • 1b42c5f providers: zeroize private key DER
  • 64ad386 Bump version to 0.23.44
  • 1efbf66 bogo: remove PostQuantum setup
  • Additional commits viewable in compare view

Updates aws-config from 1.11.0 to 1.12.0

Changelog

Sourced from aws-config's changelog.

September 21st, 2026

Breaking Changes:

  • 🐛⚠️ (client, smithy-rs#4805, smithy-rs#4810, smithy-rs#4827, @​yychen23) Across the Smithy runtime crates and generated SDK crates, http 0.2.x is now reached only through a named feature. Every crate below still supports it; nothing is removed.

    A default build is unchanged. Generated SDK crates still enable the rustls feature by default, which builds the legacy hyper 0.14 / rustls 0.21 HTTP client and brings http 0.2.x with it. No crate is added to or removed from a default dependency tree by this change. Making the default client opt-in is a separate, later change.

    What this change makes possible is removing http 0.2.x, which addresses the unpatched http 0.2.x advisories for builds that opt out. See "Removing http 0.2.x from your dependency tree" below.

    Recommended setup

    Most users need no feature configuration and are unaffected:

    aws-sdk-s3 = "..."

    Enable http-02x (on the SDK crate, or on the individual runtime crate) only if you need the http 0.2.x interop APIs:

    aws-sdk-s3 = { version = "...", features = ["http-02x"] }

    Removing http 0.2.x from your dependency tree

    If you need http 0.2.x gone entirely — for example to satisfy a patch-compliance scan, since http 0.2.x has unpatched advisories — disable default features and re-enable the ones you need, omitting rustls (and not enabling legacy-https-client, which selects the same legacy stack):

    aws-sdk-s3 = { version = "...", default-features = false, features = [
        "sigv4a", "http-1x", "default-https-client", "rt-tokio"
    ] }

    That is aws-sdk-s3's default feature list with rustls left out; the list varies slightly per SDK crate, so check the crate you depend on. The result has no http 0.2.x, http-body 0.4.x, hyper 0.14, rustls 0.21 or h2 0.3 in either normal or dev scope. aws-config needs no configuration — it already depends on the SDK crates it uses with default-features = false and defaults to default-https-client.

    Cargo features are additive, so this is the only way to get a smaller tree: there is no feature that removes http 0.2.x, only features that add it.

    aws-smithy-runtime-api

    http 0.2.x is now optional behind the pre-existing http-02x feature (off by default). The crate's internal HTTP representations (Headers, Uri, HttpError, EndpointPrefix, and request/response extensions) now use the http 1.x types.

    Breaking change: these previously unconditional pub conversions now require the http-02x feature:

    • Request::try_into_http02x and Response::try_into_http02x
    • impl From<http_02x::Uri> for Uri
    • impl TryInto<http_02x::Request<B>> for Request<B> and impl TryFrom<http_02x::Request<B>> for Request<B>
    • impl TryFrom<http_02x::Response<B>> for Response<B>
    • impl From<http_02x::StatusCode> for StatusCode and impl From<StatusCode> for http_02x::StatusCode
    • impl TryFrom<http_02x::HeaderMap> for Headers

... (truncated)

Commits

Updates aws-sdk-s3 from 1.144.0 to 1.146.1

Commits

Updates tauri from 2.11.5 to 2.11.6

Release notes

Sourced from tauri's releases.

tauri v2.11.6

Fetching advisory database from `https://github.com/RustSec/advisory-db.git`
      Loaded 1251 security advisories (from /home/runner/.cargo/advisory-db)
    Updating crates.io index
    Scanning Cargo.lock for vulnerabilities (1075 crate dependencies)
Crate:     fxhash
Version:   0.2.1
Warning:   unmaintained
Title:     fxhash - no longer maintained
Date:      2025-09-05
ID:        RUSTSEC-2025-0057
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0057

Crate: paste
Version: 1.0.15
Warning: unmaintained
Title: paste - no longer maintained
Date: 2024-10-07
ID: RUSTSEC-2024-0436
URL: https://rustsec.org/advisories/RUSTSEC-2024-0436

Crate: rustls-pemfile
Version: 1.0.4
Warning: unmaintained
Title: rustls-pemfile is unmaintained
Date: 2025-11-28
ID: RUSTSEC-2025-0134
URL: https://rustsec.org/advisories/RUSTSEC-2025-0134

Crate: rustls-pemfile
Version: 2.2.0
Warning: unmaintained
Title: rustls-pemfile is unmaintained
Date: 2025-11-28
ID: RUSTSEC-2025-0134
URL: https://rustsec.org/advisories/RUSTSEC-2025-0134

Crate: rustybuzz
Version: 0.20.1
Warning: unmaintained
Title: rustybuzz is unmaintained
Date: 2026-07-11
ID: RUSTSEC-2026-0206
URL: https://rustsec.org/advisories/RUSTSEC-2026-0206

Crate: ttf-parser
</tr></table>

... (truncated)

Commits

Updates tauri-plugin-dialog from 2.7.2 to 2.7.3

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…updates

Bumps the cargo-minor-patch group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [toml](https://github.com/toml-rs/toml) | `1.1.4+spec-1.1.0` | `1.1.6+spec-1.1.0` |
| [clap](https://github.com/clap-rs/clap) | `4.6.6` | `4.6.7` |
| [rustls](https://github.com/rustls/rustls) | `0.23.43` | `0.23.45` |
| [aws-config](https://github.com/smithy-lang/smithy-rs) | `1.11.0` | `1.12.0` |
| [aws-sdk-s3](https://github.com/awslabs/aws-sdk-rust) | `1.144.0` | `1.146.1` |
| [tauri](https://github.com/tauri-apps/tauri) | `2.11.5` | `2.11.6` |
| [tauri-plugin-dialog](https://github.com/tauri-apps/plugins-workspace) | `2.7.2` | `2.7.3` |



Updates `toml` from 1.1.4+spec-1.1.0 to 1.1.6+spec-1.1.0
- [Commits](toml-rs/toml@toml-v1.1.4...toml-v1.1.6)

Updates `clap` from 4.6.6 to 4.6.7
- [Release notes](https://github.com/clap-rs/clap/releases)
- [Changelog](https://github.com/clap-rs/clap/blob/main/CHANGELOG.md)
- [Commits](clap-rs/clap@clap_complete-v4.6.6...clap_complete-v4.6.7)

Updates `rustls` from 0.23.43 to 0.23.45
- [Release notes](https://github.com/rustls/rustls/releases)
- [Changelog](https://github.com/rustls/rustls/blob/main/CHANGELOG.md)
- [Commits](rustls/rustls@v/0.23.43...v/0.23.45)

Updates `aws-config` from 1.11.0 to 1.12.0
- [Release notes](https://github.com/smithy-lang/smithy-rs/releases)
- [Changelog](https://github.com/smithy-lang/smithy-rs/blob/main/CHANGELOG.md)
- [Commits](https://github.com/smithy-lang/smithy-rs/commits)

Updates `aws-sdk-s3` from 1.144.0 to 1.146.1
- [Release notes](https://github.com/awslabs/aws-sdk-rust/releases)
- [Commits](https://github.com/awslabs/aws-sdk-rust/commits)

Updates `tauri` from 2.11.5 to 2.11.6
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](tauri-apps/tauri@tauri-v2.11.5...tauri-v2.11.6)

Updates `tauri-plugin-dialog` from 2.7.2 to 2.7.3
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@dialog-v2.7.2...dialog-v2.7.3)

---
updated-dependencies:
- dependency-name: toml
  dependency-version: 1.1.6+spec-1.1.0
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-minor-patch
- dependency-name: clap
  dependency-version: 4.6.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-minor-patch
- dependency-name: rustls
  dependency-version: 0.23.45
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-minor-patch
- dependency-name: aws-config
  dependency-version: 1.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-minor-patch
- dependency-name: aws-sdk-s3
  dependency-version: 1.146.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-minor-patch
- dependency-name: tauri
  dependency-version: 2.11.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-minor-patch
- dependency-name: tauri-plugin-dialog
  dependency-version: 2.7.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 24, 2026
@dependabot
dependabot Bot requested a review from tonibergholm as a code owner September 24, 2026 07:15
@dependabot dependabot Bot added the rust Pull requests that update rust code label Sep 24, 2026
tonibergholm pushed a commit that referenced this pull request Sep 24, 2026
This PR touches vendor/glib-0.18.5-patched/, which triggers cargo audit,
and main still carries rustls 0.23.43. Taking #152's lockfile verbatim
keeps audit green here; it no-ops once #152 merges.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013z24CKdETNZRqL7CKMur99
@tonibergholm
tonibergholm merged commit 56ef52c into main Sep 24, 2026
8 checks passed
@dependabot
dependabot Bot deleted the dependabot/cargo/cargo-minor-patch-e46a95acce branch September 24, 2026 10:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants