Skip to content

build(deps): bump the cargo group across 1 directory with 10 updates - #320

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-44a34dc580
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-44a34dc580

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the cargo group with 10 updates in the / directory:

Package From To
thiserror 2.0.18 2.0.21
rustix 1.1.4 1.1.5
tree-sitter-cfml 0.26.42 0.26.43
tree-sitter-swift 0.7.3 0.7.4
tokio 1.53.1 1.53.2
reqwest 0.13.4 0.13.5
tokio-stream 0.1.18 0.1.19
futures-util 0.3.32 0.3.34
http-body-util 0.1.3 0.1.5
libc 0.2.189 0.2.190

Updates thiserror from 2.0.18 to 2.0.21

Release notes

Sourced from thiserror's releases.

2.0.21

  • Fix parsing of generic unit variants in display expressions (#459)

2.0.20

  • Suppress redundant_field_names clippy lint in generated code (#454)

2.0.19

  • Update to syn 3
Commits
  • b1827ee Release 2.0.21
  • 58037b5 Merge pull request #459 from dtolnay/turbofish
  • f82a0cf Keep track of nested turbofish depth
  • 72ea492 Raise required compiler to Rust 1.77
  • 72eea0d Resolve io_other_error clippy lint in tests
  • 07f09a2 Raise required compiler to Rust 1.74
  • 2715388 Update ui test suite to nightly-2026-09-22
  • 5a306c7 Update ui test suite to nightly-2026-09-05
  • ef9383b Update ui test suite to nightly-2026-08-22
  • 8336b84 Update ui tests for version 2.0.20
  • Additional commits viewable in compare view

Updates rustix from 1.1.4 to 1.1.5

Commits

Updates tree-sitter-cfml from 0.26.42 to 0.26.43

Release notes

Sourced from tree-sitter-cfml's releases.

v0.26.43

cfml & cfquery

  • An HTML tag name can contain a dot (#169). <system.webServer>…</system.webServer>, the IIS web.config section often built in a <cfsavecontent>, read as the tag <system with an attribute .webServer. Its end tag then matched nothing, and the ERROR ran on to the end of the file, taking every <cffunction> after it with it. scan_tag_name now accepts . after the first character of a non-CF tag name, as XML does. CF tag names are unchanged.

    Scanner-only, so STATE_COUNT is unchanged. The corpus scan goes from 414 error lines in 81 files to 412 in 80: Mura's core/templates/web.config.template.cfm parses. docs/FAILING-PATTERNS.md had put that file down to generator placeholders. treediff shows no tree-shape change in any file that already parsed, and npm run fuzz passes. The issue's second case, SET #process the pairs# outside <cfoutput>, already parses cleanly on 0.26.42. Both cases are now probes.

Changelog

Sourced from tree-sitter-cfml's changelog.

[0.26.43]

cfml & cfquery

  • An HTML tag name can contain a dot (#169). <system.webServer>…</system.webServer>, the IIS web.config section often built in a <cfsavecontent>, read as the tag <system with an attribute .webServer. Its end tag then matched nothing, and the ERROR ran on to the end of the file, taking every <cffunction> after it with it. scan_tag_name now accepts . after the first character of a non-CF tag name, as XML does. CF tag names are unchanged.

    Scanner-only, so STATE_COUNT is unchanged. The corpus scan goes from 414 error lines in 81 files to 412 in 80: Mura's core/templates/web.config.template.cfm parses. docs/FAILING-PATTERNS.md had put that file down to generator placeholders. treediff shows no tree-shape change in any file that already parsed, and npm run fuzz passes. The issue's second case, SET #process the pairs# outside <cfoutput>, already parses cleanly on 0.26.42. Both cases are now probes.

Commits

Updates tree-sitter-swift from 0.7.3 to 0.7.4

Commits
  • 171fa3b 0.7.4 release
  • b42acc4 Updating top repository version
  • 5f435e2 Parse Swift 6 syntax: sending, isolated, copy, value generics, inline arrays,...
  • 35245fb fix: multi_agent.cwe-476 security vulnerability
  • 187fd4d Add strict memory safety syntax -- SE-0458
  • 4a0e502 Updating top repository version
  • 00bbb0a Fix npm publish never triggering after tag pushes
  • 048688b Include prebuilt .wasm in the npm package
  • f02fc0a Updating top repository version
  • 90b7a70 Fix attributes with an empty argument list
  • Additional commits viewable in compare view

Updates tokio from 1.53.1 to 1.53.2

Release notes

Sourced from tokio's releases.

Tokio v1.53.2

1.53.2 (October 3rd, 2026)

Fixed

  • fs: handle integer overflow in buffered relative seek (#8574)
  • io: revert "always cleanup AsyncFd registration list on deregister" (#8540)
  • process: unregister Windows wait before closing child handle (#8564)
  • rt: drop blocking pool mutex before shutting down rejected task (#8562)
  • sync: fix mpsc index wraparound in block reclamation (#8546)
  • sync: forget mpsc Permit before sending value (#8560)
  • sync: validate MAX_PERMITS in Semaphore::acquire (#8548)
  • sync: wake broadcast Sender::closed outside mutex (#8558)
  • task: drop replaced waker outside lock in JoinSet (#8554)
  • time: drop timer lock before dropping waker in clear_entry (#8552)
  • time: expire timers directly on shutdown without rotating wheel (#8570)

Fixed (unstable)

  • fs: clamp io_uring read length to u32::MAX (#8572)
  • rt: ignore current_thread task dumps from other runtimes (#8544)
  • rt: preserve io_uring context if a completion waker panics (#8566)
  • sync: fix semaphore use-after-free and permit leak on tracing panic (#8542)
  • taskdump: restore deferred leaf wakes during capture (#8445)
  • time: drop stored waker when cancelling alt timer entry (#8550)

#8445: tokio-rs/tokio#8445 #8572: tokio-rs/tokio#8572 #8540: tokio-rs/tokio#8540 #8542: tokio-rs/tokio#8542 #8544: tokio-rs/tokio#8544 #8546: tokio-rs/tokio#8546 #8548: tokio-rs/tokio#8548 #8550: tokio-rs/tokio#8550 #8552: tokio-rs/tokio#8552 #8554: tokio-rs/tokio#8554 #8558: tokio-rs/tokio#8558 #8560: tokio-rs/tokio#8560 #8562: tokio-rs/tokio#8562 #8564: tokio-rs/tokio#8564 #8566: tokio-rs/tokio#8566 #8570: tokio-rs/tokio#8570 #8574: tokio-rs/tokio#8574

Commits
  • ff0c406 chore: prepare Tokio v1.53.2 (#8580)
  • a762700 Merge 'tokio-1.51.5' into 'tokio-1.53.x' (#8577)
  • ec31a9f chore: prepare Tokio v1.51.5 (#8579)
  • 625c851 sync: assign semaphore permits before emitting tracing event (#8542)
  • 832dd23 sync: avoid leaking semaphore permits on tracing panic (#8542)
  • 826954a sync: unlink semaphore waiter before emitting tracing event (#8542)
  • 9a47992 process: unregister Windows wait before closing child handle (#8564)
  • 2fc5972 fs: handle integer overflow in buffered relative seek (#8574)
  • 85a6d13 io: revert "always cleanup AsyncFd registration list on deregister" (#8540)
  • 436faa2 rt: drop blocking pool mutex before shutting down rejected task (#8562)
  • Additional commits viewable in compare view

Updates reqwest from 0.13.4 to 0.13.5

Release notes

Sourced from reqwest's releases.

v0.13.5

tl;dr

  • Add Error::is_dns() to identify errors caused by DNS resolution failures.
  • Add ClientBuilder::http1_max_headers(usize) to configure the maximum number of headers accepted in an HTTP/1 response (default 100).
  • Add TLS version to TlsInfo extension.
  • Fix hickory-dns feature to use Ipv6AndIpv4 strategy to prefer IPv6.
  • Fix sending wrong proxy-auth if multiple proxies intercept a given URL.

What's Changed

New Contributors

Full Changelog: seanmonstar/reqwest@v0.13.4...v0.13.5

Changelog

Sourced from reqwest's changelog.

v0.13.5

  • Add Error::is_dns() to identify errors caused by DNS resolution failures.
  • Add ClientBuilder::http1_max_headers(usize) to configure the maximum number of headers accepted in an HTTP/1 response (default 100).
  • Add TLS version to TlsInfo extension.
  • Fix hickory-dns feature to use Ipv6AndIpv4 strategy to prefer IPv6.
  • Fix sending wrong proxy-auth if multiple proxies intercept a given URL.
Commits
  • de55373 v0.13.5
  • 4d3fe12 fix: proxy could use wrong credentials if many matched (#3098)
  • 9f06fd2 docs: improve description of JSON method (#3082)
  • 5bdb2f0 perf(cookie): avoid cloning store and url on Poll::Pending in ResponseFuture:...
  • ffda263 perf(body): reuse tokio::time::Sleep timer via reset() in ReadTimeoutBody (#3...
  • 4e9a3c7 chore: add pull request template for human-written content
  • 17e9bcb chore(deps): upgrade base64 to 0.23 (#3074)
  • 221abe9 chore: Remove unnecessary clones and a cast (#3071)
  • 99996a1 fix(error): detect timeouts wrapped in body decode errors (#3064)
  • fc99bd5 feat: expose the negotiated TLS version via TlsInfo (#3067)
  • Additional commits viewable in compare view

Updates tokio-stream from 0.1.18 to 0.1.19

Commits
  • bc0933c chore: prepare tokio-stream v0.1.19 (#8310)
  • e3786d0 readme: remove obsolete TokioConf notices (#8311)
  • f2189d3 chore: prepare tokio-util v0.7.19 (#8309)
  • 52f2745 net: re-enable tcp_stream::try_read_buf test for WASI (#8305)
  • ac6869a rt: remove unstable cfgs leftovers after local runtime stabilization (#8298)
  • 75fef53 chore: prepare Tokio v1.53.1 (#8303)
  • ae9d011 signal: restore MSRV by removing OnceLock::wait from the Windows handler (#8300)
  • eb4988d time: fix the loom test of the race between cancellation/insertion (#8302)
  • 91d3b4c time: fix alt timer cancellation and insertion race (#8252)
  • a463384 runtime: remove dead link definition in Runtime::block_on (#8301)
  • Additional commits viewable in compare view

Updates futures-util from 0.3.32 to 0.3.34

Release notes

Sourced from futures-util's releases.

0.3.34

  • Preserve cloned waker identity. (#3032)
  • Updato syn to 3. (#3028)

0.3.33

  • Fix ReadLine's soundness issue regarding to exception safety. (#3020)
  • Fix unsound Send impl for IterPinRef and Iter. (#3003)
  • Fix stacked borrows violation in compat01as03 implementation. (#3012)
  • Fix memory leak in FuturesUnordered::IntoIter. (#3005)
  • Add portable-atomic-alloc feature and use it in FuturesUnordered. (#3007)
  • Re-export alloc::task::Wake. (#3010)
  • Update spin to 0.12. (#3014)
Changelog

Sourced from futures-util's changelog.

0.3.34 - 2026-08-11

  • Preserve cloned waker identity. (#3032)
  • Updato syn to 3. (#3028)

0.3.33 - 2026-07-18

  • Fix ReadLine's soundness issue regarding to exception safety. (#3020)
  • Fix unsound Send impl for IterPinRef and Iter. (#3003)
  • Fix stacked borrows violation in compat01as03 implementation. (#3012)
  • Fix memory leak in FuturesUnordered::IntoIter. (#3005)
  • Add portable-atomic-alloc feature and use it in FuturesUnordered. (#3007)
  • Re-export alloc::task::Wake. (#3010)
  • Update spin to 0.12. (#3014)
Commits

Updates http-body-util from 0.1.3 to 0.1.5

Release notes

Sourced from http-body-util's releases.

http-body-util-v0.1.4

What's Changed

  • Add Fused body combinator that always returns None once completed.
  • Add BodyExt::into_stream() to convert a body into a Stream.
  • Add Full::into_inner() to get the full Buf.
  • Add InspectFrame and InspectErr combinators.
Commits

Updates libc from 0.2.189 to 0.2.190

Release notes

Sourced from libc's releases.

0.2.190

There is now a single config for enabling 64-bit time_t: libc_unstable_time64. This can be set unconditionally; it opts in to 64-bit time_t on the following platforms that use 32-bit by default:

  • 32-bit Linux-GNU
  • 32-bit Linux-uClibc
  • 32-bit Linux-musl. Note that setting this flag also enables some other changes that happend in musl v1.2.
  • 32-bit Windows-GNU
  • ESP-IDF (all targets with this environment are 32-bit)

Most other 32-bit platforms are either already using 64-bit time_t, or are considered legacy and will not be gaining support from their upstream maintainers.

You can enable this using RUSTFLAGS:

RUSTFLAGS='--cfg=libc_unstable_time64' cargo ...

Note that there may still be some changes to features gated by this config option, hence "unstable" in its name. In the near future we will rename it to just libc_time64. Until then, please test it out and report any bugs you find!

Support

  • Add initial support for HelenOS (#4355)

Added

We are slowly filling out the Default implementations, to reduce the need for mem::zeroed() in user code:

  • Unix: Implement Default for a number of structs, especially on Apple platforms (#5576)
  • Linux, NetBSD: Give statvfs a Default impl (#5583)
  • Linux: Add Default to a linux/can.rs structs (#5257)

Other additions:

  • Expose the libc_unstable_time64 cfg (#5411)
  • Android, Glibc: Add pthread_gettid_np (#5359)
  • Android: Add RTLD_NEXT (#5323)
  • Android: Add reuseport BPF socket options (#5366)
  • Apple: Add TCP header flags, options and SACK limits (#5358)
  • Apple: Add NET_RT_DUMP2 (#5442)
  • Apple: Add posix_spawn_file_actions_add(f)chdir(_np) (#5558)
  • BSD: Add BPF_WORDALIGN (#5320)
  • BSD: Add lchmod and lchflags where supported (#5400)
  • BSD: Add minherit and related constants (#4849)
  • Docs: Add more links to public headers and manual pages (#5407), (#5485)

... (truncated)

Changelog

Sourced from libc's changelog.

0.2.190 - 2026-10-02

There is now a single config for enabling 64-bit time_t: libc_unstable_time64. This can be set unconditionally; it opts in to 64-bit time_t on the following platforms that use 32-bit by default:

  • 32-bit Linux-GNU
  • 32-bit Linux-uClibc
  • 32-bit Linux-musl. Note that setting this flag also enables some other changes that happend in musl v1.2.
  • 32-bit Windows-GNU
  • ESP-IDF (all targets with this environment are 32-bit)

Most other 32-bit platforms are either already using 64-bit time_t, or are considered legacy and will not be gaining support from their upstream maintainers.

You can enable this using RUSTFLAGS:

RUSTFLAGS='--cfg=libc_unstable_time64' cargo ...

Note that there may still be some changes to features gated by this config option, hence "unstable" in its name. In the near future we will rename it to just libc_time64. Until then, please test it out and report any bugs you find!

Support

  • Add initial support for HelenOS (#4355)

Added

We are slowly filling out the Default implementations, to reduce the need for mem::zeroed() in user code:

  • Unix: Implement Default for a number of structs, especially on Apple platforms (#5576)
  • Linux, NetBSD: Give statvfs a Default impl (#5583)
  • Linux: Add Default to a linux/can.rs structs (#5257)

Other additions:

  • Expose the libc_unstable_time64 cfg (#5411)
  • Android, Glibc: Add pthread_gettid_np (#5359)
  • Android: Add RTLD_NEXT (#5323)
  • Android: Add reuseport BPF socket options (#5366)
  • Apple: Add TCP header flags, options and SACK limits (#5358)
  • Apple: Add NET_RT_DUMP2 (#5442)
  • Apple: Add posix_spawn_file_actions_add(f)chdir(_np) (#5558)
  • BSD: Add BPF_WORDALIGN (#5320)
  • BSD: Add lchmod and lchflags where supported (#5400)
  • BSD: Add minherit and related constants (#4849)

... (truncated)

Commits
  • 7b0ab55 ci: Rename publish_0.2.yml to release.yaml
  • ac85dde ci: Sync release permissions with main
  • 8f8cd20 libc: Release 0.2.190
  • 052c6e6 changelog: Fix an incorrect commit link
  • ea19fd7 test: Remove explicit libc version
  • 6dbf3a2 dragonfly: Move INHERIT_ZERO to the freebsd module
  • 8a64766 apple: add posix_spawn_file_actions_add(f)chdir(_np)
  • 28de514 linux, netbsd: Give statvfs a Default impl
  • a58a95f cygwin: Change POSIX_SPAWN_* flags to c_short
  • d175264 apple: timeval32 is exhaustive
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 7, 2026
@dependabot
dependabot Bot requested a review from sunerpy as a code owner October 7, 2026 21:47
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 7, 2026
@codecov

codecov Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

Impacted file tree graph

@@            Coverage Diff             @@
##             main     #320      +/-   ##
==========================================
- Coverage   95.06%   95.05%   -0.01%     
==========================================
  Files         198      198              
  Lines      109293   109293              
==========================================
- Hits       103894   103893       -1     
- Misses       5399     5400       +1     

see 1 file with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Bumps the cargo group with 10 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [thiserror](https://github.com/dtolnay/thiserror) | `2.0.18` | `2.0.21` |
| [rustix](https://github.com/bytecodealliance/rustix) | `1.1.4` | `1.1.5` |
| [tree-sitter-cfml](https://github.com/cfmleditor/tree-sitter-cfml) | `0.26.42` | `0.26.43` |
| [tree-sitter-swift](https://github.com/alex-pinkus/tree-sitter-swift) | `0.7.3` | `0.7.4` |
| [tokio](https://github.com/tokio-rs/tokio) | `1.53.1` | `1.53.2` |
| [reqwest](https://github.com/seanmonstar/reqwest) | `0.13.4` | `0.13.5` |
| [tokio-stream](https://github.com/tokio-rs/tokio) | `0.1.18` | `0.1.19` |
| [futures-util](https://github.com/rust-lang/futures-rs) | `0.3.32` | `0.3.34` |
| [http-body-util](https://github.com/hyperium/http-body) | `0.1.3` | `0.1.5` |
| [libc](https://github.com/rust-lang/libc) | `0.2.189` | `0.2.190` |



Updates `thiserror` from 2.0.18 to 2.0.21
- [Release notes](https://github.com/dtolnay/thiserror/releases)
- [Commits](dtolnay/thiserror@2.0.18...2.0.21)

Updates `rustix` from 1.1.4 to 1.1.5
- [Release notes](https://github.com/bytecodealliance/rustix/releases)
- [Changelog](https://github.com/bytecodealliance/rustix/blob/main/CHANGES.md)
- [Commits](bytecodealliance/rustix@v1.1.4...v1.1.5)

Updates `tree-sitter-cfml` from 0.26.42 to 0.26.43
- [Release notes](https://github.com/cfmleditor/tree-sitter-cfml/releases)
- [Changelog](https://github.com/cfmleditor/tree-sitter-cfml/blob/master/CHANGELOG.md)
- [Commits](cfmleditor/tree-sitter-cfml@v0.26.42...v0.26.43)

Updates `tree-sitter-swift` from 0.7.3 to 0.7.4
- [Release notes](https://github.com/alex-pinkus/tree-sitter-swift/releases)
- [Commits](alex-pinkus/tree-sitter-swift@0.7.3...0.7.4)

Updates `tokio` from 1.53.1 to 1.53.2
- [Release notes](https://github.com/tokio-rs/tokio/releases)
- [Commits](tokio-rs/tokio@tokio-1.53.1...tokio-1.53.2)

Updates `reqwest` from 0.13.4 to 0.13.5
- [Release notes](https://github.com/seanmonstar/reqwest/releases)
- [Changelog](https://github.com/seanmonstar/reqwest/blob/master/CHANGELOG.md)
- [Commits](seanmonstar/reqwest@v0.13.4...v0.13.5)

Updates `tokio-stream` from 0.1.18 to 0.1.19
- [Release notes](https://github.com/tokio-rs/tokio/releases)
- [Commits](tokio-rs/tokio@tokio-stream-0.1.18...tokio-stream-0.1.19)

Updates `futures-util` from 0.3.32 to 0.3.34
- [Release notes](https://github.com/rust-lang/futures-rs/releases)
- [Changelog](https://github.com/rust-lang/futures-rs/blob/main/CHANGELOG.md)
- [Commits](rust-lang/futures-rs@0.3.32...0.3.34)

Updates `http-body-util` from 0.1.3 to 0.1.5
- [Release notes](https://github.com/hyperium/http-body/releases)
- [Commits](hyperium/http-body@http-body-util-v0.1.3...http-body-util-v0.1.5)

Updates `libc` from 0.2.189 to 0.2.190
- [Release notes](https://github.com/rust-lang/libc/releases)
- [Changelog](https://github.com/rust-lang/libc/blob/0.2.190/CHANGELOG.md)
- [Commits](rust-lang/libc@0.2.189...0.2.190)

---
updated-dependencies:
- dependency-name: futures-util
  dependency-version: 0.3.34
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: http-body-util
  dependency-version: 0.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: libc
  dependency-version: 0.2.190
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: reqwest
  dependency-version: 0.13.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: rustix
  dependency-version: 1.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: thiserror
  dependency-version: 2.0.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: tokio
  dependency-version: 1.53.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: tokio-stream
  dependency-version: 0.1.19
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: tree-sitter-cfml
  dependency-version: 0.26.43
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: tree-sitter-swift
  dependency-version: 0.7.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps): bump the cargo group with 10 updates build(deps): bump the cargo group across 1 directory with 10 updates Oct 8, 2026
@dependabot
dependabot Bot force-pushed the dependabot/cargo/cargo-44a34dc580 branch from 51a4841 to 17ad277 Compare October 8, 2026 09:59

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants