chore(deps): Bump the cargo-minor-patch group across 1 directory with 17 updates - #388
chore(deps): Bump the cargo-minor-patch group across 1 directory with 17 updates#388dependabot[bot] wants to merge 1 commit into
Conversation
|
@dependabot rebase |
cc15460 to
ae16cae
Compare
|
@dependabot rebase |
ae16cae to
8411734
Compare
|
@dependabot rebase |
8411734 to
0fe8048
Compare
There was a problem hiding this comment.
Reviewed exact head 0fe8048 against dev 493b7e7.
This is a lockfile-only update. The refreshed lockfile reproducibly preserves the scheduler entries from #372, the russh 0.62.5 and quinn-proto 0.11.16 security repairs from #387, and all 57 workspace packages while applying all 17 grouped updates. futures resolves to 0.3.34.
Local exact-head evidence: locked metadata passed; all-target checks passed for ardur-memory-qdrant and the automation, CLI, and E2E scheduler surfaces. Exact-head cargo-deny, dependency review, CodeQL, Ubuntu, macOS, live Qdrant integration, Docker health/SBOM/Trivy, DCO, and Hugo checks are green.
dev has since advanced via #373, but that merge changes only injection-defense source and its regression test; it does not overlap this Cargo.lock-only diff. No blocking findings.
|
@dependabot rebase |
0fe8048 to
c0d6bd4
Compare
gnanirahulnutakki
left a comment
There was a problem hiding this comment.
Reviewed exact head c0d6bd4 on tested base 940d72e. Current dev@cc5f6af adds only #390's site package files, with no Cargo.lock overlap. The PR remains lockfile-only and retains all 17 intended dependency updates. Relative to the previously reviewed payload, the only material refresh delta is incorporation of #380's active workspace base64 0.22.1 to 0.23.1 resolution; required transitive 0.13.1 and 0.22.1 entries remain. Exact-head locked metadata, diff checks, cargo-deny advisories/bans/licenses/sources, and focused locked Cedar, Qdrant-memory, embeddings, automation, CLI, and E2E tests pass. Hosted Ubuntu, macOS, live Qdrant, cargo-deny, dependency review, CodeQL, Docker image/health/SBOM/Trivy, DCO, and site gates are green. The advisory-specific RUSTSEC-2025-0134 ignore is now stale because rustls-pemfile is absent from the resolved graph; that is zero current exposure and safe follow-up cleanup, not a blocker. No blocking findings.
c0d6bd4 to
ccf7b02
Compare
… 17 updates Bumps the cargo-minor-patch group with 17 updates in the / directory: | Package | From | To | | --- | --- | --- | | [cedar-policy](https://github.com/cedar-policy/cedar) | `4.11.2` | `4.12.0` | | [libc](https://github.com/rust-lang/libc) | `0.2.186` | `0.2.189` | | [regex](https://github.com/rust-lang/regex) | `1.13.0` | `1.13.1` | | [ignore](https://github.com/BurntSushi/ripgrep) | `0.4.28` | `0.4.33` | | [cargo-lock](https://github.com/rustsec/rustsec) | `11.0.1` | `11.1.0` | | [serde_json](https://github.com/serde-rs/json) | `1.0.150` | `1.0.151` | | [anyhow](https://github.com/dtolnay/anyhow) | `1.0.103` | `1.0.104` | | [thiserror](https://github.com/dtolnay/thiserror) | `2.0.18` | `2.0.20` | | [qdrant-client](https://github.com/qdrant/rust-client) | `1.18.0` | `1.19.0` | | [async-trait](https://github.com/dtolnay/async-trait) | `0.1.89` | `0.1.92` | | [futures](https://github.com/rust-lang/futures-rs) | `0.3.32` | `0.3.33` | | [rand](https://github.com/rust-random/rand) | `0.10.1` | `0.10.2` | | [serde](https://github.com/serde-rs/serde) | `1.0.228` | `1.0.229` | | [tokio](https://github.com/tokio-rs/tokio) | `1.52.3` | `1.53.1` | | [uuid](https://github.com/uuid-rs/uuid) | `1.23.4` | `1.24.0` | | [clap](https://github.com/clap-rs/clap) | `4.6.1` | `4.6.6` | | [fastembed](https://github.com/Anush008/fastembed-rs) | `5.17.2` | `5.17.4` | Updates `cedar-policy` from 4.11.2 to 4.12.0 - [Release notes](https://github.com/cedar-policy/cedar/releases) - [Commits](cedar-policy/cedar@cedar-policy-cli-v4.11.2...cedar-policy-cli-v4.12.0) Updates `libc` from 0.2.186 to 0.2.189 - [Release notes](https://github.com/rust-lang/libc/releases) - [Changelog](https://github.com/rust-lang/libc/blob/0.2.189/CHANGELOG.md) - [Commits](rust-lang/libc@0.2.186...0.2.189) Updates `regex` from 1.13.0 to 1.13.1 - [Release notes](https://github.com/rust-lang/regex/releases) - [Changelog](https://github.com/rust-lang/regex/blob/master/CHANGELOG.md) - [Commits](rust-lang/regex@1.13.0...1.13.1) Updates `ignore` from 0.4.28 to 0.4.33 - [Release notes](https://github.com/BurntSushi/ripgrep/releases) - [Changelog](https://github.com/BurntSushi/ripgrep/blob/master/CHANGELOG.md) - [Commits](BurntSushi/ripgrep@ignore-0.4.28...ignore-0.4.33) Updates `cargo-lock` from 11.0.1 to 11.1.0 - [Release notes](https://github.com/rustsec/rustsec/releases) - [Commits](rustsec/rustsec@cargo-lock/v11.0.1...cargo-lock/v11.1.0) Updates `serde_json` from 1.0.150 to 1.0.151 - [Release notes](https://github.com/serde-rs/json/releases) - [Commits](serde-rs/json@v1.0.150...v1.0.151) Updates `anyhow` from 1.0.103 to 1.0.104 - [Release notes](https://github.com/dtolnay/anyhow/releases) - [Commits](dtolnay/anyhow@1.0.103...1.0.104) Updates `thiserror` from 2.0.18 to 2.0.20 - [Release notes](https://github.com/dtolnay/thiserror/releases) - [Commits](dtolnay/thiserror@2.0.18...2.0.20) Updates `qdrant-client` from 1.18.0 to 1.19.0 - [Release notes](https://github.com/qdrant/rust-client/releases) - [Commits](qdrant/rust-client@v1.18.0...v1.19.0) Updates `async-trait` from 0.1.89 to 0.1.92 - [Release notes](https://github.com/dtolnay/async-trait/releases) - [Commits](dtolnay/async-trait@0.1.89...0.1.92) Updates `futures` from 0.3.32 to 0.3.33 - [Release notes](https://github.com/rust-lang/futures-rs/releases) - [Changelog](https://github.com/rust-lang/futures-rs/blob/main/CHANGELOG.md) - [Commits](rust-lang/futures-rs@0.3.32...0.3.33) Updates `rand` from 0.10.1 to 0.10.2 - [Release notes](https://github.com/rust-random/rand/releases) - [Changelog](https://github.com/rust-random/rand/blob/master/CHANGELOG.md) - [Commits](rust-random/rand@0.10.1...0.10.2) Updates `serde` from 1.0.228 to 1.0.229 - [Release notes](https://github.com/serde-rs/serde/releases) - [Commits](serde-rs/serde@v1.0.228...v1.0.229) Updates `tokio` from 1.52.3 to 1.53.1 - [Release notes](https://github.com/tokio-rs/tokio/releases) - [Commits](tokio-rs/tokio@tokio-1.52.3...tokio-1.53.1) Updates `uuid` from 1.23.4 to 1.24.0 - [Release notes](https://github.com/uuid-rs/uuid/releases) - [Commits](uuid-rs/uuid@v1.23.4...v1.24.0) Updates `clap` from 4.6.1 to 4.6.6 - [Release notes](https://github.com/clap-rs/clap/releases) - [Changelog](https://github.com/clap-rs/clap/blob/master/CHANGELOG.md) - [Commits](clap-rs/clap@clap_complete-v4.6.1...clap_complete-v4.6.6) Updates `fastembed` from 5.17.2 to 5.17.4 - [Release notes](https://github.com/Anush008/fastembed-rs/releases) - [Commits](Anush008/fastembed-rs@v5.17.2...v5.17.4) --- updated-dependencies: - dependency-name: anyhow dependency-version: 1.0.104 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo-minor-patch - dependency-name: async-trait dependency-version: 0.1.92 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo-minor-patch - dependency-name: cargo-lock dependency-version: 11.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-minor-patch - dependency-name: cedar-policy dependency-version: 4.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-minor-patch - dependency-name: clap dependency-version: 4.6.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo-minor-patch - dependency-name: fastembed dependency-version: 5.17.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo-minor-patch - dependency-name: futures dependency-version: 0.3.33 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo-minor-patch - dependency-name: ignore dependency-version: 0.4.33 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo-minor-patch - dependency-name: libc dependency-version: 0.2.189 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo-minor-patch - dependency-name: qdrant-client dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-minor-patch - dependency-name: rand dependency-version: 0.10.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo-minor-patch - dependency-name: regex dependency-version: 1.13.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo-minor-patch - dependency-name: serde dependency-version: 1.0.229 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo-minor-patch - dependency-name: serde_json dependency-version: 1.0.151 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo-minor-patch - dependency-name: thiserror dependency-version: 2.0.20 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo-minor-patch - dependency-name: tokio dependency-version: 1.53.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-minor-patch - dependency-name: uuid dependency-version: 1.24.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com>
ccf7b02 to
efa218b
Compare
gnanirahulnutakki
left a comment
There was a problem hiding this comment.
Re-reviewed exact head efa218b0711ef1f41a180677985fd52a47921126 against current dev@81ca46340a068c31872fa2ea7e946586fe3a6755.
This refresh preserves the previously reviewed lockfile payload: all 17 intended direct updates remain at the same resolved versions (including futures 0.3.34), with identical package-add/remove and dependency-edge deltas. The only additional changed workspace record is ardur-code-execution, introduced by the advanced base after #381 merged.
Local exact-head evidence: cargo metadata --locked, cargo check --locked -p ardur-code-execution --all-targets, and all 19 ardur-code-execution tests pass. Exact-head cargo-deny, dependency review, CodeQL, Ubuntu, macOS, live Qdrant integration, Docker health/SBOM/Trivy, DCO, and Hugo checks are green.
No blocking findings.
Bumps the cargo-minor-patch group with 17 updates in the / directory:
4.11.24.12.00.2.1860.2.1891.13.01.13.10.4.280.4.3311.0.111.1.01.0.1501.0.1511.0.1031.0.1042.0.182.0.201.18.01.19.00.1.890.1.920.3.320.3.330.10.10.10.21.0.2281.0.2291.52.31.53.11.23.41.24.04.6.14.6.65.17.25.17.4Updates
cedar-policyfrom 4.11.2 to 4.12.0Release notes
Sourced from cedar-policy's releases.
Commits
fdcbaedCherry-pick: Fix package failure (#2497) --> 4.12.x (#2498)e8c3e3cNormalized release branch changelogs (#2486)1d65080Added script to automate minor version releases (#2484)be57bc1make proto encode faillible on message depth (#2479)277b579Fix model decoding fortags Bool(#2480)7c9e52cRemove unnecessary use of educe (#2483)f49b722Bump the github-actions group with 3 updates (#2481)763cb70Bump the rust-dependencies group across 1 directory with 58 updates (#2482)b7ff8e5removeLiteralPolicyfor proto and merge validation steps (#2475)a3e8a3fUse schema inrun_testscontext parsing (#2473)Updates
libcfrom 0.2.186 to 0.2.189Release notes
Sourced from libc's releases.
... (truncated)
Changelog
Sourced from libc's changelog.
... (truncated)
Commits
ef0906elibc: Release 0.2.1895a79f76riscv32-musl: Rename padding fields to avoid a conflict3e51062psp: Fixoverflowing_literalswarningse352fddemscripten: add pthread_sigmask, sigwait, sigwaitinfo, sigtimedwait, faccessa...63221b3macros: Requiresafeinsafe_f!invocations707ab52macros: Requireunsafeinf!invocations8e40c94Enable clone3() syscall on sparc-linux and sparc64-linux8427909windows: Add back link names fortime-related symbolsb4863fanuttx: fix wchar_t definition under arm41c683dnuttx: mirror type definitionsUpdates
regexfrom 1.13.0 to 1.13.1Changelog
Sourced from regex's changelog.
Commits
2b527591.13.1, redux40e98231.13.175fcb96changelog: 1.13.164ad0b6automata: fix bug in reverse suffix/inner optimizationfa91c31automata: fix a bug caught by Codex review30390ecautomata: formatting tweaks821a8ebautomata: refactor reverse suffix/inner search slightly10afd70automata: expose the extracted literals for inner literal extraction8c34f41automata: avoid reverse suffix optimization for non-leftmost-first5524f02test: add regression tests for failed reverse suffix/inner optimizationsUpdates
ignorefrom 0.4.28 to 0.4.33Commits
3fce3b5ignore-0.4.335055264globset-0.4.20020687aignore,globset: increase pool capacity5ed408eignore-0.4.32435f59fignore: skip loading unreachable ignore filesf9c05a9index: remove incorrect README8372866index: add some initial indexing scaffoldingd99ac34core: addindexmodule2ed0c00flags: disable many flags when indexing is enabled59e318fignore-0.4.31Updates
cargo-lockfrom 11.0.1 to 11.1.0Release notes
Sourced from cargo-lock's releases.
Commits
86193f5cargo-lock: bump version to 11.1.074cf201rustsec: lint affected arch/os against known platformsbba6794rustsec: use String to represent advisory arch and os5cdc6efcargo-lock: replace gumdrop with clap2b8e060admin: use parallel crate metadata downloading for synchronizer287c35eadmin: outline crates.io checks7dfba22rustsec: yield references to OSV advisory crate names554b276admin: avoid consuming OSV advisory list184a9dbadmin: simplify collection of aliases4485662admin: retrieve affected crates where necessaryUpdates
serde_jsonfrom 1.0.150 to 1.0.151Release notes
Sourced from serde_json's releases.
Commits
de85007Release 1.0.1513b2b3c5Merge pull request #1331 from WonderLawrence/rawvalue-from-string-unchecked0406d96Debug-assert well-formedness and no-whitespace in from_string_uncheckedcf16f75Add RawValue::from_string_unchecked827a315Update actions/upload-artifact@v6 -> v7cea36a5Update actions/checkout@v6 -> v7Updates
anyhowfrom 1.0.103 to 1.0.104Release notes
Sourced from anyhow's releases.
Commits
1dbe186Release 1.0.104f6479f8Update to syn 3Updates
thiserrorfrom 2.0.18 to 2.0.20Release notes
Sourced from thiserror's releases.
Commits
b1d5db5Release 2.0.20c4c3ebdMerge pull request #454 from dtolnay/clippy2266152Suppress redundant_field_names clippy lint2901cfdRaise minimum tested compiler to rust 1.88aa9d91fUpdate ui tests for version 2.0.19e13a785Release 2.0.190a0e76cUpdate to syn 3ec42ea7Update actions/upload-artifact@v6 -> v74178c4aUpdate actions/checkout@v6 -> v77214e0eIgnore items_after_statements pedantic clippy lint in testUpdates
qdrant-clientfrom 1.18.0 to 1.19.0Release notes
Sourced from qdrant-client's releases.
Commits
fc8ce23Bump version to 1.19.05ffa732Sync 1.19 client with latest dev protobuf (#290)3631300Update rust client for 1.19 (#288)d4b0466feat(client): opt-in connection check on Qdrant::build() (#286)fb0d0e7chore: add dependabot cooldown configuration (#285)46f77f2chore: add Dependabot configuration (#284)4c4e356chore: update dependencies (#283)e81d7ccci: update github actions to node 24 (#281)Updates
async-traitfrom 0.1.89 to 0.1.92Release notes
Sourced from async-trait's releases.
Commits
82e7e9eRelease 0.1.929a35cb8Merge pull request #303 from dtolnay/mustuse875ceecResolve double_must_use clippy lint62993a5Raise minimum tested compiler to rust 1.88d049ee0Release 0.1.917a0961fMerge pull request #301 from dtolnay/mutability740f86fIgnore mut_mut pedantic clippy lint in test4699cd3Fix mutability for by-reference receivers6dd3573Add regression test for issue 3002371797Release 0.1.90Updates
futuresfrom 0.3.32 to 0.3.33Release notes
Sourced from futures's releases.
Changelog
Sourced from futures's changelog.
Commits
89cc254Release 0.3.33cd9f5beci: Update release workflowd79a499Resolve rustdoc::broken_intra_doc_links warning95bbcf8Resolve rustdoc ambiguous link error303c165Resolve rustdoc::redundant_explicit_links warningf34e3f5ci: Cleanup66591a2Enable Miri for more testsab1072fSimplify target_has_atomic cfg in utility cratescf5d23bFix unsound compat01as03 implementation (fixes #2514) (#3012)8ae794fAdd portable-atomic-alloc feature and use it in FuturesUnordered (#3007)Updates
randfrom 0.10.1 to 0.10.2Changelog
Sourced from rand's changelog.
Commits
1540ea3Prepare rand 0.10.2 (#1800)a29964aBump chacha20 from 0.10.0 to 0.10.1 in the all-deps group (#1801)ced9491Tweak docs for RngExt::random_range and SampleRange (#1798)db14664Check UniformChar validity on deser (#1790)bea8620Bump the all-deps group with 2 updates (#1796)4f44932Bump actions/cache from 5 to 6 (#1795)b999a13Bump actions/checkout from 6 to 7 (#1794)aeab810Avoid unsafe where safety depends on non-local values (#1791)1896d7cAdd typos CI job (#1789)43eddeeBump the all-deps group with 2 updates (#1788)Updates
serdefrom 1.0.228 to 1.0.229Release notes
Sourced from serde's releases.
Commits
7fc3b4cRelease 1.0.2296d6e9a1Merge pull request #3085 from dtolnay/syn36dec3b7Update to syn 3cfe6692Resolve mut_mut pedantic clippy lint1023d07Update actions/upload-artifact@v6 -> v7dd682c2Update actions/checkout@v6 -> v75f0f18bUpdate ui test suite to nightly-2026-06-0163a1498Regenerate stderr with trybuild normalization fixesfa7da4aFix unused_features warning6b1a178Unpin CI miri toolchainUpdates
tokiofrom 1.52.3 to 1.53.1Release notes
Sourced from tokio's releases.
... (truncated)
Commits
75fef53chore: prepare Tokio v1.53.1 (#8303)ae9d011signal: restore MSRV by removing OnceLock::wait from the Windows handler (#8300)eb4988dtime: fix the loom test of the race between cancellation/insertion (#8302)91d3b4ctime: fix alt timer cancellation and insertion race (#8252)a463384runtime: remove dead link definition inRuntime::block_on(#8301)be689a3chore: prepare Tokio v1.53.0 (#8294)50f76c7chore: prepare tokio-macros v2.7.1 (#8295)f61fccaMerge 'tokio-1.52.4' into 'master' (#8290)efdba5fchore: prepare Tokio v1.52.4 (#8289)b0ba02eMerge 'tokio-1.51.4' into 'tokio-1.52.x' (#8288)Updates
uuidfrom 1.23.4 to 1.24.0Release notes
Sourced from uuid's releases.
Commits
6a8aeabMerge pull request #896 from uuid-rs/cargo/v1.24.0e6db8ecprepare for 1.24.0 release606f236Merge pull request #892 from weifanglab/mainab848dbfeat(fmt): support encoding into MaybeUninit buffers5dc6b3dMerge pull request #895 from uuid-rs/cargo/v1.23.55a7dfe5prepare for 1.23.5 release9b4bfc8Merge pull request #894 from geeknoid/main5acc5a5perf: Optimize UUID hex parsing and formatting6fa1a1efeat(fmt): support encoding into MaybeUninit buffers1e5d867Merge pull request #891 from frostyplanet/docUpdates
clapfrom 4.6.1 to 4.6.6Release notes
Sourced from clap's releases.
Changelog
Sourced from clap's changelog.
Commits
348cff3chore: Released478377docs: Update changelog04b9fbbMerge pull request #6414 from koopatroopa787/fix-bash-completion-bracket-glob7075239Merge pull request #6422 from BaumiCoder/fix-fish-indentationsf90a966fix(complete): Use spaces for indentation in fishdd4997bfix(complete): Don't glob-expand bash positionals8387c81Merge pull request #6399 from clap-rs/renovate/crate-ci-typos-1.x8141e11chore(deps): Update compatible (dev) (#6398)8a6bd4echore(deps): Update pre-commit hook crate-ci/typos to v1.47.071a7213chore(deps): Update Rust Stable to v1.96 (#6396)Updates
fastembedfrom 5.17.2 to 5.17.4Release notes
Sourced from fastembed's releases.
Commits
1bbd0b6chore(release): 5.17.4 [skip ci]a9a6679chore: bumportto2.0.0-rc.134e9dc55chore(release): 5.17.3 [skip ci]3fd10f9chore(deps): update candle-core requirement from 0.10.2 to 0.11.0 (#270)