chore: bump the cargo group with 3 updates - #11
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the cargo group with 3 updates: dirs, [toml](https://github.com/toml-rs/toml) and [ureq](https://github.com/algesten/ureq). Updates `dirs` from 6.0.0 to 7.0.0 Updates `toml` from 1.1.4+spec-1.1.0 to 1.1.5+spec-1.1.0 - [Commits](toml-rs/toml@toml-v1.1.4...toml-v1.1.5) Updates `ureq` from 3.4.0 to 3.4.1 - [Changelog](https://github.com/algesten/ureq/blob/main/CHANGELOG.md) - [Commits](algesten/ureq@3.4.0...3.4.1) --- updated-dependencies: - dependency-name: dirs dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: cargo - dependency-name: toml dependency-version: 1.1.5+spec-1.1.0 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo - dependency-name: ureq dependency-version: 3.4.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: cargo ... Signed-off-by: dependabot[bot] <support@github.com>
|
Note Reviewed by mtsu-patrol using glm-5.3 Patrol complete. Nothing to report within the inspected scope. Patrol reviewed the dependency-only diff at 9ed169f. It bumps dirs 6.0.0 → 7.0.0 (via Cargo.toml) and, as lock side-effects, toml 1.1.4 → 1.1.5 and ureq 3.4.0 → 3.4.1 (ureq-proto 0.6.1 → 0.6.2). The only behavioral change in dirs 7 is Commit: Coverage: Cargo.toml / Cargo.lock diff (dirs 6.0.0→7.0.0, toml 1.1.4→1.1.5, ureq 3.4.0→3.4.1, ureq-proto 0.6.1→0.6.2); Uses of dirs:: in this repo (paths.rs expand(); config.rs config_dir()/home_dir) checked against the dirs 7 API surface; Downloaded and diffed dirs 6.0.0 vs 7.0.0 published crate sources: only behavioral change is Windows preference_dir (LocalAppData → RoamingAppData), unused by fastpick; dirs-sys pinned at 0.5.0 in both, matching the lock; Diffed toml 1.1.4 vs 1.1.5 sources: changes are internal (DeValue lifetime/ownership plumbing via make_owned) with no parse-semantics change evident; Reviewed ureq 3.4.1 CHANGELOG: bug fixes only (ureq-proto parsing/header fixes, connection pooling and timeout fixes) Limitations: No Rust toolchain is available in the review environment (cargo/rustc not found), so the crate could not be built and its test suite could not be executed; conclusions are from source and published-crate diffs, not a run; The ser/mod.rs portion of the toml 1.1.4→1.1.5 diff was not fully inspected; ureq-proto 0.6.1→0.6.2 changes were only reviewed via the ureq CHANGELOG summary, not by diffing crate sources; dirs 7.0.0 MSRV/edition compatibility with fastpick's rust-version 1.88 was not verified by compilation; dirs-sys 0.5.0 itself was not re-diffed (lock shows it unchanged, so it was judged out of scope); Investigation was shortened to reserve budget for the report. Coverage is limited to the checks listed above. |
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Bumps the cargo group with 3 updates: dirs, toml and ureq.
Updates
dirsfrom 6.0.0 to 7.0.0Updates
tomlfrom 1.1.4+spec-1.1.0 to 1.1.5+spec-1.1.0Commits
e93ed4echore: Released23436ddocs: Update changelog151afcdfix(de): Ensure DeValue::make_owned includes DeInteger/DeFloat (#1211)26a4050fix(de): Ensure DeValue::make_owned includes DeInteger/DeFloat232f136chore(deps): Update Prek to v0.5.1 (#1209)9ee4b4echore(deps): Update crate-ci/typos digest to 4d9c206 (#1208)525f352chore(deps): Update crate-ci/committed digest to 800a04e (#1207)46043edchore(deps): Update crate-ci/typos digest to 4d9c206c00e894chore(deps): Update crate-ci/committed digest to 800a04e1ae0158chore(deps): Update Prek to v0.5.0 (#1205)Updates
ureqfrom 3.4.0 to 3.4.1Changelog
Sourced from ureq's changelog.
Commits
cf4a3cd3.4.19559d7bBump ureq-proto to 0.6.2 (#1199)9eb654cDo not pool a connection with unconsumed input (#1198)5b81318Anchor timeout budgets to phase boundaries (#1194)d480543Complete TLS handshakes while connecting (#1193)662410bBuffer read_json into memory when Content-Length is below the limit (#1191)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions