chore(deps): bump the cargo group across 1 directory with 4 updates #17
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the cargo group with 4 updates in the / directory: openssl, rustix, shlex and webpki.
Updates
openssl
from 0.10.57 to 0.10.72Release notes
Sourced from openssl's releases.
... (truncated)
Commits
87085bd
Merge pull request #2390 from alex/uaf-fixd1a12e2
Fixed two UAFs and bumped versions for release7c7b2e6
Merge pull request #2389 from skmcgrail/aws-lc-follow-up34a477b
Use --experimental with bindgen-cli with aws-lc buildd4bf071
Merge pull request #2386 from skmcgrail/aws-lc-follow-upa86bf67
Remove comment705dbfb
Fix teste0df413
Skip final call for LibreSSL 4.1.0 for CCM mode2f1164b
Enable additional capabilities for AWS-LCdde9ffb
Merge pull request #1805 from skmcgrail/aws-lc-support-finalUpdates
rustix
from 0.37.23 to 0.37.28Commits
89b7a8d
chore: Release rustix version 0.37.28f51ecb1
Check for a missingDT_HASH
section in the VDSO parser (#1254) (#1257)b720e07
Remove naked_functions feature usage for x86 (#722) (#1182)b38dc51
chore: Release rustix version 0.37.27a2d9c8e
Fix p{read,write}v{,v2}'s encoding of the offset argument on Linux. (#896) (#...dce2777
chore: Release rustix version 0.37.2606dbe83
Fixsendmsg_unix
's address encoding. (#885) (#886)00b84d6
chore: Release rustix version 0.37.25cad15a7
Fixes forDir
on macOS, FreeBSD, and WASI.df3c3a1
Merge pull request from GHSA-c827-hfw6-qwvmUpdates
shlex
from 1.1.0 to 1.3.0Changelog
Sourced from shlex's changelog.
Commits
4a0724b
Address security issues involving quote API4c53044
Minimal fix for the high-severity issue without bumping MSRVfde8a71
Version bumpf44b62e
Merge pull request #15 from danielparks/bytes0c786d4
Implement Shlex with bytes::Shlex.879d212
Add support for operating on byte stringsaa2d6e3
Merge pull request #14 from atouchet/badge18d1dae
Fix CI badge6064b48
Merge pull request #11 from adetaylor/fuzz6480b2c
Adding fuzzers for unsafe code.Updates
webpki
from 0.22.0 to 0.22.4Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.