Skip to content

chore(deps): weekly safe cargo updates · 2 packages#3

Draft
mendral-app[bot] wants to merge 1 commit into
masterfrom
mendral/deps/weekly-safe-cargo-20260601
Draft

chore(deps): weekly safe cargo updates · 2 packages#3
mendral-app[bot] wants to merge 1 commit into
masterfrom
mendral/deps/weekly-safe-cargo-20260601

Conversation

@mendral-app
Copy link
Copy Markdown

@mendral-app mendral-app Bot commented Jun 1, 2026

Packages bumped

Package Old New Published
serde_json 1.0.149 1.0.150 2026-05-21
cap-std 4.0 4.0.2 2026-02-15
Per-package detail

serde_json 1.0.149 → 1.0.150

  • Bug fix: Reject non-string enum object keys (#1324)
  • Impact on this project: No impact. This codebase only deserializes into structs (Credentials, Item, TokenResponse, Value). No enum variants with non-string object keys are used.

cap-std 4.0 → 4.0.2

  • Security hardening: Anonymous temp files no longer created with 0o666 permissions (#403)
  • Feature: cap-directories now supports XDG_STATE_HOME (#407)
  • Impact on this project: cap-std is used in unftp-sbe-fs for sandboxed filesystem access. The permission change is a security improvement with no API change.

Files modified

  • crates/unftp-auth-jsonfile/Cargo.toml
  • crates/unftp-auth-rest/Cargo.toml
  • crates/unftp-sbe-fs/Cargo.toml
  • crates/unftp-sbe-gcs/Cargo.toml
Skipped this ecosystem
Package Current Reason
async-trait 0.1.88 Open PR #1 bumps to 0.1.89
bitflags 2.10.0 Open PR #1 bumps to 2.11.1
chrono 0.4.43 Open PR #1 bumps to 0.4.44
futures-util 0.3.31 Open PR #1 bumps to 0.3.32
moka 0.12.13 Open PR #1 bumps to 0.12.15
rustls 0.23.36 Open PR #1 bumps to 0.23.40
tokio 1.49.0 Open PR #1 bumps to 1.52.3
uuid 1.20.0 Open PR #1 bumps to 1.23.1
dashmap 6.1.0 Open PR #1 bumps to 6.2.1
ipnet 2.11.0 Open PR #1 bumps to 2.12.0
hyper 1.8.1 Open PR #1 bumps to 1.9.0
hyper-rustls 0.27.7 Open PR #1 bumps to 0.27.9
clap 4.5.57 Open PR #1 bumps to 4.6.1
tempfile 3.24.0 Open PR #1 bumps to 3.27.0
tracing-subscriber 0.3.22 Open PR #1 bumps to 0.3.23
getrandom 0.3.4 Open PR #1 bumps to 0.4.2
nix 0.30.1 Open PR #1 bumps to 0.31.3
md-5 0.10.6 Open PR #2 bumps to 0.11.0
serde 1.0.228 Already at latest
thiserror 2.0.18 Already at latest
bytes 1.11.1 Already at latest
tokio-rustls 0.26.4 Already at latest
tokio-util 0.7.18 Already at latest
tokio-stream 0.1.18 Already at latest
hyper-util 0.1.20 Already at latest
regex 1.12.3 Already at latest
ring 0.17.14 Already at latest
derive_more 2.1.1 Already at latest
x509-parser 0.18.1 Already at latest
base64 0.22.1 Already at latest
flate2 1.1.9 Already at latest
http-body-util 0.1.3 Already at latest
percent-encoding 2.3.2 Already at latest
pretty_assertions 1.4.1 Already at latest
rstest 0.26.1 Already at latest
time 0.3.47 Already at latest
yup-oauth2 12.1.2 Already at latest
tracing 0.1.44 Already at latest
tracing-attributes 0.1.31 Already at latest
prometheus 0.14.0 Already at latest
proxy-protocol 0.5.0 Already at latest
lazy_static 1.5.0 Already at latest

Note

Created by Mendral. Tag @mendral-app with feedback or questions.

Bump minimum version requirements for dependencies where no code
changes are required. All APIs used by this project remain unchanged.

Safe semver-compatible bumps:
- serde_json 1.0.149 → 1.0.150
- cap-std 4.0 → 4.0.2
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants