Skip to content

Bump the cargo group with 9 updates - #55

Merged
zmofei merged 1 commit into
mainfrom
dependabot/cargo/cargo-d889a3508c
Sep 28, 2026
Merged

zmofei merged 1 commit into
mainfrom
dependabot/cargo/cargo-d889a3508c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the cargo group with 9 updates:

Package From To
rand 0.10.2 0.10.3
cc 1.4.6 1.4.7
encoding_rs 0.8.41 0.8.42
find-msvc-tools 0.1.12 0.1.14
hyper-rustls 0.27.9 0.27.10
hyper-util 0.1.20 0.1.21
libredox 0.1.24 0.1.25
smallvec 1.16.1 1.16.2
thiserror 2.0.20 2.0.21

Updates rand from 0.10.2 to 0.10.3

Changelog

Sourced from rand's changelog.

[0.10.3] — 2026-09-20

Fixes

  • Fix WeightedIndex panic when the sum of float weights is infinite; return Error::Overflow instead (#1808)
  • Fix spurious Error::NonFinite from Uniform::new_inclusive on large finite float ranges such as 0.0..=f64::MAX (#1821)
  • Fix possible panic due to sampling a deserialized Uniform<char> (#1831)

Changes

  • Report exact remaining lengths from WeightedIndex::weights() and reduce overhead when reading weights (#1838)

#1808: rust-random/rand#1808 #1821: rust-random/rand#1821 #1831: rust-random/rand#1831 #1838: rust-random/rand#1838

Commits
  • 9e7d328 Prepare rand 0.10.3 (#1840)
  • f73ce74 Optimize WeightedIndex weight lookup and iteration (#1838)
  • ef9e044 Avoid panic from deserialized Uniform\<char> where range == 0 (#1831)
  • c994eb1 docs: fix angle unit in quick start example (#1839)
  • 33dea4f Test that WeightedIndex rejects INFINITY with Error::Overflow (#1822)
  • 94c9078 Fix Uniform::new_inclusive overflow on large finite float ranges (#1821)
  • bb1262f Use Xoshiro256PlusPlus in examples/rayon-monte-carlo.rs (#1805)
  • 521fab6 Stop pinning dependencies (#1820)
  • 3f7c433 Stop pinning dependencies
  • cf4f73e sample_efraimidis_spirakis: error on more than amount non-finite weights (#1814)
  • Additional commits viewable in compare view

Updates cc from 1.4.6 to 1.4.7

Release notes

Sourced from cc's releases.

cc-v1.4.7

Fixed

  • strip OUT_DIR from the object file name hash too (#1902)
  • search_is_some clippy lint (#1903)

Other

  • Regenerate target info (#1924)
  • Regenerate windows sys bindings (#1919)
  • Fix target info parsing (#1911)
  • Add Z80 and SM83 target support (#1900)
Changelog

Sourced from cc's changelog.

1.4.7 - 2026-09-18

Fixed

  • strip OUT_DIR from the object file name hash too (#1902)
  • search_is_some clippy lint (#1903)

Other

  • Regenerate target info (#1924)
  • Regenerate windows sys bindings (#1919)
  • Fix target info parsing (#1911)
  • Add Z80 and SM83 target support (#1900)
Commits

Updates encoding_rs from 0.8.41 to 0.8.42

Commits
  • a155adc Increment version number to 0.8.42
  • 6603aed Attach the multiversion crate to the std feature instead
  • f718b07 docs: multiversion is compiled only with simd-accel
  • 4434afa chore: pull in multiversion only when it is actually used
  • 96138f6 Update main branch in URLs
  • See full diff in compare view

Updates find-msvc-tools from 0.1.12 to 0.1.14

Release notes

Sourced from find-msvc-tools's releases.

find-msvc-tools-v0.1.14

Fixed

  • Make windows_sys more private and re-export types needed by cc-rs (#1944)

find-msvc-tools-v0.1.13

Other

Commits
  • 6b0d8e6 chore: release (#1952)
  • b7d59a9 fix: don't report the file name cl.exe echoes as a warning in expand() (#1950)
  • fc01fd7 fix: ignore MSVC /link flags with a warning (#1949)
  • b81fc77 feat: inherit x86 target features from RUSTFLAGS (#1948)
  • 0da3fab ci: add additional targets for MSRV testing (#1945)
  • 0c74c6a ci(deps): bump release-plz/action from 0.5.137 to 0.5.138 (#1947)
  • e2bff2c docs: document macOS SDKROOT and Xcode CLT for testing (#1943)
  • fa75298 fix: Make windows_sys more private and re-export types needed by cc-rs (#1944)
  • 5b5d671 docs: remove License section from CONTRIBUTING.md (#1942)
  • 3651c0c docs: add CONTRIBUTING.md and Conventional Commit PR title check (#1938)
  • Additional commits viewable in compare view

Updates hyper-rustls from 0.27.9 to 0.27.10

Release notes

Sourced from hyper-rustls's releases.

0.27.10

Maintenance release, principally fixing #344

What's Changed

Full Changelog: rustls/hyper-rustls@v/0.27.9...v/0.27.10

Commits
  • ce45b6b Bump rustls from 0.23.44 to 0.23.45
  • a3a1838 Bump rustls from 0.23.43 to 0.23.44
  • 6e1d602 Bump tokio-rustls from 0.26.4 to 0.26.5
  • 96e3b92 Bump hyper from 1.11.0 to 1.11.1
  • 3989e37 Bump log from 0.4.33 to 0.4.34
  • eed79ba Bump http-body-util from 0.1.4 to 0.1.5
  • fadbc9e Bump http from 1.4.2 to 1.5.0
  • 9519052 Bump rustls from 0.23.42 to 0.23.43
  • a2f1a60 Bump webpki-roots from 1.0.8 to 1.0.9
  • acce69f Bump tokio from 1.53.0 to 1.53.1
  • Additional commits viewable in compare view

Updates hyper-util from 0.1.20 to 0.1.21

Release notes

Sourced from hyper-util's releases.

v0.1.21

Additions

  • Add crate-level documentation. (#327)
  • Add client::legacy::Builder::http2_header_table_size() method. (#274)
  • Add client::legacy::Builder::http2_max_concurrent_streams() method. (#274)
  • Add client::legacy::Builder::http2_max_local_error_reset_streams() method. (#277)
  • Add client::legacy::connect::HttpConnector::set_mark() method. (#303)
  • Add rt::tracing::WithSpanExecutor<E>, hyper_util::rt::tracing::CurrentSpanExecutor<E>, and hyper_util::rt::tracing::MkSpanExecutor<E, F> executors. (#323)

Fixes

  • Fix client::legacy::Client so that it properly validates CONNECT responses. (#315)
  • Fix client::legacy::Client to cancel the idle interval once its pool empties. (#292)
  • Fix client::legacy::Client to properly handle IPv6 addresses when using a SOCKS proxy. (#302)
  • Fix client::pool::cache to preserve readiness with clones. (#297)
  • Fix client::pool::cache to wake its waiters in FIFO order. (#298)
  • Fix client::pool::singleton::Singleton to properly handle cancellation. (#299)
  • Fix client::pool::singleton::Singleton to share errors with all waiters. (#296)
  • Fix client::proxy::matcher handling for IP wildcards. (#309)
  • The tokio/net feature is narrowed to the client-legacy feature flag, from the client feature flag. (#276)
  • Various fixes to the client::legacy::Client's SOCKS proxying. (#302) (#307) (#308) (#310)

Changes

This release contains a minor behavioral change for users of the tracing feature flag to be aware of.

This feature flag was introduced in v0.1.11. When enabled, rt::TokioExecutor<E> began propagating the currently active tracing::Span to spawned tasks when hyper::rt::Executor::execute() is called. This caused issues for some users, due to background tasks keeping a span open for the duration of a long-lived connection.

This behavior has now been removed from rt::TokioExecutor<E> (#322) by default. A collection of executor wrappers have been added to a new rt::tracing submodule, to provide facilities for instrumenting a client or server's spawned tasks. See the module-level documentation of rt::tracing for more information.

To temporarily preserve the previous rt::TokioExecutor<E> span propagation behavior, enable the rt-tracing-exec-force feature. Note that this feature flag will be removed in a future release.

This release bumps the minimal supported Rust version (MSRV) from 1.64 to 1.85.

This release bumps the rust edition from 2021 to 2024.

... (truncated)

Changelog

Sourced from hyper-util's changelog.

0.1.21 (2026-09-24)

This release bumps the minimal supported Rust version (MSRV) from 1.64 to 1.85.

This release bumps the rust edition from 2021 to 2024.

Additions

  • Add crate-level documentation. (#327)
  • Add client::legacy::Builder::http2_header_table_size() method. (#274)
  • Add client::legacy::Builder::http2_max_concurrent_streams() method. (#274)
  • Add client::legacy::Builder::http2_max_local_error_reset_streams() method. (#277)
  • Add client::legacy::connect::HttpConnector::set_mark() method. (#303)
  • Add rt::tracing::WithSpanExecutor<E>, hyper_util::rt::tracing::CurrentSpanExecutor<E>, and hyper_util::rt::tracing::MkSpanExecutor<E, F> executors. (#323)

Fixes

  • Fix client::legacy::Client so that it properly validates CONNECT responses. (#315)
  • Fix client::legacy::Client to cancel the idle interval once its pool empties. (#292)
  • Fix client::legacy::Client to properly handle IPv6 addresses when using a SOCKS proxy. (#302)
  • Fix client::pool::cache to preserve readiness with clones. (#297)
  • Fix client::pool::cache to wake its waiters in FIFO order. (#298)
  • Fix client::pool::singleton::Singleton to properly handle cancellation. (#299)
  • Fix client::pool::singleton::Singleton to share errors with all waiters. (#296)
  • Fix client::proxy::matcher handling for IP wildcards. (#309)
  • The tokio/net feature is narrowed to the client-legacy feature flag, from the client feature flag. (#276)
  • Various fixes to the client::legacy::Client's SOCKS proxying. (#302) (#307) (#308) (#310)

Changes

This release contains a minor behavioral change for users of the tracing feature flag to be aware of.

This feature flag was introduced in v0.1.11. When enabled, rt::TokioExecutor<E> began propagating the currently active tracing::Span to spawned tasks when hyper::rt::Executor::execute() is called. This caused issues for some users, due to background tasks keeping a span open for the duration of a long-lived connection.

This behavior has now been removed from rt::TokioExecutor<E> (#322) by default. A collection of executor wrappers have been added to a new rt::tracing submodule, to provide facilities for instrumenting a client or server's spawned tasks. See the module-level documentation of rt::tracing for more information.

To temporarily preserve the previous rt::TokioExecutor<E> span propagation behavior, enable the rt-tracing-exec-force feature. Note that this feature flag will be removed in a future release.

Commits
  • 23a8689 v0.1.21
  • cdb2346 doc(client/pool): add broken_intra_doc_links allowance (#326)
  • 13b6110 chore(error): remove disabled hyper_util::error submodule (#325)
  • b9ee451 docs(lib): add crate-level documentation (#327)
  • d6b7d7e feat(rt/tracing): introduce tracing executors (#323)
  • f2da915 feat(client): add HttpConnector::set_mark for SO_MARK (#303)
  • 4dbd494 feat(rt): change TokioExecutor to not trace, add rt-tracing-exec-force feat...
  • d480d9f fix(client): parse proxy CONNECT response with httparse (#315)
  • 7e0958b chore(ci): simplify msrv check (#317)
  • 0734568 chore(ci): update to actions/checkout@v7 (#316)
  • Additional commits viewable in compare view

Updates libredox from 0.1.24 to 0.1.25

Updates smallvec from 1.16.1 to 1.16.2

Release notes

Sourced from smallvec's releases.

v1.16.2

What's Changed

New Contributors

Full Changelog: servo/rust-smallvec@v1.16.1...v1.16.2

Commits
  • ccf5fc7 chore: bump version (#617)
  • af207cc Merge pull request #608 from Rayan-and-beyond/fix/manual-readme-warning-606
  • cda4b73 Merge pull request #594 from astral-sh/charlie/codex-fix-may-dangle
  • d0556cb Merge pull request #596 from astral-sh/charlie/codex-v1-compact
  • f73914c Flatten retain tests into the unit test module
  • 954d599 Move retain tests into the unit test module
  • 8d93633 Remove added retain benchmark harness
  • 88c6bfa Limit compaction optimization to retain
  • b9ef17d Fix element ownership tracking with may_dangle
  • 42029c2 Compact retained elements directly in retain and dedup_by
  • See full diff in compare view

Updates thiserror from 2.0.20 to 2.0.21

Release notes

Sourced from thiserror's releases.

2.0.21

  • Fix parsing of generic unit variants in display expressions (#459)
Commits
  • b1827ee Release 2.0.21
  • 58037b5 Merge pull request #459 from dtolnay/turbofish
  • f82a0cf Keep track of nested turbofish depth
  • 72ea492 Raise required compiler to Rust 1.77
  • 72eea0d Resolve io_other_error clippy lint in tests
  • 07f09a2 Raise required compiler to Rust 1.74
  • 2715388 Update ui test suite to nightly-2026-09-22
  • 5a306c7 Update ui test suite to nightly-2026-09-05
  • ef9383b Update ui test suite to nightly-2026-08-22
  • 8336b84 Update ui tests for version 2.0.20
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the cargo group with 9 updates:

| Package | From | To |
| --- | --- | --- |
| [rand](https://github.com/rust-random/rand) | `0.10.2` | `0.10.3` |
| [cc](https://github.com/rust-lang/cc-rs) | `1.4.6` | `1.4.7` |
| [encoding_rs](https://github.com/hsivonen/encoding_rs) | `0.8.41` | `0.8.42` |
| [find-msvc-tools](https://github.com/rust-lang/cc-rs) | `0.1.12` | `0.1.14` |
| [hyper-rustls](https://github.com/rustls/hyper-rustls) | `0.27.9` | `0.27.10` |
| [hyper-util](https://github.com/hyperium/hyper-util) | `0.1.20` | `0.1.21` |
| libredox | `0.1.24` | `0.1.25` |
| [smallvec](https://github.com/servo/rust-smallvec) | `1.16.1` | `1.16.2` |
| [thiserror](https://github.com/dtolnay/thiserror) | `2.0.20` | `2.0.21` |


Updates `rand` from 0.10.2 to 0.10.3
- [Release notes](https://github.com/rust-random/rand/releases)
- [Changelog](https://github.com/rust-random/rand/blob/master/CHANGELOG.md)
- [Commits](rust-random/rand@0.10.2...0.10.3)

Updates `cc` from 1.4.6 to 1.4.7
- [Release notes](https://github.com/rust-lang/cc-rs/releases)
- [Changelog](https://github.com/rust-lang/cc-rs/blob/main/CHANGELOG.md)
- [Commits](rust-lang/cc-rs@cc-v1.4.6...cc-v1.4.7)

Updates `encoding_rs` from 0.8.41 to 0.8.42
- [Commits](hsivonen/encoding_rs@v0.8.41...v0.8.42)

Updates `find-msvc-tools` from 0.1.12 to 0.1.14
- [Release notes](https://github.com/rust-lang/cc-rs/releases)
- [Changelog](https://github.com/rust-lang/cc-rs/blob/main/CHANGELOG.md)
- [Commits](rust-lang/cc-rs@find-msvc-tools-v0.1.12...find-msvc-tools-v0.1.14)

Updates `hyper-rustls` from 0.27.9 to 0.27.10
- [Release notes](https://github.com/rustls/hyper-rustls/releases)
- [Commits](rustls/hyper-rustls@v/0.27.9...v/0.27.10)

Updates `hyper-util` from 0.1.20 to 0.1.21
- [Release notes](https://github.com/hyperium/hyper-util/releases)
- [Changelog](https://github.com/hyperium/hyper-util/blob/master/CHANGELOG.md)
- [Commits](hyperium/hyper-util@v0.1.20...v0.1.21)

Updates `libredox` from 0.1.24 to 0.1.25

Updates `smallvec` from 1.16.1 to 1.16.2
- [Release notes](https://github.com/servo/rust-smallvec/releases)
- [Commits](servo/rust-smallvec@v1.16.1...v1.16.2)

Updates `thiserror` from 2.0.20 to 2.0.21
- [Release notes](https://github.com/dtolnay/thiserror/releases)
- [Commits](dtolnay/thiserror@2.0.20...2.0.21)

---
updated-dependencies:
- dependency-name: rand
  dependency-version: 0.10.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: cc
  dependency-version: 1.4.7
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: encoding_rs
  dependency-version: 0.8.42
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: find-msvc-tools
  dependency-version: 0.1.14
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: hyper-rustls
  dependency-version: 0.27.10
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: hyper-util
  dependency-version: 0.1.21
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: libredox
  dependency-version: 0.1.25
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: smallvec
  dependency-version: 1.16.2
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: thiserror
  dependency-version: 2.0.21
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: cargo
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 28, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 28, 2026 08:17
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 28, 2026
@zmofei
zmofei merged commit f1d7092 into main Sep 28, 2026
8 checks passed
@dependabot
dependabot Bot deleted the dependabot/cargo/cargo-d889a3508c branch September 28, 2026 08:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant