Skip to content

chore(deps): bump the cargo group with 11 updates - #30

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/cargo/cargo-52528caf01
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/cargo/cargo-52528caf01

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Bumps the cargo group with 11 updates:

Package From To
async-compression 0.4.48 0.4.50
brotli 8.0.4 9.0.0
brotli-decompressor 5.0.3 6.0.1
cc 1.5.1 1.6.0
compression-codecs 0.4.43 0.4.45
libc 0.2.189 0.2.190
mio 1.2.3 1.2.4
quinn-proto 0.11.18 0.11.19
tokio 1.53.1 1.53.2
tokio-rustls 0.26.5 0.26.6
yoke-derive 0.8.3 0.8.4

Updates async-compression from 0.4.48 to 0.4.50

Release notes

Sourced from async-compression's releases.

async-compression-v0.4.50

Other

  • (deps) update brotli requirement from 8 to 9 (#499)

async-compression-v0.4.49

Added

  • (brotli) add optional mbrotli backend (#492)
Commits

Updates brotli from 8.0.4 to 9.0.0

Commits
  • a51b65e 9.0.0 release
  • fb3104d Add non-default portable-float feature for target-independent encoder output
  • c9af3de Fix #257
  • 93ea851 fix: handle short empty streams in BroCatli
  • 5bf2ed8 fixed simd (.to_int() renamed to .to_simd())
  • ac02943 Revert "fixed simd (.to_int() renamed to .to_simd())"
  • b4ed6ac fixed simd (.to_int() renamed to .to_simd())
  • 3e7adf2 fixed simd (mask.to_int() renamed to mask.to_simd())
  • See full diff in compare view

Updates brotli-decompressor from 5.0.3 to 6.0.1

Commits
  • e4f3bf3 Release 6.0.1
  • 99c8ac3 Update README.md
  • f955674 Fix comment
  • 2de82ce Drop partially initialized fallback allocations on panic
  • 48e9ba0 Handle allocation failure in the FFI default allocator
  • f93cd44 Remove UB
  • 731d7d5 Give the C test harness its own package name
  • 6f0f88b Use aligned dangling pointers for empty no-std blocks
  • 6a26082 Harden output and parameter handling in the C API
  • c31d20b Validate the complete input cursor range
  • Additional commits viewable in compare view

Updates cc from 1.5.1 to 1.6.0

Release notes

Sourced from cc's releases.

cc-v1.6.0

Added

  • add Build::create_archive and emit_link_directives (#1972)
  • read the process environment once per Build, on first use (#1969)
  • add Build::message_logger for structured access to cc's messages (#1967)
  • add CXXSTDLIB_STATIC to link the C++ stdlib statically from outside (#1957)

Fixed

  • key the flag support cache on target, host, language and environment (#1965)
  • forward each line of compiler stderr once and whole with parallel (#1959)

Other

  • find compile commands by source file so tests pass with parallel (#1973)
  • add support for armeb-unknown-linux-gnueabi (#1958)
Changelog

Sourced from cc's changelog.

1.6.0 - 2026-10-03

Added

  • add Build::create_archive and emit_link_directives (#1972)
  • read the process environment once per Build, on first use (#1969)
  • add Build::message_logger for structured access to cc's messages (#1967)
  • add CXXSTDLIB_STATIC to link the C++ stdlib statically from outside (#1957)

Fixed

  • key the flag support cache on target, host, language and environment (#1965)
  • forward each line of compiler stderr once and whole with parallel (#1959)

Other

  • find compile commands by source file so tests pass with parallel (#1973)
  • add support for armeb-unknown-linux-gnueabi (#1958)
Commits
  • 25fa77c chore(cc): release v1.6.0 (#1971)
  • 53598f7 feat: add Build::create_archive and emit_link_directives (#1972)
  • 9756c09 feat: read the process environment once per Build, on first use (#1969)
  • 7347893 test: find compile commands by source file so tests pass with parallel (#1973)
  • 1af399d ci(deps): bump dtolnay/rust-toolchain (#1970)
  • eca35e1 feat: add Build::message_logger for structured access to cc's messages (#1967)
  • c619f08 fix: key the flag support cache on target, host, language and environment (#1...
  • 29fa8ba fix: forward each line of compiler stderr once and whole with parallel (#1959)
  • 0c7e959 ci(deps): bump taiki-e/install-action from 2.87.12 to 2.87.18 (#1964)
  • c8e62c0 ci(deps): bump release-plz/action from 0.5.138 to 0.5.139 (#1961)
  • Additional commits viewable in compare view

Updates compression-codecs from 0.4.43 to 0.4.45

Release notes

Sourced from compression-codecs's releases.

compression-codecs-v0.4.45

Other

  • (deps) update brotli requirement from 8 to 9 (#499)

compression-codecs-v0.4.44

Added

  • (brotli) add optional mbrotli backend (#492)
Commits

Updates libc from 0.2.189 to 0.2.190

Release notes

Sourced from libc's releases.

0.2.190

There is now a single config for enabling 64-bit time_t: libc_unstable_time64. This can be set unconditionally; it opts in to 64-bit time_t on the following platforms that use 32-bit by default:

  • 32-bit Linux-GNU
  • 32-bit Linux-uClibc
  • 32-bit Linux-musl. Note that setting this flag also enables some other changes that happend in musl v1.2.
  • 32-bit Windows-GNU
  • ESP-IDF (all targets with this environment are 32-bit)

Most other 32-bit platforms are either already using 64-bit time_t, or are considered legacy and will not be gaining support from their upstream maintainers.

You can enable this using RUSTFLAGS:

RUSTFLAGS='--cfg=libc_unstable_time64' cargo ...

Note that there may still be some changes to features gated by this config option, hence "unstable" in its name. In the near future we will rename it to just libc_time64. Until then, please test it out and report any bugs you find!

Support

  • Add initial support for HelenOS (#4355)

Added

We are slowly filling out the Default implementations, to reduce the need for mem::zeroed() in user code:

  • Unix: Implement Default for a number of structs, especially on Apple platforms (#5576)
  • Linux, NetBSD: Give statvfs a Default impl (#5583)
  • Linux: Add Default to a linux/can.rs structs (#5257)

Other additions:

  • Expose the libc_unstable_time64 cfg (#5411)
  • Android, Glibc: Add pthread_gettid_np (#5359)
  • Android: Add RTLD_NEXT (#5323)
  • Android: Add reuseport BPF socket options (#5366)
  • Apple: Add TCP header flags, options and SACK limits (#5358)
  • Apple: Add NET_RT_DUMP2 (#5442)
  • Apple: Add posix_spawn_file_actions_add(f)chdir(_np) (#5558)
  • BSD: Add BPF_WORDALIGN (#5320)
  • BSD: Add lchmod and lchflags where supported (#5400)
  • BSD: Add minherit and related constants (#4849)
  • Docs: Add more links to public headers and manual pages (#5407), (#5485)

... (truncated)

Changelog

Sourced from libc's changelog.

0.2.190 - 2026-10-02

There is now a single config for enabling 64-bit time_t: libc_unstable_time64. This can be set unconditionally; it opts in to 64-bit time_t on the following platforms that use 32-bit by default:

  • 32-bit Linux-GNU
  • 32-bit Linux-uClibc
  • 32-bit Linux-musl. Note that setting this flag also enables some other changes that happend in musl v1.2.
  • 32-bit Windows-GNU
  • ESP-IDF (all targets with this environment are 32-bit)

Most other 32-bit platforms are either already using 64-bit time_t, or are considered legacy and will not be gaining support from their upstream maintainers.

You can enable this using RUSTFLAGS:

RUSTFLAGS='--cfg=libc_unstable_time64' cargo ...

Note that there may still be some changes to features gated by this config option, hence "unstable" in its name. In the near future we will rename it to just libc_time64. Until then, please test it out and report any bugs you find!

Support

  • Add initial support for HelenOS (#4355)

Added

We are slowly filling out the Default implementations, to reduce the need for mem::zeroed() in user code:

  • Unix: Implement Default for a number of structs, especially on Apple platforms (#5576)
  • Linux, NetBSD: Give statvfs a Default impl (#5583)
  • Linux: Add Default to a linux/can.rs structs (#5257)

Other additions:

  • Expose the libc_unstable_time64 cfg (#5411)
  • Android, Glibc: Add pthread_gettid_np (#5359)
  • Android: Add RTLD_NEXT (#5323)
  • Android: Add reuseport BPF socket options (#5366)
  • Apple: Add TCP header flags, options and SACK limits (#5358)
  • Apple: Add NET_RT_DUMP2 (#5442)
  • Apple: Add posix_spawn_file_actions_add(f)chdir(_np) (#5558)
  • BSD: Add BPF_WORDALIGN (#5320)
  • BSD: Add lchmod and lchflags where supported (#5400)
  • BSD: Add minherit and related constants (#4849)

... (truncated)

Commits
  • 7b0ab55 ci: Rename publish_0.2.yml to release.yaml
  • ac85dde ci: Sync release permissions with main
  • 8f8cd20 libc: Release 0.2.190
  • 052c6e6 changelog: Fix an incorrect commit link
  • ea19fd7 test: Remove explicit libc version
  • 6dbf3a2 dragonfly: Move INHERIT_ZERO to the freebsd module
  • 8a64766 apple: add posix_spawn_file_actions_add(f)chdir(_np)
  • 28de514 linux, netbsd: Give statvfs a Default impl
  • a58a95f cygwin: Change POSIX_SPAWN_* flags to c_short
  • d175264 apple: timeval32 is exhaustive
  • Additional commits viewable in compare view

Updates mio from 1.2.3 to 1.2.4

Changelog

Sourced from mio's changelog.

1.2.4

Commits

Updates quinn-proto from 0.11.18 to 0.11.19

Release notes

Sourced from quinn-proto's releases.

quinn-proto 0.11.19

Fixes several advisories:

What's Changed

Commits
  • 8192ed3 udp: bump version to 0.5.16
  • 6862d3d udp: backport receive error handling to 0.11.x
  • 78d30dc proto: bump version to 0.11.19
  • 73114d8 Check MAX_STREAM_DATA on remote bidi streams against limit
  • a6e78d1 proto: reserve close frame space after large Initial headers
  • 74c33ff proto: reject Initial tokens that prevent packet construction
  • f97fb5a quinn: Wake wait_idle when the endpoint driver is dropped
  • 8ada074 quinn-proto: Pad Initial datagrams to the configured minimum MTU
  • 16ecc70 fix: stale waker in blocked_readers
  • 12d7f07 fix: cleanup state if transmit failed
  • Additional commits viewable in compare view

Updates tokio from 1.53.1 to 1.53.2

Release notes

Sourced from tokio's releases.

Tokio v1.53.2

1.53.2 (October 3rd, 2026)

Fixed

  • fs: handle integer overflow in buffered relative seek (#8574)
  • io: revert "always cleanup AsyncFd registration list on deregister" (#8540)
  • process: unregister Windows wait before closing child handle (#8564)
  • rt: drop blocking pool mutex before shutting down rejected task (#8562)
  • sync: fix mpsc index wraparound in block reclamation (#8546)
  • sync: forget mpsc Permit before sending value (#8560)
  • sync: validate MAX_PERMITS in Semaphore::acquire (#8548)
  • sync: wake broadcast Sender::closed outside mutex (#8558)
  • task: drop replaced waker outside lock in JoinSet (#8554)
  • time: drop timer lock before dropping waker in clear_entry (#8552)
  • time: expire timers directly on shutdown without rotating wheel (#8570)

Fixed (unstable)

  • fs: clamp io_uring read length to u32::MAX (#8572)
  • rt: ignore current_thread task dumps from other runtimes (#8544)
  • rt: preserve io_uring context if a completion waker panics (#8566)
  • sync: fix semaphore use-after-free and permit leak on tracing panic (#8542)
  • taskdump: restore deferred leaf wakes during capture (#8445)
  • time: drop stored waker when cancelling alt timer entry (#8550)

#8445: tokio-rs/tokio#8445 #8572: tokio-rs/tokio#8572 #8540: tokio-rs/tokio#8540 #8542: tokio-rs/tokio#8542 #8544: tokio-rs/tokio#8544 #8546: tokio-rs/tokio#8546 #8548: tokio-rs/tokio#8548 #8550: tokio-rs/tokio#8550 #8552: tokio-rs/tokio#8552 #8554: tokio-rs/tokio#8554 #8558: tokio-rs/tokio#8558 #8560: tokio-rs/tokio#8560 #8562: tokio-rs/tokio#8562 #8564: tokio-rs/tokio#8564 #8566: tokio-rs/tokio#8566 #8570: tokio-rs/tokio#8570 #8574: tokio-rs/tokio#8574

Commits
  • ff0c406 chore: prepare Tokio v1.53.2 (#8580)
  • a762700 Merge 'tokio-1.51.5' into 'tokio-1.53.x' (#8577)
  • ec31a9f chore: prepare Tokio v1.51.5 (#8579)
  • 625c851 sync: assign semaphore permits before emitting tracing event (#8542)
  • 832dd23 sync: avoid leaking semaphore permits on tracing panic (#8542)
  • 826954a sync: unlink semaphore waiter before emitting tracing event (#8542)
  • 9a47992 process: unregister Windows wait before closing child handle (#8564)
  • 2fc5972 fs: handle integer overflow in buffered relative seek (#8574)
  • 85a6d13 io: revert "always cleanup AsyncFd registration list on deregister" (#8540)
  • 436faa2 rt: drop blocking pool mutex before shutting down rejected task (#8562)
  • Additional commits viewable in compare view

Updates tokio-rustls from 0.26.5 to 0.26.6

Release notes

Sourced from tokio-rustls's releases.

0.26.6

0.26.5 added an optimization to batch multiple reads which could swallow some errors. Buffer errors so that they propagate to the caller as soon as the caller next reads from the stream.

What's Changed

Commits
  • 8aebb7c Bump version to 0.26.6
  • 6f8509a Rename buffered_err to error
  • bd0494d Buffer and propagate errors from transport
  • a781340 Add regression test for issue 204
  • 9d0dae6 build(deps): bump rustls from 0.23.44 to 0.23.45
  • 0ad049e build(deps): bump rustls from 0.23.43 to 0.23.44
  • 4f913c7 build(deps): bump rcgen from 0.14.9 to 0.14.10
  • See full diff in compare view

Updates yoke-derive from 0.8.3 to 0.8.4

Changelog

Sourced from yoke-derive's changelog.

Changelog

icu4x 2.3.x

Several crates have had patch releases in the 2.3 stream:

  • Components
    • (2.3.1) icu
      • Remove dev-dependency on unpublished crate icu_host_info (unicode-org#8404)
    • (0.6.2) icu_codepointtrie_buider
      • Fix use_icu4c build (unicode-org#8541)
    • (2.3.1) icu_collator
      • Fix panic when a contraction contracts a starter, does not contract a following non-starter, and the non-starter starts another contraction. Occurs in Burmese. (unicode-org#8380)
    • (2.3.1) icu_locale
      • Remove unnecessary dependencies on icu_pattern when unstable feature is not enabled (unicode-org#8397)
  • Data model and providers
    • (2.3.1) icu_provider
      • Improve performance of data loading that uses locale fallback (unicode-org#8406)
    • (2.3.1) icu_provider_source
      • Fix checksum on 32-bit systems (unicode-org#8401)
  • FFI
    • General
      • Upate to Diplomat 0.16.1 (unicode-org#8411)
    • (2.3.1) icu_capi
      • Add missing docs to properties (unicode-org#8407)
    • (2.3.2) icu_capi
      • Add missing stability annotations (unicode-org#8462)
    • (2.3.1) Dart
    • (2.3.2) Dart
      • Cache downloaded pre-built binaries (unicode-org#8426)
      • Add missing stability annotations (unicode-org#8462)
    • (2.3.1) NPM
    • (2.3.2) NPM
      • Add missing stability annotations (unicode-org#8462)
  • Utils
    • (0.2.2) databake-derive
      • Update to syn@3 dependency (unicode-org#8293)
    • (0.8.3) yoke-derive
      • Update to syn@3 dependency (unicode-org#8293)
    • (0.8.4) yoke-derive
      • Declare MSRV
    • (0.1.8) zerofrom-derive
      • Update to syn@3 dependency (unicode-org#8293)
    • (0.11.5, 0.11.6) zerovec-derive
      • (0.11.5) Fix soundness issue around multi element buffer validation in ULE derives (unicode-org#8393)
      • (0.11.6) Fix when building with MIRIFLAGS=-Zmiri-tree-borrows (unicode-org#8391)
    • (0.11.8) zerovec
      • Fix length check in impl ULE for [T; N] (unicode-org#8400)

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the cargo group with 11 updates:

| Package | From | To |
| --- | --- | --- |
| [async-compression](https://github.com/Nullus157/async-compression) | `0.4.48` | `0.4.50` |
| [brotli](https://github.com/dropbox/rust-brotli) | `8.0.4` | `9.0.0` |
| [brotli-decompressor](https://github.com/dropbox/rust-brotli-decompressor) | `5.0.3` | `6.0.1` |
| [cc](https://github.com/rust-lang/cc-rs) | `1.5.1` | `1.6.0` |
| [compression-codecs](https://github.com/Nullus157/async-compression) | `0.4.43` | `0.4.45` |
| [libc](https://github.com/rust-lang/libc) | `0.2.189` | `0.2.190` |
| [mio](https://github.com/tokio-rs/mio) | `1.2.3` | `1.2.4` |
| [quinn-proto](https://github.com/quinn-rs/quinn) | `0.11.18` | `0.11.19` |
| [tokio](https://github.com/tokio-rs/tokio) | `1.53.1` | `1.53.2` |
| [tokio-rustls](https://github.com/rustls/tokio-rustls) | `0.26.5` | `0.26.6` |
| [yoke-derive](https://github.com/unicode-org/icu4x) | `0.8.3` | `0.8.4` |


Updates `async-compression` from 0.4.48 to 0.4.50
- [Release notes](https://github.com/Nullus157/async-compression/releases)
- [Commits](Nullus157/async-compression@async-compression-v0.4.48...async-compression-v0.4.50)

Updates `brotli` from 8.0.4 to 9.0.0
- [Release notes](https://github.com/dropbox/rust-brotli/releases)
- [Commits](dropbox/rust-brotli@8.0.4...9.0.0)

Updates `brotli-decompressor` from 5.0.3 to 6.0.1
- [Release notes](https://github.com/dropbox/rust-brotli-decompressor/releases)
- [Commits](dropbox/rust-brotli-decompressor@5.0.3...6.0.1)

Updates `cc` from 1.5.1 to 1.6.0
- [Release notes](https://github.com/rust-lang/cc-rs/releases)
- [Changelog](https://github.com/rust-lang/cc-rs/blob/main/CHANGELOG.md)
- [Commits](rust-lang/cc-rs@cc-v1.5.1...cc-v1.6.0)

Updates `compression-codecs` from 0.4.43 to 0.4.45
- [Release notes](https://github.com/Nullus157/async-compression/releases)
- [Commits](Nullus157/async-compression@compression-codecs-v0.4.43...compression-codecs-v0.4.45)

Updates `libc` from 0.2.189 to 0.2.190
- [Release notes](https://github.com/rust-lang/libc/releases)
- [Changelog](https://github.com/rust-lang/libc/blob/0.2.190/CHANGELOG.md)
- [Commits](rust-lang/libc@0.2.189...0.2.190)

Updates `mio` from 1.2.3 to 1.2.4
- [Release notes](https://github.com/tokio-rs/mio/releases)
- [Changelog](https://github.com/tokio-rs/mio/blob/master/CHANGELOG.md)
- [Commits](tokio-rs/mio@v1.2.3...v1.2.4)

Updates `quinn-proto` from 0.11.18 to 0.11.19
- [Release notes](https://github.com/quinn-rs/quinn/releases)
- [Commits](quinn-rs/quinn@quinn-proto-0.11.18...quinn-proto-0.11.19)

Updates `tokio` from 1.53.1 to 1.53.2
- [Release notes](https://github.com/tokio-rs/tokio/releases)
- [Commits](tokio-rs/tokio@tokio-1.53.1...tokio-1.53.2)

Updates `tokio-rustls` from 0.26.5 to 0.26.6
- [Release notes](https://github.com/rustls/tokio-rustls/releases)
- [Commits](rustls/tokio-rustls@v/0.26.5...v/0.26.6)

Updates `yoke-derive` from 0.8.3 to 0.8.4
- [Release notes](https://github.com/unicode-org/icu4x/releases)
- [Changelog](https://github.com/unicode-org/icu4x/blob/main/CHANGELOG.md)
- [Commits](https://github.com/unicode-org/icu4x/commits)

---
updated-dependencies:
- dependency-name: async-compression
  dependency-version: 0.4.50
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: brotli
  dependency-version: 9.0.0
  dependency-type: indirect
  update-type: version-update:semver-major
  dependency-group: cargo
- dependency-name: brotli-decompressor
  dependency-version: 6.0.1
  dependency-type: indirect
  update-type: version-update:semver-major
  dependency-group: cargo
- dependency-name: cc
  dependency-version: 1.6.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: cargo
- dependency-name: compression-codecs
  dependency-version: 0.4.45
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: libc
  dependency-version: 0.2.190
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: mio
  dependency-version: 1.2.4
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: quinn-proto
  dependency-version: 0.11.19
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: tokio
  dependency-version: 1.53.2
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: tokio-rustls
  dependency-version: 0.26.6
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: yoke-derive
  dependency-version: 0.8.4
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: cargo
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 7, 2026
@dependabot
dependabot Bot requested a review from NullSablex as a code owner October 7, 2026 06:56
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 7, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants