chore(deps): weekly safe cargo updates · 4 packages - #10
Closed
mendral-app[bot] wants to merge 1 commit into
Closed
Conversation
|
Closing this and every other open mendral dependency PR on the org. These had accumulated to ~425 across 50+ repos, most of them superseded by a later run of the same weekly job, and a large share already in merge conflict. As a queue they were never going to be merged, and they were burying the alerts that actually matter under review noise. Nothing is lost by closing them: the open Dependabot alerts remain the source of truth, and remediation is being done through dedicated, tested PRs per repo instead of bulk updates. Anything still genuinely vulnerable will be fixed there. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Packages bumped
tonictonic-prosttonic-prost-buildprost-wkt-typesPer-package details
tonic / tonic-prost / tonic-prost-build 0.14.2 → 0.14.6
Changelog highlights (v0.14.6):
ServerCertVerifierAPI on transport/channelmax_frame_sizeto client EndpointImpact on this repo: This repo defines gRPC APIs via protobuf and generates Rust bindings. The tonic ecosystem is used for code generation (
tonic-prost-build) and the generated server/client stubs (tonic,tonic-prost). These are all additive/fix changes — no breaking API modifications. The new features (ServerCertVerifier, max_frame_size, header table size) are opt-in and not used here.prost-wkt-types 0.7 → 0.7.1
Changelog highlights:
schemarsdependency to 1.2Impact on this repo: This crate provides well-known protobuf type wrappers used in the generated code. The 0.7.1 bump is purely internal (dependency update + workspace restructuring). No API changes.
Files modified
Cargo.toml— version bumps for 4 packagesSkipped this ecosystem
prostprost-typestokioserde"1.0"in Cargo.toml; lockfile resolves latest automaticallyNote
Created by Mendral. Tag @mendral-app with feedback or questions.
Note
Low Risk
Patch-level dependency bumps with no code changes; tonic 0.14.x fixes/features are opt-in and prost-wkt-types 0.7.1 is internal.
Overview
Dependency-only update in
Cargo.toml: the gRPC stack (tonic,tonic-prost,tonic-prost-build) moves from 0.14.2 → 0.14.6, andprost-wkt-typesfrom 0.7 → 0.7.1.No application or protobuf source changes—only manifest version pins for the crates used to generate and run Dragonfly’s gRPC API bindings.
Reviewed by Cursor Bugbot for commit 618aba0. Bugbot is set up for automated code reviews on this repo. Configure here.