Skip to content

chore(deps): bump the rust-security group across 1 directory with 10 updates - #10

Merged
David Mireles (louzt) merged 2 commits into
mainfrom
dependabot/cargo/rust-security-76e0833681
Aug 15, 2026
Merged

David Mireles (louzt) merged 2 commits into
mainfrom
dependabot/cargo/rust-security-76e0833681

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 13, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the rust-security group with 10 updates in the / directory:

Package From To
thiserror 1.0.69 2.0.20
ulid 1.2.1 3.0.0
rusqlite 0.31.0 0.40.2
clap 4.6.4 4.6.6
quick-xml 0.36.2 0.41.0
lz4_flex 0.11.6 0.14.0
dirs 5.0.1 6.0.0
toml 0.8.23 1.1.4+spec-1.1.0
ratatui 0.28.1 0.30.2
crossterm 0.28.1 0.29.0

Updates thiserror from 1.0.69 to 2.0.20

Release notes

Sourced from thiserror's releases.

2.0.20

  • Suppress redundant_field_names clippy lint in generated code (#454)

2.0.19

  • Update to syn 3

2.0.18

2.0.17

  • Use differently named __private module per patch release (#434)

2.0.16

  • Add to "no-std" crates.io category (#429)

2.0.15

  • Prevent Error::provide API becoming unavailable from a future new compiler lint (#427)

2.0.14

  • Allow build-script cleanup failure with NFSv3 output directory to be non-fatal (#426)

2.0.13

  • Documentation improvements

2.0.12

  • Prevent elidable_lifetime_names pedantic clippy lint in generated impl (#413)

2.0.11

2.0.10

  • Support errors containing a generic type parameter's associated type in a field (#408)

2.0.9

  • Work around missing_inline_in_public_items clippy restriction being triggered in macro-generated code (#404)

2.0.8

  • Improve support for macro-generated derive(Error) call sites (#399)

2.0.7

  • Work around conflict with #[deny(clippy::allow_attributes)] (#397, thanks @​zertosh)

2.0.6

  • Suppress deprecation warning on generated From impls (#396)

2.0.5

  • Prevent deprecation warning on generated impl for deprecated type (#394)

2.0.4

  • Eliminate needless_lifetimes clippy lint in generated From impls (#391, thanks @​matt-phylum)

... (truncated)

Commits
  • b1d5db5 Release 2.0.20
  • c4c3ebd Merge pull request #454 from dtolnay/clippy
  • 2266152 Suppress redundant_field_names clippy lint
  • 2901cfd Raise minimum tested compiler to rust 1.88
  • aa9d91f Update ui tests for version 2.0.19
  • e13a785 Release 2.0.19
  • 0a0e76c Update to syn 3
  • ec42ea7 Update actions/upload-artifact@v6 -> v7
  • 4178c4a Update actions/checkout@v6 -> v7
  • 7214e0e Ignore items_after_statements pedantic clippy lint in test
  • Additional commits viewable in compare view

Updates ulid from 1.2.1 to 3.0.0

Commits
  • 90992f5 Bump version to v3.0.0
  • 1d6ad4e Enable warn(keyword_idents) and replace gen usages
  • 82c545a Fix wasm32 build
  • a30176c Cleanup in prep for release
  • 1af7ec8 bump version to v2.0.0
  • 13b3614 Cleanup clippy warnings
  • ce49f86 Add the ability for Generator to overflow
  • 5fe66d5 Remove deprecated method
  • 4ac1cf7 Rename Ulid::new -> Ulid::gen; add Ulid::max
  • 926ebfa Update rand to v0.10
  • Additional commits viewable in compare view

Updates rusqlite from 0.31.0 to 0.40.2

Release notes

Sourced from rusqlite's releases.

0.40.2

What's Changed

  • Lower MSRV to 1.88.0

Full Changelog: rusqlite/rusqlite@v0.40.1...v0.40.2

0.40.1

What's Changed

  • Fix clippy warnings #1852
  • Bump bundled SQLite version to 3.53.2 #1853
  • Bump hashlink version #1855
  • Fix SQL injection when SAVEPOINT name is tainted #1854

Full Changelog: rusqlite/rusqlite@v0.40.0...v0.40.1

0.40.0

What's Changed

  • Breaking changes: Replace VTab macros by constructors #1823
  • Breaking changes: Fix VTab::best_index #1824
  • Asserts on VTab::connect aux and args #1825
  • Breaking changes: Fix VTab::connect / create #1826
  • Breaking changes: Allow opting out of using sqlite-wasm-rs on wasm32-unknown-unknown #1828, #1829
  • Derive Default for SeriesTabCursor/ArrayTabCursor #1830
  • Update link to pre-update hook #1831
  • Breaking changes: Fix VTab::connect #1832
  • impl From for FromSqlError #1833
  • Breaking changes: Fix vtab::dequote #1835
  • Bump bundled SQLCipher to version 4.14.0 #1837
  • sqlite3_set_errmsg #1752
  • Bump sqlite3-parser version #1838
  • Fix UB in ToSqlOutput::from_rc #1839
  • Ensure miri doesn't complain #1840
  • Bump to actions/checkout@v6 #1842
  • Add support to UtcDateTime #1843, #1844
  • Bump bundled SQLite version to 3.53.1 #1848
  • Replace some cfg(not by cfg_select #1850

Full Changelog: rusqlite/rusqlite@v0.39.0...v0.40.0

0.39.0

What's Changed

  • Fix constraints on VTab Aux data #1778, #1771
  • Fix docs.rs generation #1779
  • Fix a small typo in rollback_hook docstring #1780
  • Fix some warnings from Intellij #1781
  • Minimal doc for features #1783
  • Clear hooks only for owning connections #1785, #1784
  • Fix link to SQLite C Interface, Prepare Flags #1787
  • Comment functions which are not usable from a loadable extension #1789
  • Factorize code #1792

... (truncated)

Commits

Updates clap from 4.6.4 to 4.6.6

Release notes

Sourced from clap's releases.

v4.6.6

[4.6.6] - 2026-08-06

Features

  • Add Command::get_overridden_usage

v4.6.5

[4.6.5] - 2026-07-31

Fixes

  • (help) Correctly mark which value_names are optional with num_args
Changelog

Sourced from clap's changelog.

[4.6.6] - 2026-08-06

Features

  • Add Command::get_overridden_usage

[4.6.5] - 2026-07-31

Fixes

  • (help) Correctly mark which value_names are optional with num_args
Commits
  • 348cff3 chore: Release
  • d478377 docs: Update changelog
  • 04b9fbb Merge pull request #6414 from koopatroopa787/fix-bash-completion-bracket-glob
  • 7075239 Merge pull request #6422 from BaumiCoder/fix-fish-indentations
  • f90a966 fix(complete): Use spaces for indentation in fish
  • dd4997b fix(complete): Don't glob-expand bash positionals
  • 8387c81 Merge pull request #6399 from clap-rs/renovate/crate-ci-typos-1.x
  • 8141e11 chore(deps): Update compatible (dev) (#6398)
  • 8a6bd4e chore(deps): Update pre-commit hook crate-ci/typos to v1.47.0
  • 71a7213 chore(deps): Update Rust Stable to v1.96 (#6396)
  • Additional commits viewable in compare view

Updates quick-xml from 0.36.2 to 0.41.0

Release notes

Sourced from quick-xml's releases.

v0.41.0 - Secuirity fixes

What's Changed

New Features

  • #970: Add NsReader::resolver_mut() and NamespaceResolver::{max_declarations_per_element, set_max_declarations_per_element}.

Bug Fixes

  • #969: Attributes (and anything that iterates BytesStart::attributes() with the default with_checks(true)) no longer takes O(N²) time on a start tag with a large number of attributes. Small tags keep the previous linear scan; larger ones switch to a 64-bit hash pre-filter, so the whole tag is O(N). The exact AttrError::Duplicated(new, prev) positions are unchanged.
  • #970: NamespaceResolver::push (and hence every NsReader Start/Empty event) now rejects a start tag that declares more than DEFAULT_MAX_DECLARATIONS_PER_ELEMENT (256) xmlns / xmlns:* namespace bindings, returning the new NamespaceError::TooManyDeclarations. Previously push allocated one NamespaceBinding per declaration with no upper bound, before the event was returned to the caller, so an NsReader consumer could not bound its memory exposure on untrusted input. The limit is configurable via NamespaceResolver::set_max_declarations_per_element (use usize::MAX to disable).

#969: tafia/quick-xml#969 #970: tafia/quick-xml#970

New Contributors

Full Changelog: tafia/quick-xml@v0.40.1...v0.41.0

v0.40.1 - Fix rarely possible serde deserialization panic

What's Changed

  • #964: Fix unreachable!() panic in the serde deserializer when a DOCTYPE declaration appears between two text runs inside an element (e.g. <a>x<!DOCTYPE y>z</a>). The DOCTYPE used to break drain_text's consecutive-text merge, so two DeEvent::Text events reached read_text and tripped its "Cannot be two consequent Text events" invariant. DOCTYPE is now treated as transparent during text drain — it still goes through the entity resolver, but the surrounding text is merged into one run. Discovered via libFuzzer on a real-world SAML deserializer harness.

#964: tafia/quick-xml#964

New Contributors

Full Changelog: tafia/quick-xml@v0.40.0...v0.40.1

v0.40.0 - UTF-16 and ISO-2022-JP encodings supported

What's Changed

MSRV bumped to 1.79.

Now quick-xml supports the UTF-16 and ISO-2022-JP encoded documents. See the new DecodingReader type.

New Features

  • #956: Add DecodingReader, a BufRead adapter that auto-detects encoding from BOM or XML declaration and transcodes to UTF-8. Enabled by the encoding feature.
  • #938: Add new enumeration XmlVersion and typified getter BytesDecl::xml_version().
  • #938: Add new error variant IllFormedError::UnknownVersion.
  • #371: Add new error variant EscapeError::TooManyNestedEntities.
  • #371: Improved compliance with the XML attribute value normalization process by adding
    • Attribute::normalized_value()
    • Attribute::normalized_value_with()
    • Attribute::decoded_and_normalized_value()
    • Attribute::decoded_and_normalized_value_with()

... (truncated)

Changelog

Sourced from quick-xml's changelog.

0.41.0 -- 2026-06-29

New Features

  • #970: Add NsReader::resolver_mut() and NamespaceResolver::{max_declarations_per_element, set_max_declarations_per_element}.

Bug Fixes

  • #969: Attributes (and anything that iterates BytesStart::attributes() with the default with_checks(true)) no longer takes O(N²) time on a start tag with a large number of attributes. Small tags keep the previous linear scan; larger ones switch to a 64-bit hash pre-filter, so the whole tag is O(N). The exact AttrError::Duplicated(new, prev) positions are unchanged.
  • #970: NamespaceResolver::push (and hence every NsReader Start/Empty event) now rejects a start tag that declares more than 256 xmlns / xmlns:* namespace bindings, returning the new NamespaceError::TooManyDeclarations. Previously push allocated one NamespaceBinding per declaration with no upper bound, before the event was returned to the caller, so an NsReader consumer could not bound its memory exposure on untrusted input. The limit is configurable via NamespaceResolver::set_max_declarations_per_element (use usize::MAX to disable).

#969: tafia/quick-xml#969 #970: tafia/quick-xml#970

0.40.1 -- 2026-05-15

Bug Fixes

  • #964: Fix unreachable!() panic in the serde deserializer when a DOCTYPE declaration appears between two text runs inside an element (e.g. <a>x<!DOCTYPE y>z</a>). The DOCTYPE used to break drain_text's consecutive-text merge, so two DeEvent::Text events reached read_text and tripped its "Cannot be two consequent Text events" invariant. DOCTYPE is now treated as transparent during text drain — it still goes through the entity resolver, but the surrounding text is merged into one run. Discovered via libFuzzer on a real-world SAML deserializer harness.

#964: tafia/quick-xml#964

0.40.0 -- 2026-05-11

MSRV bumped to 1.79.

Now quick-xml supports UTF-16 encoded documents. See the new DecodingReader type.

New Features

... (truncated)

Commits
  • 4deda08 Release 0.41.0
  • 1b3b73b Remove unused argument to check!
  • 07f3db8 Fix O(N²) duplicate-attribute check in Attributes iterator
  • 7ca2526 Cap namespace declarations per element in NamespaceResolver::push
  • 9aaea92 Release 0.40.1
  • ce488bc Merge pull request #964 from williamareynolds/fix/de-doctype-in-text-unreachable
  • e00ae5c Fix unreachable!() panic when DOCTYPE appears between text runs in element co...
  • 2778564 Release 0.40.0
  • 393db03 Merge pull request #962 from Mingun/prepare-0.40
  • a27709a Fix misprint in code example
  • Additional commits viewable in compare view

Updates lz4_flex from 0.11.6 to 0.14.0

Release notes

Sourced from lz4_flex's releases.

0.13.1

What's Changed

New Contributors

Full Changelog: PSeitz/lz4_flex@0.13.0...0.13.1

0.13.0

What's Changed

New Contributors

Full Changelog: PSeitz/lz4_flex@0.12.0...0.13.0

0.12.0

What's Changed

New Contributors

Full Changelog: PSeitz/lz4_flex@0.11.5...0.12.0

Changelog

Sourced from lz4_flex's changelog.

0.14.0 (2026-07-14)

Features

  • Add alloc feature to allow no_std operation without an allocator. The std feature now implies alloc. Without alloc only the _into variants of the block API are available, e.g. compress_into; the compression hash table is placed on the stack or can be provided via compress_into_with_table.
Note: Users with `default-features = false` need to additionally enable the `alloc`
feature to keep the APIs returning `Vec`, e.g. `compress` and `decompress`.

0.13.1 (2026-05-09)

Fixes

  • Fix compression with short dictionaries (less than 4 bytes), avoiding a panic/out-of-bounds read #222
Compression with dictionaries shorter than the minimum match length of 4 now falls
back to compression without a dictionary instead of panicking or reading past
the dictionary. 

This is a security fix for unsafe compression with untrusted dictionaries.
Users on 0.13.0 should upgrade to 0.13.1.

  • Fix panic in From<io::Error> implementation for frame::Error #221 (thanks @​phoerious)

0.13.0 (2026-03-15)

Features

Fixes

Invalid match offsets (offset == 0) during decompression were not properly
handled, which could lead to invalid memory reads. This is a security fix
that was also backported to 0.12.1 and 0.11.6.
  • Fix get_maximum_output_size overflow on 32-bit targets #205 (thanks @​dglittle)
Cast input_len to u64 before multiplying by 110, avoiding overflow on
32-bit targets (e.g. wasm32) where input_len * 110 overflows usize
when input_len > ~39MB.

0.12.2 (2026-05-09)

Fixes

  • Fix compression with short dictionaries (less than 4 bytes), avoiding a panic/out-of-bounds read #222
Compression with dictionaries shorter than the minimum match length of 4 now falls
back to compression without a dictionary instead of panicking or reading past
the dictionary. 
</tr></table> 

... (truncated)

Commits
  • 1bffdcb Merge pull request #229 from PSeitz/release/0.14.0-changelog
  • a5973e4 Update CHANGELOG for 0.14.0 release, bump version to 0.14.0
  • 43cdb22 Merge pull request #228 from PSeitz/0.14.x
  • 08fd47e add release skill
  • a6c6135 Merge pull request #225 from fbrozovic/alloc-feature
  • ca019ec Add alloc feature to support no_std without an allocator
  • 19194f9 Merge pull request #223 from PSeitz/0.13.x
  • 5a1962c update CHANGELOG
  • ce548ab fix: handle short compression dictionaries
  • 1756d13 Fix panic in From<io::Error> implementation for frame::Error
  • Additional commits viewable in compare view

Updates dirs from 5.0.1 to 6.0.0

Commits

Updates toml from 0.8.23 to 1.1.4+spec-1.1.0

Commits
  • beee9fe chore: Release
  • 16e2ac1 docs: Update changelog
  • 89f5541 fix(toml): preserve datetimes when deserializing Value (#1194)
  • 534039c fix(serde): Deserialize Value datetimes into typed targets
  • 6e45cef test(serde): Reproduce Value datetime deserialization error
  • 4ec099f chore: Release
  • 5a47a51 docs: Update changelog
  • da0911f perf(parser): Reduce over allocation by better tokens/byte ratio (#1193)
  • 26eb157 perf(parser): Reduce over allocation by better tokens/byte ratio
  • ca4c7bf chore(deps): Update Prek to v0.4.11 (#1191)
  • Additional commits viewable in compare view

Updates ratatui from 0.28.1 to 0.30.2

Release notes

Sourced from ratatui's releases.

ratatui-v0.30.2

a gift

We are excited to announce the new version of ratatui - a Rust library that's all about cooking up TUIs 👨‍🍳🐀

✨ Release highlights: https://ratatui.rs/highlights/v0302/

⚠️ List of breaking changes can be found here.

Features

  • 90639c1 (uncategorized) Add Termina backend by @joshka in #2561

    Summary

    • add the ratatui-termina backend crate using the published termina crate
    • expose the backend through the termina feature and Ratatui prelude/backend re-exports
    • add a small Termina event-loop example and wire the backend into CI, xtask, README generation, and docs

    Refs #1784

    Validation

    • cargo +nightly fmt
    • cargo check -p ratatui-termina --all-features --all-targets
    • cargo check -p ratatui --no-default-features --features termina
    • cargo check -p xtask
    • cargo check -p release-header
    • cargo xtask check-backend termina
    • cargo xtask test-backend termina
    • cargo xtask rdme --check
    • markdownlint-cli2 ARCHITECTURE.md ratatui-termina/README.md .github/ISSUE_TEMPLATE/bug_report.md

Bug Fixes

  • fce3c80 (widgets) Require thread-safe shadow effects by @joshka in #2584

    Summary

    • require custom shadow effects to preserve the auto traits expected by Block-backed widgets
    • document the CellEffect auto-trait contract
    • add a public widget regression test for the affected ratatui::widgets re-exports

... (truncated)

Changelog

Sourced from ratatui's changelog.

0.30.2 - 2026-06-19

a gift

We are excited to announce the new version of ratatui - a Rust library that's all about cooking up TUIs 👨‍🍳🐀

✨ Release highlights: https://ratatui.rs/highlights/v0302/

⚠️ List of breaking changes can be found here.

Features

  • 90639c1 (uncategorized) Add Termina backend by @joshka in #2561

    Summary

    • add the ratatui-termina backend crate using the published termina crate
    • expose the backend through the termina feature and Ratatui prelude/backend re-exports
    • add a small Termina event-loop example and wire the backend into CI, xtask, README generation, and docs

    Refs #1784

    Validation

    • cargo +nightly fmt
    • cargo check -p ratatui-termina --all-features --all-targets
    • cargo check -p ratatui --no-default-features --features termina
    • cargo check -p xtask
    • cargo check -p release-header
    • cargo xtask check-backend termina
    • cargo xtask test-backend termina
    • cargo xtask rdme --check
    • markdownlint-cli2 ARCHITECTURE.md ratatui-termina/README.md .github/ISSUE_TEMPLATE/bug_report.md

Bug Fixes

  • fce3c80 (widgets) Require thread-safe shadow effects by @joshka in #2584

    Summary

    • require custom shadow effects to preserve the auto traits expected by Block-backed widgets
    • document the CellEffect auto-trait contract
    • add a public widget regression test for the affected ratatui::widgets

... (truncated)

Commits
  • e665c36 chore(ratatui): unleash the rats v0.30.2 (#2581)
  • 2700b16 docs(changelog): update changelog for 0.30.2 (#2608)
  • e306ce6 fix(buffer): create updates for "uncovered" cells (#2587)
  • 81e667f fix(scrollbar): keep a large thumb within the track at the end (#2594)
  • c75d778 chore(ci): add cargo-udeps dependency check (#2599)
  • 25314d8 build(deps): bump release-plz/action from 0.5.129 to 0.5.130 (#2600)
  • 3534070 build(deps): bump taiki-e/install-action from 2.81.8 to 2.81.10 (#2601)
  • a798a13 build(deps): bump tombi-toml/setup-tombi from 1.1.2 to 1.1.3 (#2602)
  • 3ac8850 build(deps): bump octocrab from 0.52.0 to 0.53.1 (#2603)
  • 9c79633 build(deps): bump time from 0.3.47 to 0.3.49 (#2604)
  • Additional commits viewable in compare view

Updates crossterm from 0.28.1 to 0.29.0

Release notes

Sourced from crossterm's releases.

0.29

Version 0.29

Added ⭐

  • Copy to clipboard using OSC52 (#974)
  • Derive standard traits for "SetCursorStyle" (#909)
  • Add query_keyboard_enhancement_flags to read enabled flags (#958)
  • Add is_* and as_* methods to the event enums (#949)
  • Add a feature flag for derive_more impls (#970)
  • Update rustix to 1.0 (#982)
  • Upgrade various dependencies

Breaking ⚠️

  • Correctly fix KeyModifiers Display impl Properly adding + in between modifiers (#979)

@​joshka @​linrongbin16 @​kmicklas @​maciek50322 @​rosew0od @​sxyazi @​the-mikedavis @​hthuz @​aschey @​naseschwarz @​Flokkq @​gaesa @​WindSoilder

Changelog

Sourced from crossterm's changelog.

Unreleased

Breaking ⚠️

  • Raise the minimum supported Rust version from 1.63 to 1.85.
  • Remove IsTty trait. Use the standard library's std::io::IsTerminal trait instead, which provides equivalent functionality.

Changed ⚙️

  • Migrate the crate to the Rust 2024 edition. This does not raise the MSRV beyond Rust 1.85.

Fixed 🐛

  • Fix color commands emitting a bare CSI m when colors are disabled via NO_COLOR, which reset every attribute instead of doing nothing. Affects SetForegroundColor, SetBackgroundColor, SetUnderlineColor, and SetColors.
  • Fix integer underflow in mouse / cursor-position parsers when coord bytes encoded the protocol origin (panic in debug, wrap to 65535 in release). Affects parse_csi_normal_mouse, parse_csi_rxvt_mouse, parse_csi_sgr_mouse, and parse_csi_cursor_position.
  • Fix Colors::from(Colored::UnderlineColor(_)) setting the background color. Colors has no underline field, so the color is now dropped instead of being applied to the background.

Version 0.29

Added ⭐

  • Copy to clipboard using OSC52 (#974)
  • Derive standard traits for "SetCursorStyle" (#909)
  • Add query_keyboard_enhancement_flags to read enabled flags (#958)
  • Add is_* and as_* methods to the event enums (#949)
  • Add a feature flag for derive_more impls (#970)
  • Update rustix to 1.0 (#982)

Breaking ⚠️

  • Correctly fix KeyModifiers Display impl Properly adding + in between modifiers (#979)
Commits

@dependabot dependabot Bot added area:core Touches `linkmarks-core` (model, traits, canonical, dedupe). chore Build, tooling, dependency, or housekeeping change. labels Aug 13, 2026
@dependabot
dependabot Bot force-pushed the dependabot/cargo/rust-security-76e0833681 branch from 48f4bab to 55cca69 Compare August 15, 2026 09:03
David Mireles (louzt) added a commit that referenced this pull request Aug 15, 2026
cargo fmt --all across the workspace. This is the F2.5 fmt cleanup that
was tracked in MANIFEST-2026-08-07-linkmarks-fase2-batch.md §Known caveats
#1 ('cargo fmt --check not 100% clean — 56 pre-existing hunks of drift in
F1–F4 .rs files').

Required to unblock Dependabot PR #10 (rust-security group bump), whose
CI was failing not on its own changes (Cargo.toml/Cargo.lock only) but on
the fmt drift in render_test.rs / input_test.rs etc. that pre-dated
Dependabot's branch.

Pure formatting — no semantic changes. Verified:
- cargo build --workspace --all-targets — clean
- cargo test --workspace --no-fail-fast — 250/250 green
- cargo clippy --workspace --all-targets -- -D warnings — clean
- cargo fmt --all -- --check — clean (exit 0)
@louzt

louzt commented Aug 15, 2026

Copy link
Copy Markdown
Contributor

Dependabot (@dependabot) rebase

1 similar comment
@louzt

louzt commented Aug 15, 2026

Copy link
Copy Markdown
Contributor

Dependabot (@dependabot) rebase

@dependabot
dependabot Bot force-pushed the dependabot/cargo/rust-security-76e0833681 branch from 55cca69 to de98a1d Compare August 15, 2026 09:12
@louzt

louzt commented Aug 15, 2026

Copy link
Copy Markdown
Contributor

Dependabot (@dependabot) recreate

…updates

Bumps the rust-security group with 10 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [thiserror](https://github.com/dtolnay/thiserror) | `1.0.69` | `2.0.20` |
| [ulid](https://github.com/dylanhart/ulid-rs) | `1.2.1` | `3.0.0` |
| [rusqlite](https://github.com/rusqlite/rusqlite) | `0.31.0` | `0.40.2` |
| [clap](https://github.com/clap-rs/clap) | `4.6.4` | `4.6.6` |
| [quick-xml](https://github.com/tafia/quick-xml) | `0.36.2` | `0.41.0` |
| [lz4_flex](https://github.com/pseitz/lz4_flex) | `0.11.6` | `0.14.0` |
| [dirs](https://github.com/soc/dirs-rs) | `5.0.1` | `6.0.0` |
| [toml](https://github.com/toml-rs/toml) | `0.8.23` | `1.1.4+spec-1.1.0` |
| [ratatui](https://github.com/ratatui/ratatui) | `0.28.1` | `0.30.2` |
| [crossterm](https://github.com/crossterm-rs/crossterm) | `0.28.1` | `0.29.0` |



Updates `thiserror` from 1.0.69 to 2.0.20
- [Release notes](https://github.com/dtolnay/thiserror/releases)
- [Commits](dtolnay/thiserror@1.0.69...2.0.20)

Updates `ulid` from 1.2.1 to 3.0.0
- [Commits](dylanhart/ulid-rs@v1.2.1...v3.0.0)

Updates `rusqlite` from 0.31.0 to 0.40.2
- [Release notes](https://github.com/rusqlite/rusqlite/releases)
- [Changelog](https://github.com/rusqlite/rusqlite/blob/master/Changelog.md)
- [Commits](rusqlite/rusqlite@v0.31.0...v0.40.2)

Updates `clap` from 4.6.4 to 4.6.6
- [Release notes](https://github.com/clap-rs/clap/releases)
- [Changelog](https://github.com/clap-rs/clap/blob/master/CHANGELOG.md)
- [Commits](clap-rs/clap@clap_complete-v4.6.4...clap_complete-v4.6.6)

Updates `quick-xml` from 0.36.2 to 0.41.0
- [Release notes](https://github.com/tafia/quick-xml/releases)
- [Changelog](https://github.com/tafia/quick-xml/blob/master/Changelog.md)
- [Commits](tafia/quick-xml@v0.36.2...v0.41.0)

Updates `lz4_flex` from 0.11.6 to 0.14.0
- [Release notes](https://github.com/pseitz/lz4_flex/releases)
- [Changelog](https://github.com/PSeitz/lz4_flex/blob/main/CHANGELOG.md)
- [Commits](PSeitz/lz4_flex@0.11.6...0.14.0)

Updates `dirs` from 5.0.1 to 6.0.0
- [Commits](https://github.com/soc/dirs-rs/commits)

Updates `toml` from 0.8.23 to 1.1.4+spec-1.1.0
- [Commits](toml-rs/toml@toml-v0.8.23...toml-v1.1.4)

Updates `ratatui` from 0.28.1 to 0.30.2
- [Release notes](https://github.com/ratatui/ratatui/releases)
- [Changelog](https://github.com/ratatui/ratatui/blob/main/CHANGELOG.md)
- [Commits](ratatui/ratatui@v0.28.1...ratatui-v0.30.2)

Updates `crossterm` from 0.28.1 to 0.29.0
- [Release notes](https://github.com/crossterm-rs/crossterm/releases)
- [Changelog](https://github.com/crossterm-rs/crossterm/blob/master/CHANGELOG.md)
- [Commits](https://github.com/crossterm-rs/crossterm/commits/0.29)

---
updated-dependencies:
- dependency-name: clap
  dependency-version: 4.6.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-security
- dependency-name: crossterm
  dependency-version: 0.29.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-security
- dependency-name: dirs
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: rust-security
- dependency-name: lz4_flex
  dependency-version: 0.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-security
- dependency-name: quick-xml
  dependency-version: 0.41.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-security
- dependency-name: ratatui
  dependency-version: 0.30.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-security
- dependency-name: rusqlite
  dependency-version: 0.40.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-security
- dependency-name: thiserror
  dependency-version: 2.0.20
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: rust-security
- dependency-name: toml
  dependency-version: 1.1.4+spec-1.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: rust-security
- dependency-name: ulid
  dependency-version: 3.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: rust-security
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/cargo/rust-security-76e0833681 branch from de98a1d to ee1087d Compare August 15, 2026 09:14
Two breaking changes from Dependabot's rust-security group bump
landed in CI but did not compile against the v0.36 / 1.x code paths.

1. **ulid 1.x → 3.x** — `Ulid::new()` removed; the constructor is now
   `Ulid::generate()` (the previous free function on `Ulid`) which
   returns `Self` rather than `Result`. Updated the single call
   site in `crates/linkmarks-core/src/model.rs:23`.

2. **quick-xml 0.36 → 0.41** — character references (`&amp;`, `&#160;`,
   `&aacute;` …) are now emitted as a separate `Event::GeneralRef`
   rather than being folded into the surrounding `Event::Text`. The
   previous exhaustive match on `Start/End/Text/Empty/...`
   therefore stopped compiling.

   The new handler decodes the entity body bytes through the same
   `resolve_entity` / `decode_numeric_entity` helpers that the
   text path uses. The full set of HTML5 named entities
   (`&amp;`, `&aacute;`, …) plus numeric refs (`&#NN;`,
   `&#xNN;`) is preserved.

   One subtle behavioural correction falls out of this work:
   previously, both `handle_text` and the new `GeneralRef` arm
   inserted a single ASCII space as a 'separator' before each
   non-empty text chunk. With quick-xml 0.36 this was a no-op for
   the common case because each text chunk was already self-
   contained (decoded entities folded in). With quick-xml 0.41 a
   single logical text chunk is now broken into
   `Text"AT" + GeneralRef& + Text"T"` for an input like
   `AT&amp;T`, and the separator logic produced "AT & T"
   instead of the expected "AT&T". The fix is to drop the
   separator: the contents of a single `<A>` title is one
   contiguous string and must not have artificial padding between
   events.

A separate clippy nit was folded in: `&**text` triggered
`explicit-auto-deref` under Rust 1.97; the type-annotated binding
`let raw_bytes: &[u8] = text;` reads cleanly via `Deref`.

`attr.unescape_value()` is deprecated in quick-xml 0.41 (in
favour of `normalized_value`), but the deprecation note explicitly
says it only fires when the `encoding` feature is OFF — our case
(we only enable `serialize`). The replacement `normalized_value`
additionally applies XML attribute-value normalization (whitespace
collapsing), which would corrupt URLs that legitimately contain
multiple spaces, so we `#[allow(deprecated)]` on that single call
site and document the rationale.

Validation:
- `cargo test --workspace --no-fail-fast` → 250/250 green.
- `cargo clippy --workspace --all-targets -- -D warnings` → clean.
- `cargo fmt --all -- --check` → clean.

Refs: #10
@louzt
David Mireles (louzt) merged commit ab4748f into main Aug 15, 2026
2 checks passed
@louzt
David Mireles (louzt) deleted the dependabot/cargo/rust-security-76e0833681 branch August 15, 2026 15:13
David Mireles (louzt) added a commit that referenced this pull request Aug 15, 2026
Bumps workspace version 2.0.0 → 2.0.1 and adds CHANGELOG entry covering
the 10 dep updates that landed in PR #10 (thiserror 1→2, ulid 1→3,
dirs 5→6, toml 0.8→1.1, ratatui 0.28→0.30, crossterm 0.28→0.29,
rusqlite 0.31→0.40, lz4_flex 0.11→0.14, clap 4.6.4→4.6.6,
quick-xml 0.36→0.41) plus the manual fix-up commits:

- ulid 1.x→3.x API change (Ulid::new() → Ulid::generate())
- quick-xml 0.36→0.41 Event::GeneralRef handler with proper
  entity decoding and separator-removal for AT&amp;T round-trip
- clippy explicit-auto-deref cleanup under Rust 1.97

All 250 tests green; clippy + fmt clean; CI smoke green on PR #10.

Refs: #10

louzt <davidmirelesll@outlook.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:core Touches `linkmarks-core` (model, traits, canonical, dedupe). chore Build, tooling, dependency, or housekeeping change.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant