Skip to content

chore(deps): bump the cargo-dependencies group across 1 directory with 7 updates - #96

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-dependencies-609038ce8b
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-dependencies-609038ce8b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the cargo-dependencies group with 7 updates in the / directory:

Package From To
tower-http 0.7.0 0.7.1
redb 4.1.0 4.3.0
clap 4.6.6 4.6.7
clap_complete 4.6.9 4.6.11
interprocess 2.4.3 2.4.4
toml 1.1.4+spec-1.1.0 1.1.6+spec-1.1.0
reqwest 0.13.4 0.13.5

Updates tower-http from 0.7.0 to 0.7.1

Release notes

Sourced from tower-http's releases.

tower-http-0.7.1

Added

  • fs: add ServeDir::redirect_to_trailing_slash() to serve directory indexes directly instead of first redirecting to the trailing-slash path. The redirect remains the default (#728)
  • fs: add ignore_multi_range_requests() to ServeDir and ServeFile, serving the full representation when a request asks for multiple byte ranges. The existing 416 Range Not Satisfiable response remains the default (#727)
  • request-id: the constructors and accessors on the request-id layers, services, and RequestId are now const fn, so they can be used in const context (#716)

Changed

  • fs: the minimum http-range-header requirement is now 0.4.2 (#661)

Fixed

  • behavioral change: fs: make ServeDir::try_call propagate expected filesystem I/O errors when no fallback is configured, as documented, instead of converting them to 404 Not Found responses (#718)
  • decompression: don't end the body when a data frame with no remaining bytes arrives after the decompressor reports end-of-stream. Trailers following such a frame were dropped and could not be recovered (#722)
  • decompression: return a body error when a data frame with remaining bytes arrives after the decompressor reports end-of-stream, rather than silently truncating. This regressed in 0.7.0 (#712)
  • fs: multipart range requests are now rejected before range validation, so they consistently return 416 Range Not Satisfiable with a Cannot serve multipart range requests body instead of a generic unsatisfiable-range response (#661)
  • fs: range error responses no longer carry representation headers such as Content-Type and Content-Encoding (#727)
  • set-header: SetMultipleResponseHeadersLayer and SetMultipleResponseHeader are now Clone regardless of the response body type, matching the fix applied to the request-side types in 0.7.0 (#714)

#661: tower-rs/tower-http#661 #712: tower-rs/tower-http#712 #714: tower-rs/tower-http#714 #716: tower-rs/tower-http#716 #718: tower-rs/tower-http#718 #722: tower-rs/tower-http#722 #727: tower-rs/tower-http#727 #728: tower-rs/tower-http#728

All the changes

... (truncated)

Commits
  • c941451 chore(release): prepare 0.7.1 (#729)
  • 9697702 chore(deps): bump taiki-e/install-action from 2.86.3 to 2.86.8 (#730)
  • e2582e2 Allow ignoring multi-range requests (#727)
  • 888f7fe feat(services): configure directory redirects (#728)
  • 5ad7654 chore(deps): bump taiki-e/install-action from 2.85.12 to 2.86.3 (#726)
  • d154adb fix: reject multipart ranges before validation (#661)
  • d9e5c8a ci: Update to cargo-check-external-types 0.5.0 (#724)
  • 90c072b Propagate ServeDir::try_call I/O errors (#718)
  • 860922e fix(decompression): don't end the body on an empty data frame (#722)
  • 8532252 docs(example)/custom future with multiple bodies (#711)
  • Additional commits viewable in compare view

Updates redb from 4.1.0 to 4.3.0

Release notes

Sourced from redb's releases.

4.3.0

New features

  • Add optional locking methods to StorageBackend. Backends may implement these methods to support locking. Custom backends that wrap FileBackend should delegate these methods to the FileBackend otherwise file locking functionality will be lost.
  • Add an optional Key::separator(), which returns a short byte string that separates two keys. &[u8], &str, String keys now store minimal prefixes. Option, array keys, and tuple keys also store optimized separators when their element type is variable length. Tables with these key types will use slightly less space, and lookups will be faster.
  • Add Key::min_encoded_key(), the encoding of a key type's smallest value. Implementing it is optional, and lets container types holding that key store shorter separators.
  • Add experimental support for multi-process read-write access to a single database file, behind the experimental-multiprocess feature flag.

Bug fixes

  • Fix a crash shortly after a commit being able to silently roll that commit back during recovery, if check_integrity() had previously repaired the database.
  • Fix ReadOnlyUntypedTable and ReadOnlyUntypedMultimapTable potentially returning incorrect results if the originating transaction is dropped.
  • Fix iterators silently omitting data when iteration continues after an error. An iterator that yielded Err(Corrupted) could yield the rest of the table on later calls, skipping the unreadable entries with no further error. Iterators and read-only cursors now keep returning an error after the first one; re-seeking a cursor resets it.
  • Fix restore_savepoint(), rename_table(), and delete_table() leaving the transaction committable after a storage error. Committing it could corrupt the database or silently lose a table. Such failures now poison the transaction: commit() returns an error instead of committing the half-applied state.
  • Fix pages being leaked permanently when a panic unwound through a live write transaction and was caught with catch_unwind. The leak survived closing and reopening the database and grew with every such panic; the pages are now reclaimed the next time the database is opened.
  • Fix a Windows-only hang: a write to the database file that reported writing zero bytes made the commit retry it forever. It now fails with a WriteZero I/O error.
  • Fix rename_table() and rename_multimap_table() returning TableExists when the new name is the same as the current one. Renaming a table to its own name now succeeds and leaves the table unchanged.
  • Fix persistent_savepoint() and delete_persistent_savepoint() making the transaction ineligible for further savepoints, so a second savepoint in the same transaction failed with InvalidSavepoint. Only opening, renaming, or deleting a data table, or restoring a savepoint, makes a transaction savepoint-ineligible now.

4.2.0

New features

  • Add an experimental cursor API, behind the experimental_cursor feature flag: Table::lower_bound_mut() and Table::upper_bound_mut() return a CursorMut pointing at a gap between entries, modeled on the standard library's BTreeMap cursors. Inserting sorted data through its insert_before() method can be around 3x faster than calling insert() with the same data; insert_after() inserts through the gap in descending order at the same speed. ReadableTable::lower_bound() and ReadableTable::upper_bound() return a read-only Cursor. The feature is unstable and may change incompatibly, or be removed, in any release.
  • Add ReadOnlyTable::get_owned(), ReadOnlyTable::range_owned(),

... (truncated)

Changelog

Sourced from redb's changelog.

4.3.0 - 2026-09-14

New features

  • Add optional locking methods to StorageBackend. Backends may implement these methods to support locking. Custom backends that wrap FileBackend should delegate these methods to the FileBackend otherwise file locking functionality will be lost.
  • Add an optional Key::separator(), which returns a short byte string that separates two keys. &[u8], &str, String keys now store minimal prefixes. Option, array keys, and tuple keys also store optimized separators when their element type is variable length. Tables with these key types will use slightly less space, and lookups will be faster.
  • Add Key::min_encoded_key(), the encoding of a key type's smallest value. Implementing it is optional, and lets container types holding that key store shorter separators.
  • Add experimental support for multi-process read-write access to a single database file, behind the experimental-multiprocess feature flag.

Bug fixes

  • Fix a crash shortly after a commit being able to silently roll that commit back during recovery, if check_integrity() had previously repaired the database.
  • Fix ReadOnlyUntypedTable and ReadOnlyUntypedMultimapTable potentially returning incorrect results if the originating transaction is dropped.
  • Fix iterators silently omitting data when iteration continues after an error. An iterator that yielded Err(Corrupted) could yield the rest of the table on later calls, skipping the unreadable entries with no further error. Iterators and read-only cursors now keep returning an error after the first one; re-seeking a cursor resets it.
  • Fix restore_savepoint(), rename_table(), and delete_table() leaving the transaction committable after a storage error. Committing it could corrupt the database or silently lose a table. Such failures now poison the transaction: commit() returns an error instead of committing the half-applied state.
  • Fix pages being leaked permanently when a panic unwound through a live write transaction and was caught with catch_unwind. The leak survived closing and reopening the database and grew with every such panic; the pages are now reclaimed the next time the database is opened.
  • Fix a Windows-only hang: a write to the database file that reported writing zero bytes made the commit retry it forever. It now fails with a WriteZero I/O error.
  • Fix rename_table() and rename_multimap_table() returning TableExists when the new name is the same as the current one. Renaming a table to its own name now succeeds and leaves the table unchanged.
  • Fix persistent_savepoint() and delete_persistent_savepoint() making the transaction ineligible for further savepoints, so a second savepoint in the same transaction failed with InvalidSavepoint. Only opening, renaming, or deleting a data table, or restoring a savepoint, makes a transaction savepoint-ineligible now.

4.2.0 - 2026-08-17

New features

  • Add an experimental cursor API, behind the experimental_cursor feature flag: Table::lower_bound_mut() and Table::upper_bound_mut() return a CursorMut pointing at a gap between entries, modeled on the standard library's BTreeMap cursors. Inserting sorted data through its insert_before() method can be around 3x faster than calling insert() with the same data; insert_after() inserts through the gap in descending order at the same speed. ReadableTable::lower_bound() and ReadableTable::upper_bound() return a read-only Cursor. The feature is unstable and may change incompatibly, or be removed, in any release.

... (truncated)

Commits
  • 2de02fa Bump version to 4.3.0
  • 7644dd8 Update changelog
  • 13011e5 Gate multiprocess error variants behind their feature
  • 8f08680 Update changelog
  • cfaa852 Keep local multi-writer commits in the read cache
  • ecec3ba Update changelog
  • ae626c6 Fix table formating in design doc
  • 38624a7 Rename the concurrency modes
  • e4993eb Update AGENTS.md
  • 2846ab7 Keep aborted savepoint handles invalid across writer processes
  • Additional commits viewable in compare view

Updates clap from 4.6.6 to 4.6.7

Release notes

Sourced from clap's releases.

v4.6.7

[4.6.7] - 2026-09-14

Features

  • (derive) Add #[command(defer = <bool>)] attribute to opt-in to lazy initialisation of subcommands
Changelog

Sourced from clap's changelog.

[4.6.7] - 2026-09-14

Features

  • (derive) Add #[command(defer = <bool>)] attribute to opt-in to lazy initialisation of subcommands
Commits
  • d3e59a9 chore: Release
  • d997f87 docs: Update changelog
  • fb6058c Merge pull request #6409 from heaths/pwsh-support
  • 2310870 test(complete): Add tests for completer_for_path
  • 5967c17 refactor(complete): Move shell detection to Shells
  • 594602b fix(complete): Detect pwsh for PowerShell
  • 3a4f2d0 Merge pull request #6427 from clap-rs/renovate/shlex-2.x
  • 67ebaed Merge pull request #6426 from clap-rs/renovate/actions-checkout-7.x
  • c968b13 chore(deps): Update Rust crate shlex to v2
  • 8f247cb chore(deps): Update actions/checkout action to v7
  • Additional commits viewable in compare view

Updates clap_complete from 4.6.9 to 4.6.11

Commits
  • 2cb76fd chore: Release
  • 0b00b8d docs: Update changelog
  • 3443000 Merge pull request #6526 from bonnefoa/fix-completion-escape
  • a1b6be7 fix(clap_complete): Fix value escape in zsh completion
  • face9e8 test(complete): Add completion test without arg's help
  • 88053ab test(complete): Re-enable complete tests
  • e6adcc2 chore(release): Simplify replacements
  • 13f2db5 chore: Release
  • 3304fea docs: Update changelog
  • 7b2ad34 Merge pull request #6521 from r-near/feat/derive-deferred-initialization
  • Additional commits viewable in compare view

Updates interprocess from 2.4.3 to 2.4.4

Release notes

Sourced from interprocess's releases.

2.4.4

  • Fixed a dead link in the readme and a typo in the docs.
  • checks-and-tests.py is no longer packaged by Cargo to avoid tricking distro package managers into thinking Interprocess requires Python (#98).
Commits

Updates toml from 1.1.4+spec-1.1.0 to 1.1.6+spec-1.1.0

Commits
  • 572c005 chore: Release
  • 66d0c53 docs: Update changelog
  • 07af4e7 perf: Reduce allocations in toml_edit parsing and dumping (#1215)
  • 0ff90db perf(display): Write encoded strings directly
  • efb2536 perf(display): Move generated representation strings
  • 075c444 refactor(display): Consolidate key-path encoding
  • b48f338 perf(display): Borrow table keys during document output
  • c6c1de3 perf(parser): Move completed table header keys
  • ec90463 perf(parser): Borrow input when creating editable documents
  • d76a48a test: Benchmark rendering generated keys and values
  • Additional commits viewable in compare view

Updates reqwest from 0.13.4 to 0.13.5

Release notes

Sourced from reqwest's releases.

v0.13.5

tl;dr

  • Add Error::is_dns() to identify errors caused by DNS resolution failures.
  • Add ClientBuilder::http1_max_headers(usize) to configure the maximum number of headers accepted in an HTTP/1 response (default 100).
  • Add TLS version to TlsInfo extension.
  • Fix hickory-dns feature to use Ipv6AndIpv4 strategy to prefer IPv6.
  • Fix sending wrong proxy-auth if multiple proxies intercept a given URL.

What's Changed

New Contributors

Full Changelog: seanmonstar/reqwest@v0.13.4...v0.13.5

Changelog

Sourced from reqwest's changelog.

v0.13.5

  • Add Error::is_dns() to identify errors caused by DNS resolution failures.
  • Add ClientBuilder::http1_max_headers(usize) to configure the maximum number of headers accepted in an HTTP/1 response (default 100).
  • Add TLS version to TlsInfo extension.
  • Fix hickory-dns feature to use Ipv6AndIpv4 strategy to prefer IPv6.
  • Fix sending wrong proxy-auth if multiple proxies intercept a given URL.
Commits
  • de55373 v0.13.5
  • 4d3fe12 fix: proxy could use wrong credentials if many matched (#3098)
  • 9f06fd2 docs: improve description of JSON method (#3082)
  • 5bdb2f0 perf(cookie): avoid cloning store and url on Poll::Pending in ResponseFuture:...
  • ffda263 perf(body): reuse tokio::time::Sleep timer via reset() in ReadTimeoutBody (#3...
  • 4e9a3c7 chore: add pull request template for human-written content
  • 17e9bcb chore(deps): upgrade base64 to 0.23 (#3074)
  • 221abe9 chore: Remove unnecessary clones and a cast (#3071)
  • 99996a1 fix(error): detect timeouts wrapped in body decode errors (#3064)
  • fc99bd5 feat: expose the negotiated TLS version via TlsInfo (#3067)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…h 7 updates

Bumps the cargo-dependencies group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [tower-http](https://github.com/tower-rs/tower-http) | `0.7.0` | `0.7.1` |
| [redb](https://github.com/cberner/redb) | `4.1.0` | `4.3.0` |
| [clap](https://github.com/clap-rs/clap) | `4.6.6` | `4.6.7` |
| [clap_complete](https://github.com/clap-rs/clap) | `4.6.9` | `4.6.11` |
| [interprocess](https://github.com/kotauskas/interprocess) | `2.4.3` | `2.4.4` |
| [toml](https://github.com/toml-rs/toml) | `1.1.4+spec-1.1.0` | `1.1.6+spec-1.1.0` |
| [reqwest](https://github.com/seanmonstar/reqwest) | `0.13.4` | `0.13.5` |



Updates `tower-http` from 0.7.0 to 0.7.1
- [Release notes](https://github.com/tower-rs/tower-http/releases)
- [Commits](tower-rs/tower-http@tower-http-0.7.0...tower-http-0.7.1)

Updates `redb` from 4.1.0 to 4.3.0
- [Release notes](https://github.com/cberner/redb/releases)
- [Changelog](https://github.com/cberner/redb/blob/master/CHANGELOG.md)
- [Commits](cberner/redb@v4.1.0...v4.3.0)

Updates `clap` from 4.6.6 to 4.6.7
- [Release notes](https://github.com/clap-rs/clap/releases)
- [Changelog](https://github.com/clap-rs/clap/blob/main/CHANGELOG.md)
- [Commits](clap-rs/clap@clap_complete-v4.6.6...clap_complete-v4.6.7)

Updates `clap_complete` from 4.6.9 to 4.6.11
- [Release notes](https://github.com/clap-rs/clap/releases)
- [Changelog](https://github.com/clap-rs/clap/blob/main/CHANGELOG.md)
- [Commits](clap-rs/clap@clap_complete-v4.6.9...clap_complete-v4.6.11)

Updates `interprocess` from 2.4.3 to 2.4.4
- [Release notes](https://github.com/kotauskas/interprocess/releases)
- [Commits](kotauskas/interprocess@2.4.3...2.4.4)

Updates `toml` from 1.1.4+spec-1.1.0 to 1.1.6+spec-1.1.0
- [Commits](toml-rs/toml@toml-v1.1.4...toml-v1.1.6)

Updates `reqwest` from 0.13.4 to 0.13.5
- [Release notes](https://github.com/seanmonstar/reqwest/releases)
- [Changelog](https://github.com/seanmonstar/reqwest/blob/master/CHANGELOG.md)
- [Commits](seanmonstar/reqwest@v0.13.4...v0.13.5)

---
updated-dependencies:
- dependency-name: tower-http
  dependency-version: 0.7.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-dependencies
- dependency-name: redb
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-dependencies
- dependency-name: clap
  dependency-version: 4.6.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-dependencies
- dependency-name: clap_complete
  dependency-version: 4.6.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-dependencies
- dependency-name: interprocess
  dependency-version: 2.4.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-dependencies
- dependency-name: toml
  dependency-version: 1.1.6+spec-1.1.0
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-dependencies
- dependency-name: reqwest
  dependency-version: 0.13.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 1, 2026
@socket-security

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants