Skip to content

build(deps): bump the rust group with 8 updates - #151

Merged
peterj merged 1 commit into
mainfrom
dependabot/cargo/rust-50e088e92e
Oct 7, 2026
Merged

peterj merged 1 commit into
mainfrom
dependabot/cargo/rust-50e088e92e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Bumps the rust group with 8 updates:

Package From To
hyper-rustls 0.27.9 0.27.10
rustls 0.23.43 0.23.45
libc 0.2.189 0.2.190
tokio 1.53.1 1.53.2
uuid 1.26.1 1.27.0
tauri 2.12.0 2.12.1
tauri-plugin-single-instance 2.5.0 2.5.2
tauri-build 2.7.0 2.7.1

Updates hyper-rustls from 0.27.9 to 0.27.10

Release notes

Sourced from hyper-rustls's releases.

0.27.10

Maintenance release, principally fixing #344

What's Changed

Full Changelog: rustls/hyper-rustls@v/0.27.9...v/0.27.10

Commits
  • ce45b6b Bump rustls from 0.23.44 to 0.23.45
  • a3a1838 Bump rustls from 0.23.43 to 0.23.44
  • 6e1d602 Bump tokio-rustls from 0.26.4 to 0.26.5
  • 96e3b92 Bump hyper from 1.11.0 to 1.11.1
  • 3989e37 Bump log from 0.4.33 to 0.4.34
  • eed79ba Bump http-body-util from 0.1.4 to 0.1.5
  • fadbc9e Bump http from 1.4.2 to 1.5.0
  • 9519052 Bump rustls from 0.23.42 to 0.23.43
  • a2f1a60 Bump webpki-roots from 1.0.8 to 1.0.9
  • acce69f Bump tokio from 1.53.0 to 1.53.1
  • Additional commits viewable in compare view

Updates rustls from 0.23.43 to 0.23.45

Commits
  • 2976d90 Prepare 0.23.45
  • f9d4ee9 Handshake "alignment" check covers previously-received messages
  • c4e92e8 Keep data needed for HRR processing together
  • e553a7a server: TLS1.2 is not available after a HRR
  • 5dff9da Test whether server negotiates TLS1.2 after HRR
  • 185a063 reject a second ClientHello that changes the cipher suite
  • 9fafe6d reject a second ClientHello that drops pre_shared_key
  • 1b42c5f providers: zeroize private key DER
  • 64ad386 Bump version to 0.23.44
  • 1efbf66 bogo: remove PostQuantum setup
  • Additional commits viewable in compare view

Updates libc from 0.2.189 to 0.2.190

Release notes

Sourced from libc's releases.

0.2.190

There is now a single config for enabling 64-bit time_t: libc_unstable_time64. This can be set unconditionally; it opts in to 64-bit time_t on the following platforms that use 32-bit by default:

  • 32-bit Linux-GNU
  • 32-bit Linux-uClibc
  • 32-bit Linux-musl. Note that setting this flag also enables some other changes that happend in musl v1.2.
  • 32-bit Windows-GNU
  • ESP-IDF (all targets with this environment are 32-bit)

Most other 32-bit platforms are either already using 64-bit time_t, or are considered legacy and will not be gaining support from their upstream maintainers.

You can enable this using RUSTFLAGS:

RUSTFLAGS='--cfg=libc_unstable_time64' cargo ...

Note that there may still be some changes to features gated by this config option, hence "unstable" in its name. In the near future we will rename it to just libc_time64. Until then, please test it out and report any bugs you find!

Support

  • Add initial support for HelenOS (#4355)

Added

We are slowly filling out the Default implementations, to reduce the need for mem::zeroed() in user code:

  • Unix: Implement Default for a number of structs, especially on Apple platforms (#5576)
  • Linux, NetBSD: Give statvfs a Default impl (#5583)
  • Linux: Add Default to a linux/can.rs structs (#5257)

Other additions:

  • Expose the libc_unstable_time64 cfg (#5411)
  • Android, Glibc: Add pthread_gettid_np (#5359)
  • Android: Add RTLD_NEXT (#5323)
  • Android: Add reuseport BPF socket options (#5366)
  • Apple: Add TCP header flags, options and SACK limits (#5358)
  • Apple: Add NET_RT_DUMP2 (#5442)
  • Apple: Add posix_spawn_file_actions_add(f)chdir(_np) (#5558)
  • BSD: Add BPF_WORDALIGN (#5320)
  • BSD: Add lchmod and lchflags where supported (#5400)
  • BSD: Add minherit and related constants (#4849)
  • Docs: Add more links to public headers and manual pages (#5407), (#5485)

... (truncated)

Changelog

Sourced from libc's changelog.

0.2.190 - 2026-10-02

There is now a single config for enabling 64-bit time_t: libc_unstable_time64. This can be set unconditionally; it opts in to 64-bit time_t on the following platforms that use 32-bit by default:

  • 32-bit Linux-GNU
  • 32-bit Linux-uClibc
  • 32-bit Linux-musl. Note that setting this flag also enables some other changes that happend in musl v1.2.
  • 32-bit Windows-GNU
  • ESP-IDF (all targets with this environment are 32-bit)

Most other 32-bit platforms are either already using 64-bit time_t, or are considered legacy and will not be gaining support from their upstream maintainers.

You can enable this using RUSTFLAGS:

RUSTFLAGS='--cfg=libc_unstable_time64' cargo ...

Note that there may still be some changes to features gated by this config option, hence "unstable" in its name. In the near future we will rename it to just libc_time64. Until then, please test it out and report any bugs you find!

Support

  • Add initial support for HelenOS (#4355)

Added

We are slowly filling out the Default implementations, to reduce the need for mem::zeroed() in user code:

  • Unix: Implement Default for a number of structs, especially on Apple platforms (#5576)
  • Linux, NetBSD: Give statvfs a Default impl (#5583)
  • Linux: Add Default to a linux/can.rs structs (#5257)

Other additions:

  • Expose the libc_unstable_time64 cfg (#5411)
  • Android, Glibc: Add pthread_gettid_np (#5359)
  • Android: Add RTLD_NEXT (#5323)
  • Android: Add reuseport BPF socket options (#5366)
  • Apple: Add TCP header flags, options and SACK limits (#5358)
  • Apple: Add NET_RT_DUMP2 (#5442)
  • Apple: Add posix_spawn_file_actions_add(f)chdir(_np) (#5558)
  • BSD: Add BPF_WORDALIGN (#5320)
  • BSD: Add lchmod and lchflags where supported (#5400)
  • BSD: Add minherit and related constants (#4849)

... (truncated)

Commits
  • 7b0ab55 ci: Rename publish_0.2.yml to release.yaml
  • ac85dde ci: Sync release permissions with main
  • 8f8cd20 libc: Release 0.2.190
  • 052c6e6 changelog: Fix an incorrect commit link
  • ea19fd7 test: Remove explicit libc version
  • 6dbf3a2 dragonfly: Move INHERIT_ZERO to the freebsd module
  • 8a64766 apple: add posix_spawn_file_actions_add(f)chdir(_np)
  • 28de514 linux, netbsd: Give statvfs a Default impl
  • a58a95f cygwin: Change POSIX_SPAWN_* flags to c_short
  • d175264 apple: timeval32 is exhaustive
  • Additional commits viewable in compare view

Updates tokio from 1.53.1 to 1.53.2

Release notes

Sourced from tokio's releases.

Tokio v1.53.2

1.53.2 (October 3rd, 2026)

Fixed

  • fs: handle integer overflow in buffered relative seek (#8574)
  • io: revert "always cleanup AsyncFd registration list on deregister" (#8540)
  • process: unregister Windows wait before closing child handle (#8564)
  • rt: drop blocking pool mutex before shutting down rejected task (#8562)
  • sync: fix mpsc index wraparound in block reclamation (#8546)
  • sync: forget mpsc Permit before sending value (#8560)
  • sync: validate MAX_PERMITS in Semaphore::acquire (#8548)
  • sync: wake broadcast Sender::closed outside mutex (#8558)
  • task: drop replaced waker outside lock in JoinSet (#8554)
  • time: drop timer lock before dropping waker in clear_entry (#8552)
  • time: expire timers directly on shutdown without rotating wheel (#8570)

Fixed (unstable)

  • fs: clamp io_uring read length to u32::MAX (#8572)
  • rt: ignore current_thread task dumps from other runtimes (#8544)
  • rt: preserve io_uring context if a completion waker panics (#8566)
  • sync: fix semaphore use-after-free and permit leak on tracing panic (#8542)
  • taskdump: restore deferred leaf wakes during capture (#8445)
  • time: drop stored waker when cancelling alt timer entry (#8550)

#8445: tokio-rs/tokio#8445 #8572: tokio-rs/tokio#8572 #8540: tokio-rs/tokio#8540 #8542: tokio-rs/tokio#8542 #8544: tokio-rs/tokio#8544 #8546: tokio-rs/tokio#8546 #8548: tokio-rs/tokio#8548 #8550: tokio-rs/tokio#8550 #8552: tokio-rs/tokio#8552 #8554: tokio-rs/tokio#8554 #8558: tokio-rs/tokio#8558 #8560: tokio-rs/tokio#8560 #8562: tokio-rs/tokio#8562 #8564: tokio-rs/tokio#8564 #8566: tokio-rs/tokio#8566 #8570: tokio-rs/tokio#8570 #8574: tokio-rs/tokio#8574

Commits
  • ff0c406 chore: prepare Tokio v1.53.2 (#8580)
  • a762700 Merge 'tokio-1.51.5' into 'tokio-1.53.x' (#8577)
  • ec31a9f chore: prepare Tokio v1.51.5 (#8579)
  • 625c851 sync: assign semaphore permits before emitting tracing event (#8542)
  • 832dd23 sync: avoid leaking semaphore permits on tracing panic (#8542)
  • 826954a sync: unlink semaphore waiter before emitting tracing event (#8542)
  • 9a47992 process: unregister Windows wait before closing child handle (#8564)
  • 2fc5972 fs: handle integer overflow in buffered relative seek (#8574)
  • 85a6d13 io: revert "always cleanup AsyncFd registration list on deregister" (#8540)
  • 436faa2 rt: drop blocking pool mutex before shutting down rejected task (#8562)
  • Additional commits viewable in compare view

Updates uuid from 1.26.1 to 1.27.0

Release notes

Sourced from uuid's releases.

v1.27.0

What's Changed

New Contributors

Full Changelog: uuid-rs/uuid@v1.26.1...v1.27.0

Commits
  • b62154e Merge pull request #917 from uuid-rs/cargo/v1.27.0
  • ffd8ec5 prepare for 1.27.0 release
  • 4b6c10f Merge pull request #915 from uuid-rs/fix/v7-ordering
  • a1aa126 Merge pull request #912 from jaideeppyne/fix/urn-prefix-case-insensitive
  • 4639d67 fix ordering of V7 UUIDs created by earlier seconds with later subsec nanos
  • 2723703 bump MSRV to 1.89.0
  • a3e64fa refactor: simplify URN prefix parsing
  • 5055fd4 refactor: inline case-insensitive URN prefix checks
  • cb8b1d5 refactor: simplify case-insensitive URN parsing
  • 285967d Accept case-insensitive urn:uuid: prefixes when parsing
  • See full diff in compare view

Updates tauri from 2.12.0 to 2.12.1

Release notes

Sourced from tauri's releases.

tauri-cli v2.12.1

Fetching advisory database from `https://github.com/RustSec/advisory-db.git`
      Loaded 1277 security advisories (from /home/runner/.cargo/advisory-db)
    Updating crates.io index
    Scanning Cargo.lock for vulnerabilities (1091 crate dependencies)
Crate:     fxhash
Version:   0.2.1
Warning:   unmaintained
Title:     fxhash - no longer maintained
Date:      2025-09-05
ID:        RUSTSEC-2025-0057
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0057

Crate: paste
Version: 1.0.15
Warning: unmaintained
Title: paste - no longer maintained
Date: 2024-10-07
ID: RUSTSEC-2024-0436
URL: https://rustsec.org/advisories/RUSTSEC-2024-0436

Crate: rustls-pemfile
Version: 2.2.0
Warning: unmaintained
Title: rustls-pemfile is unmaintained
Date: 2025-11-28
ID: RUSTSEC-2025-0134
URL: https://rustsec.org/advisories/RUSTSEC-2025-0134

Crate: rustybuzz
Version: 0.20.1
Warning: unmaintained
Title: rustybuzz is unmaintained
Date: 2026-07-11
ID: RUSTSEC-2026-0206
URL: https://rustsec.org/advisories/RUSTSEC-2026-0206

Crate: ttf-parser
Version: 0.25.1
Warning: unmaintained
Title: ttf-parser is unmaintained
Date: 2026-06-28
ID: RUSTSEC-2026-0192
URL: https://rustsec.org/advisories/RUSTSEC-2026-0192

warning: 5 allowed warnings found
</tr></table>

... (truncated)

Commits

Updates tauri-plugin-single-instance from 2.5.0 to 2.5.2

Release notes

Sourced from tauri-plugin-single-instance's releases.

single-instance v2.5.2

[2.5.2]

Dependencies

  • Upgraded to deep-link@2.6.1
Updating crates.io index
   Packaging tauri-plugin-single-instance v2.5.2 (/home/runner/work/plugins-workspace/plugins-workspace/plugins/single-instance)
    Updating crates.io index
warning: package `yoke-derive v0.8.3` in Cargo.lock is yanked in registry `crates-io`
  |
  = help: consider updating to a version that is not yanked
    Packaged 15 files, 168.3KiB (46.0KiB compressed)
   Uploading tauri-plugin-single-instance v2.5.2 (/home/runner/work/plugins-workspace/plugins-workspace/plugins/single-instance)
    Uploaded tauri-plugin-single-instance v2.5.2 to registry `crates-io`
note: waiting for tauri-plugin-single-instance v2.5.2 to be available at registry `crates-io`
help: you may press ctrl-c to skip waiting; the crate should be available shortly
   Published tauri-plugin-single-instance v2.5.2 at registry `crates-io`

single-instance v2.5.1

[2.5.1]

  • ecd3273e (#3480 by @​renovate) Updated windows-rs dependencies:

    • deep-link: updated windows-registry to 0.6 and windows-result to 0.4. The public Error::Windows variant wraps windows_result::Error; applications using this type directly should update their windows-result dependency.
    • opener: updated windows to 0.62. The public Error::Win32Error variant wraps windows::core::Error; applications using this type directly should update their windows dependency.
    • single-instance: updated windows-sys to 0.61
    • updater: updated windows-sys to 0.61

Dependencies

  • Upgraded to deep-link@2.6.0
Updating crates.io index
   Packaging tauri-plugin-single-instance v2.5.1 (/home/runner/work/plugins-workspace/plugins-workspace/plugins/single-instance)
    Updating crates.io index
    Packaged 15 files, 168.2KiB (46.0KiB compressed)
   Uploading tauri-plugin-single-instance v2.5.1 (/home/runner/work/plugins-workspace/plugins-workspace/plugins/single-instance)
</tr></table> 

... (truncated)

Commits

Updates tauri-build from 2.7.0 to 2.7.1

Release notes

Sourced from tauri-build's releases.

tauri-build v2.7.1

Fetching advisory database from `https://github.com/RustSec/advisory-db.git`
      Loaded 1277 security advisories (from /home/runner/.cargo/advisory-db)
    Updating crates.io index
    Scanning Cargo.lock for vulnerabilities (1091 crate dependencies)
Crate:     fxhash
Version:   0.2.1
Warning:   unmaintained
Title:     fxhash - no longer maintained
Date:      2025-09-05
ID:        RUSTSEC-2025-0057
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0057

Crate: paste
Version: 1.0.15
Warning: unmaintained
Title: paste - no longer maintained
Date: 2024-10-07
ID: RUSTSEC-2024-0436
URL: https://rustsec.org/advisories/RUSTSEC-2024-0436

Crate: rustls-pemfile
Version: 2.2.0
Warning: unmaintained
Title: rustls-pemfile is unmaintained
Date: 2025-11-28
ID: RUSTSEC-2025-0134
URL: https://rustsec.org/advisories/RUSTSEC-2025-0134

Crate: rustybuzz
Version: 0.20.1
Warning: unmaintained
Title: rustybuzz is unmaintained
Date: 2026-07-11
ID: RUSTSEC-2026-0206
URL: https://rustsec.org/advisories/RUSTSEC-2026-0206

Crate: ttf-parser
Version: 0.25.1
Warning: unmaintained
Title: ttf-parser is unmaintained
Date: 2026-06-28
ID: RUSTSEC-2026-0192
URL: https://rustsec.org/advisories/RUSTSEC-2026-0192

warning: 5 allowed warnings found
</tr></table>

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the rust group with 8 updates:

| Package | From | To |
| --- | --- | --- |
| [hyper-rustls](https://github.com/rustls/hyper-rustls) | `0.27.9` | `0.27.10` |
| [rustls](https://github.com/rustls/rustls) | `0.23.43` | `0.23.45` |
| [libc](https://github.com/rust-lang/libc) | `0.2.189` | `0.2.190` |
| [tokio](https://github.com/tokio-rs/tokio) | `1.53.1` | `1.53.2` |
| [uuid](https://github.com/uuid-rs/uuid) | `1.26.1` | `1.27.0` |
| [tauri](https://github.com/tauri-apps/tauri) | `2.12.0` | `2.12.1` |
| [tauri-plugin-single-instance](https://github.com/tauri-apps/plugins-workspace) | `2.5.0` | `2.5.2` |
| [tauri-build](https://github.com/tauri-apps/tauri) | `2.7.0` | `2.7.1` |


Updates `hyper-rustls` from 0.27.9 to 0.27.10
- [Release notes](https://github.com/rustls/hyper-rustls/releases)
- [Commits](rustls/hyper-rustls@v/0.27.9...v/0.27.10)

Updates `rustls` from 0.23.43 to 0.23.45
- [Release notes](https://github.com/rustls/rustls/releases)
- [Changelog](https://github.com/rustls/rustls/blob/main/CHANGELOG.md)
- [Commits](rustls/rustls@v/0.23.43...v/0.23.45)

Updates `libc` from 0.2.189 to 0.2.190
- [Release notes](https://github.com/rust-lang/libc/releases)
- [Changelog](https://github.com/rust-lang/libc/blob/0.2.190/CHANGELOG.md)
- [Commits](rust-lang/libc@0.2.189...0.2.190)

Updates `tokio` from 1.53.1 to 1.53.2
- [Release notes](https://github.com/tokio-rs/tokio/releases)
- [Commits](tokio-rs/tokio@tokio-1.53.1...tokio-1.53.2)

Updates `uuid` from 1.26.1 to 1.27.0
- [Release notes](https://github.com/uuid-rs/uuid/releases)
- [Commits](uuid-rs/uuid@v1.26.1...v1.27.0)

Updates `tauri` from 2.12.0 to 2.12.1
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](tauri-apps/tauri@tauri-v2.12.0...tauri-v2.12.1)

Updates `tauri-plugin-single-instance` from 2.5.0 to 2.5.2
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@fs-v2.5.0...fs-v2.5.2)

Updates `tauri-build` from 2.7.0 to 2.7.1
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](tauri-apps/tauri@tauri-build-v2.7.0...tauri-build-v2.7.1)

---
updated-dependencies:
- dependency-name: hyper-rustls
  dependency-version: 0.27.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust
- dependency-name: rustls
  dependency-version: 0.23.45
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust
- dependency-name: libc
  dependency-version: 0.2.190
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust
- dependency-name: tokio
  dependency-version: 1.53.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust
- dependency-name: uuid
  dependency-version: 1.27.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust
- dependency-name: tauri
  dependency-version: 2.12.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust
- dependency-name: tauri-plugin-single-instance
  dependency-version: 2.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust
- dependency-name: tauri-build
  dependency-version: 2.7.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 7, 2026
@peterj
peterj merged commit b4442dc into main Oct 7, 2026
3 checks passed
@dependabot
dependabot Bot deleted the dependabot/cargo/rust-50e088e92e branch October 7, 2026 19:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant