Bump the cargo group across 1 directory with 7 updates
Type: Pull Request
State: Open
![dependabot[bot]](https://github.com/dependabot.png)
Association: Contributor
Comments: 0
(12 days ago)
(12 days ago)
🤖 dependabot
Bumps the cargo group with 7 updates in the / directory:
Package | From | To |
---|---|---|
clap | 4.5.45 |
4.5.46 |
config | 0.15.14 |
0.15.15 |
percent-encoding | 2.3.1 |
2.3.2 |
serde_json | 1.0.142 |
1.0.143 |
thiserror | 2.0.15 |
2.0.16 |
tracing-subscriber | 0.3.19 |
0.3.20 |
tempfile | 3.20.0 |
3.21.0 |
Updates clap
from 4.5.45 to 4.5.46
Release notes
Sourced from clap's releases.
v4.5.46
[4.5.46] - 2025-08-26
Features
- Expose
StyledStr::push_str
Commits
acf9abb
chore: Release9186a18
docs: Update changelog233c316
Merge pull request #5926 from sorairolake/feature/value-parser-factory-for-sa...13931a2
Merge pull request #5923 from Reverier-Xu/master536e29f
feat(builder): AddValueParserFactory
forSaturating\<T>
45ed71c
chore: Avoid using gen for rust 2024 preserved keyword5029bb3
chore: Avoid usinggen
for rust 2024 preserved keyword8a1d59b
chore(deps): Update Rust Stable to v1.85 (#5921)9caee53
docs(changelog): Clarify 5.0.0cb2352f
Merge pull request #5918 from epage/test- Additional commits viewable in compare view
Updates config
from 0.15.14 to 0.15.15
Changelog
Sourced from config's changelog.
[0.15.15] - 2025-08-29
Fixes
- (json5) Correctly deserialize
null
(regressed in 0.15.14)
Commits
3931f4c
chore: Release config version 0.15.151e85483
docs: Update changelog63ef7c7
fix(format): Correctly deserialize json5 (#690)ea823c1
fix(format): Correctly deserialize json5b4bc68f
test(format): Verify null where supported35bafb9
refactor(file): Minor clean up to file discovery (#688)e6e3fcf
fix(file): Switch error to user-facing termsdaf02c8
refactor(file): Clarify we are dealing with a path, not a namefd28355
refactor(format): Simplify extension mappingb154785
refactor(file): Pull out extension lookup- Additional commits viewable in compare view
Updates percent-encoding
from 2.3.1 to 2.3.2
Commits
- See full diff in compare view
Updates serde_json
from 1.0.142 to 1.0.143
Release notes
Sourced from serde_json's releases.
v1.0.143
- Implement Clone and Debug for serde_json::Map iterators (#1264, thanks
@​xlambein
)- Implement Default for CompactFormatter (#1268, thanks
@​SOF3
)- Implement FromStr for serde_json::Map (#1271, thanks
@​mickvangelderen
)
Commits
10102c4
Release 1.0.1432a5b853
Replace super::super with absolute path within crate447170b
Merge pull request 1271 from mickvangelderen/mick/impl-from-str-for-mapec190d6
Merge pull request #1264 from xlambein/master8be6647
Merge pull request #1268 from SOF3/compact-defaultba5b3cc
Revert "Pin nightly toolchain used for miri job"fd35a02
Implement FromStr for Map<String, Value>bea0fe6
Implement Default for CompactFormatter0c0e9f6
Add Clone and Debug impls to map iterators- See full diff in compare view
Updates thiserror
from 2.0.15 to 2.0.16
Commits
40b5853
Release 2.0.1683dfb5f
Merge pull request #429 from dtolnay/nostd9b4a99f
Add to "no-std" crates.io category- See full diff in compare view
Updates tracing-subscriber
from 0.3.19 to 0.3.20
Release notes
Sourced from tracing-subscriber's releases.
tracing-subscriber 0.3.20
Security Fix: ANSI Escape Sequence Injection (CVE-TBD)
Impact
Previous versions of tracing-subscriber were vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be injected into terminal output when logged, potentially allowing attackers to:
- Manipulate terminal title bars
- Clear screens or modify terminal display
- Potentially mislead users through terminal manipulation
In isolation, impact is minimal, however security issues have been found in terminal emulators that enabled an attacker to use ANSI escape sequences via logs to exploit vulnerabilities in the terminal emulator.
Solution
Version 0.3.20 fixes this vulnerability by escaping ANSI control characters in when writing events to destinations that may be printed to the terminal.
Affected Versions
All versions of tracing-subscriber prior to 0.3.20 are affected by this vulnerability.
Recommendations
Immediate Action Required: We recommend upgrading to tracing-subscriber 0.3.20 immediately, especially if your application:
- Logs user-provided input (form data, HTTP headers, query parameters, etc.)
- Runs in environments where terminal output is displayed to users
Migration
This is a patch release with no breaking API changes. Simply update your Cargo.toml:
[dependencies] tracing-subscriber = "0.3.20"
Acknowledgments
We would like to thank zefr0x who responsibly reported the issue at
security@tokio.rs
.If you believe you have found a security vulnerability in any tokio-rs project, please email us at
security@tokio.rs
.
Commits
4c52ca5
fmt: fix ANSI escape sequence injection vulnerability (#3368)f71cebe
subscriber: impl Clone for EnvFilter (#3360)3a1f571
Fix CI (#3361)e63ef57
chore: prepare tracing-attributes 0.1.30 (#3316)6e59a13
attributes: fix tracing::instrument regression around shadowing (#3311)e4df761
tracing: update core to 0.1.34 and attributes to 0.1.29 (#3305)643f392
chore: prepare tracing-attributes 0.1.29 (#3304)d08e7a6
chore: prepare tracing-core 0.1.34 (#3302)6e70c57
tracing-subscriber: count numbers of enters inTimings
(#2944)c01d4fd
fix docs and enable CI onmain
branch (#3295)- Additional commits viewable in compare view
Updates tempfile
from 3.20.0 to 3.21.0
Changelog
Sourced from tempfile's changelog.
3.21.0
- Updated
windows-sys
requirement to allow version 0.60.x
Commits
48bff5f
test(tempdir): configure tempdir on wasi704a1d2
test(tempdir): cleanup tempdir tests and run more tests on wasia0dc80d
Add Android CI target (#367)4ad1ae6
chore(release): release 3.21.03849edd
build(deps): bump actions/checkout from 4 to 5 (#368)0657fdf
build(deps): update windows-sys requirement <0.61 (#360)69b95c7
ci: fix was tests in CI (#361)- See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions
Pull Request Statistics
1
2
+33
-89
Package Dependencies
Technical Details
ID: | 6449516 |
UUID: | 2790933820 |
Node ID: | PR_kwDONZLcv86mWkU8 |
Host: | GitHub |
Repository: | joshuadavidthomas/django-language-server |
Merge State: | Unknown |