Repository navigation
chore(deps): bump the rust-security group across 1 directory with 10 updates - #10
Merged
David Mireles (louzt) merged 2 commits intoAug 15, 2026
Merged
Conversation
dependabot
Bot
force-pushed
the
dependabot/cargo/rust-security-76e0833681
branch
from
August 15, 2026 09:03
48f4bab to
55cca69
Compare
David Mireles (louzt)
added a commit
that referenced
this pull request
Aug 15, 2026
cargo fmt --all across the workspace. This is the F2.5 fmt cleanup that was tracked in MANIFEST-2026-08-07-linkmarks-fase2-batch.md §Known caveats #1 ('cargo fmt --check not 100% clean — 56 pre-existing hunks of drift in F1–F4 .rs files'). Required to unblock Dependabot PR #10 (rust-security group bump), whose CI was failing not on its own changes (Cargo.toml/Cargo.lock only) but on the fmt drift in render_test.rs / input_test.rs etc. that pre-dated Dependabot's branch. Pure formatting — no semantic changes. Verified: - cargo build --workspace --all-targets — clean - cargo test --workspace --no-fail-fast — 250/250 green - cargo clippy --workspace --all-targets -- -D warnings — clean - cargo fmt --all -- --check — clean (exit 0)
Contributor
|
Dependabot (@dependabot) rebase |
1 similar comment
Contributor
|
Dependabot (@dependabot) rebase |
dependabot
Bot
force-pushed
the
dependabot/cargo/rust-security-76e0833681
branch
from
August 15, 2026 09:12
55cca69 to
de98a1d
Compare
Contributor
|
Dependabot (@dependabot) recreate |
…updates Bumps the rust-security group with 10 updates in the / directory: | Package | From | To | | --- | --- | --- | | [thiserror](https://github.com/dtolnay/thiserror) | `1.0.69` | `2.0.20` | | [ulid](https://github.com/dylanhart/ulid-rs) | `1.2.1` | `3.0.0` | | [rusqlite](https://github.com/rusqlite/rusqlite) | `0.31.0` | `0.40.2` | | [clap](https://github.com/clap-rs/clap) | `4.6.4` | `4.6.6` | | [quick-xml](https://github.com/tafia/quick-xml) | `0.36.2` | `0.41.0` | | [lz4_flex](https://github.com/pseitz/lz4_flex) | `0.11.6` | `0.14.0` | | [dirs](https://github.com/soc/dirs-rs) | `5.0.1` | `6.0.0` | | [toml](https://github.com/toml-rs/toml) | `0.8.23` | `1.1.4+spec-1.1.0` | | [ratatui](https://github.com/ratatui/ratatui) | `0.28.1` | `0.30.2` | | [crossterm](https://github.com/crossterm-rs/crossterm) | `0.28.1` | `0.29.0` | Updates `thiserror` from 1.0.69 to 2.0.20 - [Release notes](https://github.com/dtolnay/thiserror/releases) - [Commits](dtolnay/thiserror@1.0.69...2.0.20) Updates `ulid` from 1.2.1 to 3.0.0 - [Commits](dylanhart/ulid-rs@v1.2.1...v3.0.0) Updates `rusqlite` from 0.31.0 to 0.40.2 - [Release notes](https://github.com/rusqlite/rusqlite/releases) - [Changelog](https://github.com/rusqlite/rusqlite/blob/master/Changelog.md) - [Commits](rusqlite/rusqlite@v0.31.0...v0.40.2) Updates `clap` from 4.6.4 to 4.6.6 - [Release notes](https://github.com/clap-rs/clap/releases) - [Changelog](https://github.com/clap-rs/clap/blob/master/CHANGELOG.md) - [Commits](clap-rs/clap@clap_complete-v4.6.4...clap_complete-v4.6.6) Updates `quick-xml` from 0.36.2 to 0.41.0 - [Release notes](https://github.com/tafia/quick-xml/releases) - [Changelog](https://github.com/tafia/quick-xml/blob/master/Changelog.md) - [Commits](tafia/quick-xml@v0.36.2...v0.41.0) Updates `lz4_flex` from 0.11.6 to 0.14.0 - [Release notes](https://github.com/pseitz/lz4_flex/releases) - [Changelog](https://github.com/PSeitz/lz4_flex/blob/main/CHANGELOG.md) - [Commits](PSeitz/lz4_flex@0.11.6...0.14.0) Updates `dirs` from 5.0.1 to 6.0.0 - [Commits](https://github.com/soc/dirs-rs/commits) Updates `toml` from 0.8.23 to 1.1.4+spec-1.1.0 - [Commits](toml-rs/toml@toml-v0.8.23...toml-v1.1.4) Updates `ratatui` from 0.28.1 to 0.30.2 - [Release notes](https://github.com/ratatui/ratatui/releases) - [Changelog](https://github.com/ratatui/ratatui/blob/main/CHANGELOG.md) - [Commits](ratatui/ratatui@v0.28.1...ratatui-v0.30.2) Updates `crossterm` from 0.28.1 to 0.29.0 - [Release notes](https://github.com/crossterm-rs/crossterm/releases) - [Changelog](https://github.com/crossterm-rs/crossterm/blob/master/CHANGELOG.md) - [Commits](https://github.com/crossterm-rs/crossterm/commits/0.29) --- updated-dependencies: - dependency-name: clap dependency-version: 4.6.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: rust-security - dependency-name: crossterm dependency-version: 0.29.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: rust-security - dependency-name: dirs dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: rust-security - dependency-name: lz4_flex dependency-version: 0.14.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: rust-security - dependency-name: quick-xml dependency-version: 0.41.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: rust-security - dependency-name: ratatui dependency-version: 0.30.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: rust-security - dependency-name: rusqlite dependency-version: 0.40.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: rust-security - dependency-name: thiserror dependency-version: 2.0.20 dependency-type: direct:production update-type: version-update:semver-major dependency-group: rust-security - dependency-name: toml dependency-version: 1.1.4+spec-1.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: rust-security - dependency-name: ulid dependency-version: 3.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: rust-security ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/cargo/rust-security-76e0833681
branch
from
August 15, 2026 09:14
de98a1d to
ee1087d
Compare
Two breaking changes from Dependabot's rust-security group bump landed in CI but did not compile against the v0.36 / 1.x code paths. 1. **ulid 1.x → 3.x** — `Ulid::new()` removed; the constructor is now `Ulid::generate()` (the previous free function on `Ulid`) which returns `Self` rather than `Result`. Updated the single call site in `crates/linkmarks-core/src/model.rs:23`. 2. **quick-xml 0.36 → 0.41** — character references (`&`, ` `, `á` …) are now emitted as a separate `Event::GeneralRef` rather than being folded into the surrounding `Event::Text`. The previous exhaustive match on `Start/End/Text/Empty/...` therefore stopped compiling. The new handler decodes the entity body bytes through the same `resolve_entity` / `decode_numeric_entity` helpers that the text path uses. The full set of HTML5 named entities (`&`, `á`, …) plus numeric refs (`&#NN;`, `&#xNN;`) is preserved. One subtle behavioural correction falls out of this work: previously, both `handle_text` and the new `GeneralRef` arm inserted a single ASCII space as a 'separator' before each non-empty text chunk. With quick-xml 0.36 this was a no-op for the common case because each text chunk was already self- contained (decoded entities folded in). With quick-xml 0.41 a single logical text chunk is now broken into `Text"AT" + GeneralRef& + Text"T"` for an input like `AT&T`, and the separator logic produced "AT & T" instead of the expected "AT&T". The fix is to drop the separator: the contents of a single `<A>` title is one contiguous string and must not have artificial padding between events. A separate clippy nit was folded in: `&**text` triggered `explicit-auto-deref` under Rust 1.97; the type-annotated binding `let raw_bytes: &[u8] = text;` reads cleanly via `Deref`. `attr.unescape_value()` is deprecated in quick-xml 0.41 (in favour of `normalized_value`), but the deprecation note explicitly says it only fires when the `encoding` feature is OFF — our case (we only enable `serialize`). The replacement `normalized_value` additionally applies XML attribute-value normalization (whitespace collapsing), which would corrupt URLs that legitimately contain multiple spaces, so we `#[allow(deprecated)]` on that single call site and document the rationale. Validation: - `cargo test --workspace --no-fail-fast` → 250/250 green. - `cargo clippy --workspace --all-targets -- -D warnings` → clean. - `cargo fmt --all -- --check` → clean. Refs: #10
David Mireles (louzt)
deleted the
dependabot/cargo/rust-security-76e0833681
branch
August 15, 2026 15:13
David Mireles (louzt)
added a commit
that referenced
this pull request
Aug 15, 2026
Bumps workspace version 2.0.0 → 2.0.1 and adds CHANGELOG entry covering the 10 dep updates that landed in PR #10 (thiserror 1→2, ulid 1→3, dirs 5→6, toml 0.8→1.1, ratatui 0.28→0.30, crossterm 0.28→0.29, rusqlite 0.31→0.40, lz4_flex 0.11→0.14, clap 4.6.4→4.6.6, quick-xml 0.36→0.41) plus the manual fix-up commits: - ulid 1.x→3.x API change (Ulid::new() → Ulid::generate()) - quick-xml 0.36→0.41 Event::GeneralRef handler with proper entity decoding and separator-removal for AT&T round-trip - clippy explicit-auto-deref cleanup under Rust 1.97 All 250 tests green; clippy + fmt clean; CI smoke green on PR #10. Refs: #10 louzt <davidmirelesll@outlook.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the rust-security group with 10 updates in the / directory:
1.0.692.0.201.2.13.0.00.31.00.40.24.6.44.6.60.36.20.41.00.11.60.14.05.0.16.0.00.8.231.1.4+spec-1.1.00.28.10.30.20.28.10.29.0Updates
thiserrorfrom 1.0.69 to 2.0.20Release notes
Sourced from thiserror's releases.
... (truncated)
Commits
b1d5db5Release 2.0.20c4c3ebdMerge pull request #454 from dtolnay/clippy2266152Suppress redundant_field_names clippy lint2901cfdRaise minimum tested compiler to rust 1.88aa9d91fUpdate ui tests for version 2.0.19e13a785Release 2.0.190a0e76cUpdate to syn 3ec42ea7Update actions/upload-artifact@v6 -> v74178c4aUpdate actions/checkout@v6 -> v77214e0eIgnore items_after_statements pedantic clippy lint in testUpdates
ulidfrom 1.2.1 to 3.0.0Commits
90992f5Bump version to v3.0.01d6ad4eEnable warn(keyword_idents) and replace gen usages82c545aFix wasm32 builda30176cCleanup in prep for release1af7ec8bump version to v2.0.013b3614Cleanup clippy warningsce49f86Add the ability for Generator to overflow5fe66d5Remove deprecated method4ac1cf7Rename Ulid::new -> Ulid::gen; add Ulid::max926ebfaUpdate rand to v0.10Updates
rusqlitefrom 0.31.0 to 0.40.2Release notes
Sourced from rusqlite's releases.
... (truncated)
Commits
e88f112Prepare released11c76eUpdate main.ymlc922ca5Lower MSRV to 1.88.06d3c282Merge pull request #1856 from gwenn/0.40.12ba28b7Prepare next releasea021dc7Merge pull request #1854 from gwenn/savepoint534a149Merge pull request #1855 from gwenn/hashlink6d9764fBump hashlink versionfa574ebUsesqlite3_keyword_check15385ccFix SQL injection when SAVEPOINT name is taintedUpdates
clapfrom 4.6.4 to 4.6.6Release notes
Sourced from clap's releases.
Changelog
Sourced from clap's changelog.
Commits
348cff3chore: Released478377docs: Update changelog04b9fbbMerge pull request #6414 from koopatroopa787/fix-bash-completion-bracket-glob7075239Merge pull request #6422 from BaumiCoder/fix-fish-indentationsf90a966fix(complete): Use spaces for indentation in fishdd4997bfix(complete): Don't glob-expand bash positionals8387c81Merge pull request #6399 from clap-rs/renovate/crate-ci-typos-1.x8141e11chore(deps): Update compatible (dev) (#6398)8a6bd4echore(deps): Update pre-commit hook crate-ci/typos to v1.47.071a7213chore(deps): Update Rust Stable to v1.96 (#6396)Updates
quick-xmlfrom 0.36.2 to 0.41.0Release notes
Sourced from quick-xml's releases.
... (truncated)
Changelog
Sourced from quick-xml's changelog.
... (truncated)
Commits
4deda08Release 0.41.01b3b73bRemove unused argument tocheck!07f3db8Fix O(N²) duplicate-attribute check inAttributesiterator7ca2526Cap namespace declarations per element inNamespaceResolver::push9aaea92Release 0.40.1ce488bcMerge pull request #964 from williamareynolds/fix/de-doctype-in-text-unreachablee00ae5cFix unreachable!() panic when DOCTYPE appears between text runs in element co...2778564Release 0.40.0393db03Merge pull request #962 from Mingun/prepare-0.40a27709aFix misprint in code exampleUpdates
lz4_flexfrom 0.11.6 to 0.14.0Release notes
Sourced from lz4_flex's releases.
Changelog
Sourced from lz4_flex's changelog.
... (truncated)
Commits
1bffdcbMerge pull request #229 from PSeitz/release/0.14.0-changeloga5973e4Update CHANGELOG for 0.14.0 release, bump version to 0.14.043cdb22Merge pull request #228 from PSeitz/0.14.x08fd47eadd release skilla6c6135Merge pull request #225 from fbrozovic/alloc-featureca019ecAdd alloc feature to support no_std without an allocator19194f9Merge pull request #223 from PSeitz/0.13.x5a1962cupdate CHANGELOGce548abfix: handle short compression dictionaries1756d13Fix panic in From<io::Error> implementation for frame::ErrorUpdates
dirsfrom 5.0.1 to 6.0.0Commits
Updates
tomlfrom 0.8.23 to 1.1.4+spec-1.1.0Commits
beee9fechore: Release16e2ac1docs: Update changelog89f5541fix(toml): preserve datetimes when deserializing Value (#1194)534039cfix(serde): Deserialize Value datetimes into typed targets6e45ceftest(serde): Reproduce Value datetime deserialization error4ec099fchore: Release5a47a51docs: Update changelogda0911fperf(parser): Reduce over allocation by better tokens/byte ratio (#1193)26eb157perf(parser): Reduce over allocation by better tokens/byte ratioca4c7bfchore(deps): Update Prek to v0.4.11 (#1191)Updates
ratatuifrom 0.28.1 to 0.30.2Release notes
Sourced from ratatui's releases.
... (truncated)
Changelog
Sourced from ratatui's changelog.
... (truncated)
Commits
e665c36chore(ratatui): unleash the rats v0.30.2 (#2581)2700b16docs(changelog): update changelog for 0.30.2 (#2608)e306ce6fix(buffer): create updates for "uncovered" cells (#2587)81e667ffix(scrollbar): keep a large thumb within the track at the end (#2594)c75d778chore(ci): add cargo-udeps dependency check (#2599)25314d8build(deps): bump release-plz/action from 0.5.129 to 0.5.130 (#2600)3534070build(deps): bump taiki-e/install-action from 2.81.8 to 2.81.10 (#2601)a798a13build(deps): bump tombi-toml/setup-tombi from 1.1.2 to 1.1.3 (#2602)3ac8850build(deps): bump octocrab from 0.52.0 to 0.53.1 (#2603)9c79633build(deps): bump time from 0.3.47 to 0.3.49 (#2604)Updates
crosstermfrom 0.28.1 to 0.29.0Release notes
Sourced from crossterm's releases.
Changelog
Sourced from crossterm's changelog.
Commits