From 7dc0d706e914899b199d4e3c3a38580806233535 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 19 Sep 2026 12:12:57 +0000 Subject: [PATCH] build(deps): bump base64 from 0.22.1 to 0.23.1 Bumps [base64](https://github.com/marshallpierce/rust-base64) from 0.22.1 to 0.23.1. - [Changelog](https://github.com/marshallpierce/rust-base64/blob/master/RELEASE-NOTES.md) - [Commits](https://github.com/marshallpierce/rust-base64/compare/v0.22.1...v0.23.1) --- updated-dependencies: - dependency-name: base64 dependency-version: 0.23.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] --- Cargo.lock | 4 ++-- crates/oauth-as-conformance/Cargo.toml | 2 +- crates/oauth-as/Cargo.toml | 4 ++-- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/Cargo.lock b/Cargo.lock index 68fa416..3df1875 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -1259,7 +1259,7 @@ version = "0.10.0" dependencies = [ "axum", "axum-server", - "base64 0.22.1", + "base64 0.23.1", "bytes", "ed25519-dalek", "getrandom 0.3.4", @@ -1281,7 +1281,7 @@ dependencies = [ name = "oauth-as-conformance" version = "0.1.0" dependencies = [ - "base64 0.22.1", + "base64 0.23.1", "hmac", "jsonwebtoken", "oauth2", diff --git a/crates/oauth-as-conformance/Cargo.toml b/crates/oauth-as-conformance/Cargo.toml index fc7a680..8ea5707 100644 --- a/crates/oauth-as-conformance/Cargo.toml +++ b/crates/oauth-as-conformance/Cargo.toml @@ -24,7 +24,7 @@ license = "MIT OR Apache-2.0" [dependencies] serde = { version = "1", features = ["derive"] } serde_json = "1" -base64 = "0.22" +base64 = "0.23" sha2 = "0.10" hmac = "0.12" # jsonwebtoken verifies the RFC 7515 Appendix A RS256/ES256 vectors and, in black-box mode, diff --git a/crates/oauth-as/Cargo.toml b/crates/oauth-as/Cargo.toml index cb6bcb3..f83f16e 100644 --- a/crates/oauth-as/Cargo.toml +++ b/crates/oauth-as/Cargo.toml @@ -288,7 +288,7 @@ serde = { version = "1", features = ["derive"] } serde_json = { version = "1", optional = true } getrandom = "0.3" sha2 = "0.10" # PKCE S256 (RFC 7636); verified against the RFC's appendix B vector -base64 = "0.22" # BASE64URL-without-padding, the exact PKCE challenge encoding +base64 = "0.23" # BASE64URL-without-padding, the exact PKCE challenge encoding # OPTIONAL, feature `http` only. The HTTP vocabulary, and nothing above it. # @@ -386,7 +386,7 @@ serde_json = "1" # — there is no access token in a proof's own signature, so the RS is the only party that can bind # the proof to the token. Both crates are already in the library's normal tree (base64 and sha2 back # PKCE), so declaring them dev-only adds nothing to a consumer's build. -base64 = "0.22" +base64 = "0.23" sha2 = "0.10" # IN-TREE CONFORMANCE CHECKS (dev-only; never in any shipped binary): # - `oauth2` is a widely used third-party OAuth 2 CLIENT. tests/third_party_client.rs drives it