Skip to content

chore(deps): weekly safe cargo updates · 3 packages - #45

Open
ghost wants to merge 2 commits into
mainfrom
mendral/deps/weekly-safe-cargo-20260817
Open

ghost wants to merge 2 commits into
mainfrom
mendral/deps/weekly-safe-cargo-20260817

Conversation

@ghost

@ghost ghost commented Aug 17, 2026

Copy link
Copy Markdown

Packages bumped

Crate Old New Published
async-trait 0.1.89 0.1.92 2026-08-08
rustls 0.23.37 0.23.43 2026-07-29
thiserror 2.0.18 2.0.20 2026-08-08
Per-package detail

async-trait 0.1.89 → 0.1.92

  • 0.1.91: Updated to syn 3; fixed mutability for by-reference receivers.
  • 0.1.92: Suppressed double_must_use clippy lint in generated code.
  • Impact: We use #[async_trait] on port/connector traits (src/ports/, src/connectors/). No API changes — these are internal fixes.

rustls 0.23.37 → 0.23.43

  • 0.23.38: Allow skipping selected ALPN validation (client config option).
  • 0.23.39–0.23.41: Nightly read_buf API adaptations (maintenance).
  • 0.23.40: Corrected ECH padding and require_ems default based on provider FIPS status.
  • 0.23.42: New opt-in RFC 9149 "TLS Ticket Requests" support (ClientConfig.send_ticket_request, ServerConfig.max_tls13_tickets).
  • 0.23.43: Fixed panic in Rfc5077Ticketer with aws-lc-rs provider (ring unaffected); fixed QUIC client panics.
  • Impact: We use rustls only as TLS backend for reqwest/octocrab with ring provider (src/main.rs:12-13). We don't use QUIC, ECH, or aws-lc-rs. No behavioral change for our usage.

thiserror 2.0.18 → 2.0.20

  • 2.0.19: Updated to syn 3.
  • 2.0.20: Suppressed redundant_field_names clippy lint in generated code.
  • Impact: We use #[derive(thiserror::Error)] across 7 error types. No API changes — internal dependency update and lint fix.

Files modified

  • Cargo.toml
  • Cargo.lock
Skipped this ecosystem
Crate Current Latest eligible Reason
ammonia 4.1.2 4.1.4 Open PR #42
askama_escape 0.15.4 0.16.0 Open PR #24 (breaking)
axum 0.8.8 0.8.9 Open PR #31
chrono 0.4.44 0.4.45 Open PR #31
hex 0.4.3 — Already latest
hmac 0.12.1 0.13.0 Open PR #33 (breaking)
http 1.4.0 1.5.0 Open PR #44
http-body-util 0.1.3 0.1.4 Open PR #37
jsonwebtoken 10.3.0 11.0.0 Major bump blocked by octocrab coupling
mockall 0.14.0 0.15.0 Open PR #35
octocrab 0.49.5 0.53.1+ Open PR #28
rand 0.10.0 0.10.2 Open PR #37
reqwest 0.13.2 0.13.4 Open PR #31
serde 1.0.228 1.0.229 Open PR #40
serde_json 1.0.149 1.0.151 Open PR #40
sha2 0.10.9 0.11.0 Open PR #33 (breaking)
tokio 1.49.0 1.53.1 Open PR #42
tower 0.5.3 — Already latest
tracing 0.1.44 — Already latest
tracing-subscriber 0.3.22 0.3.23 Open PR #29
uuid 1.21.0 1.24.1 1.24.1 within cooldown (published 2026-08-14); 1.24.0 covered by PR #37

Note

Created by Mendral. Tag @mendral-app with feedback or questions.

Bump async-trait 0.1.89 → 0.1.92, rustls 0.23.37 → 0.23.43, thiserror 2.0.18 → 2.0.20
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Aug 17, 2026 •

Copy link
Copy Markdown

Deploying pratrol with  Cloudflare Pages  Cloudflare Pages

Latest commit: 9f0e96e
Status: ✅  Deploy successful!
Preview URL: https://fff58c02.pratrol.pages.dev
Branch Preview URL: https://mendral-deps-weekly-safe-car-5yqb.pratrol.pages.dev

View logs

Required by repository policy to prevent supply-chain attacks via
mutable action tags.
@ghost
ghost marked this pull request as ready for review August 17, 2026 09:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants