Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump the cargo group across 1 directory with 3 updates #33

Merged
merged 1 commit into from
May 24, 2024

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github May 23, 2024

Bumps the cargo group with 3 updates in the /src-tauri directory: tauri, h2 and rustls.

Updates tauri from 1.6.1 to 1.6.2

Release notes

Sourced from tauri's releases.

tauri v1.6.2

Updating crates.io index

Fetching advisory database from `https://github.com/RustSec/advisory-db.git`
      Loaded 621 security advisories (from /home/runner/.cargo/advisory-db)
    Updating crates.io index
    Scanning Cargo.lock for vulnerabilities (577 crate dependencies)
Crate:     atty
Version:   0.2.14
Warning:   unsound
Title:     Potential unaligned read
Date:      2021-07-04
ID:        RUSTSEC-2021-0145
URL:       https://rustsec.org/advisories/RUSTSEC-2021-0145
Dependency tree:
atty 0.2.14
└── clap 3.2.25
    └── tauri 1.6.2
        ├── tauri 1.6.2
        ├── restart 0.1.0
        └── app-updater 0.1.0

warning: 1 allowed warning found

[1.6.2]

Bug Fixes

  • e3b6d38d2(#9166) Fix basename(path, 'ext') JS API when removing all occurances of ext where it should only remove the last one.
  • 705da977a(#9529) Do not use JS optional chaining to prevent script errors on older webviews such as macOS 10.14.
Updating crates.io index
   Packaging tauri v1.6.2 (/home/runner/work/tauri/tauri/core/tauri)
    Updating crates.io index
   Verifying tauri v1.6.2 (/home/runner/work/tauri/tauri/core/tauri)
 Downloading crates ...
  Downloaded alloc-stdlib v0.2.2
  Downloaded cairo-sys-rs v0.15.1
  Downloaded atk-sys v0.15.1
  Downloaded cairo-rs v0.15.12
</tr></table> 

... (truncated)

Commits
  • caddd5b Apply Version Updates From Current Changes (v1) (#9544)
  • 72c2636 chore(ci): fix MSRV downgrade (#9543)
  • 83e024c chore(ci): downgrade home crate (#9542)
  • 07c9e35 fix(ci): downgrade cc crate for MSRV compatibility (#9541)
  • d00178d ci: Fix package downgrades in covector workflow (#9538)
  • 705da97 fix: optional chaining is not supported on older webviews (#9529)
  • 1675e41 fix(bundler): don't convert product name to snake case when cross compiling (...
  • f9638b6 fix(cli): append extension to app binary manually on rename (#9491)
  • aeddc40 fix(cli/info): fix crash when checking node version (#9411)
  • fe6f81f chore: fix clippy false positive (#9329)
  • Additional commits viewable in compare view

Updates h2 from 0.4.3 to 0.4.5

Release notes

Sourced from h2's releases.

v0.4.5

What's Changed

New Contributors

v0.4.4

Fixes

  • Limit number of CONTINUATION frames for misbehaving connections.

See https://seanmonstar.com/blog/hyper-http2-continuation-flood/ for more info.

Changelog

Sourced from h2's changelog.

0.4.5 (May 17, 2024)

  • Fix race condition that sometimes hung connections during shutdown.
  • Fix pseudo header construction for CONNECT and OPTIONS requests.

0.4.4 (April 3, 2024)

  • Limit number of CONTINUATION frames for misbehaving connections.
Commits
  • f161f7c v0.4.5
  • 3c41151 Replace futures-util with atomic-waker and manual poll_fn (#721)
  • c83b2d5 Fix request pseudo-header construction for CONNECT & OPTION methods (#770)
  • ecb0095 chore(lib): fix unexpected cfg warning (#777)
  • 092f3b3 examples: update to rustls 0.23
  • be12983 Fix race condition in connection termination
  • 0d66e3c readme: Added link to Tokio Discord. (#771)
  • e2168de chore: add simple h2 benchmark (#762)
  • 51fe05a v0.4.4
  • e76bd74 fix: limit number of CONTINUATION frames allowed
  • See full diff in compare view

Updates rustls from 0.22.3 to 0.22.4

Commits
  • ae277be Prepare 0.22.4
  • 5374108 complete_io: bail out if progress is impossible
  • 00e695d Regression test for complete_io infinite loop bug
  • 0c6cd7e Don't specially handle unauthenticated close_notify alerts
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the cargo group with 3 updates in the /src-tauri directory: [tauri](https://github.com/tauri-apps/tauri), [h2](https://github.com/hyperium/h2) and [rustls](https://github.com/rustls/rustls).


Updates `tauri` from 1.6.1 to 1.6.2
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](tauri-apps/tauri@tauri-v1.6.1...tauri-v1.6.2)

Updates `h2` from 0.4.3 to 0.4.5
- [Release notes](https://github.com/hyperium/h2/releases)
- [Changelog](https://github.com/hyperium/h2/blob/master/CHANGELOG.md)
- [Commits](hyperium/h2@v0.4.3...v0.4.5)

Updates `rustls` from 0.22.3 to 0.22.4
- [Release notes](https://github.com/rustls/rustls/releases)
- [Changelog](https://github.com/rustls/rustls/blob/main/CHANGELOG.md)
- [Commits](rustls/rustls@v/0.22.3...v/0.22.4)

---
updated-dependencies:
- dependency-name: tauri
  dependency-type: direct:production
  dependency-group: cargo
- dependency-name: h2
  dependency-type: indirect
  dependency-group: cargo
- dependency-name: rustls
  dependency-type: indirect
  dependency-group: cargo
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file rust Pull requests that update Rust code labels May 23, 2024
@Somfic Somfic merged commit ffa232c into main May 24, 2024
2 checks passed
@dependabot dependabot bot deleted the dependabot/cargo/src-tauri/cargo-1d60c2f697 branch May 24, 2024 00:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file rust Pull requests that update Rust code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant