Skip to content

Combined Dependabot PRs 2026-10-02 - #357

Closed
code-search-bot wants to merge 12 commits into
mainfrom
combined-dependabot-20261002-070747
Closed

code-search-bot wants to merge 12 commits into
mainfrom
combined-dependabot-20261002-070747

Conversation

@code-search-bot

Copy link
Copy Markdown
Collaborator

This PR combines 6 Dependabot PRs.

ℹ️ Details from merged PRs:

Details from Bump release-plz/action from 0.5.136 to 0.5.139

Release notes

Sourced from release-plz/action's releases.

v0.5.139

What's Changed

Full Changelog: release-plz/action@v0.5.138...v0.5.139

v0.5.138

What's Changed

Full Changelog: release-plz/action@v0.5.137...v0.5.138

v0.5.137

What's Changed

New Contributors

Full Changelog: release-plz/action@v0.5.136...v0.5.137

Commits
  • b8d6b54 Update to 0.3.169 (#540)
  • 7e10418 chore(deps): update dependency taiki-e/install-action to v2.87.16 (#538)
  • d857f61 chore(deps): update dependency taiki-e/install-action to v2.87.15 (#537)
  • 9e858f9 chore(deps): update dependency taiki-e/install-action to v2.87.14 (#536)
  • d6c5627 Update to 0.3.168 (#535)
  • 3acb31e chore(deps): update dependency taiki-e/install-action to v2.87.13 (#534)
  • f77cdb1 chore(deps): lock file maintenance (#532)
  • 8e61445 Update to 0.3.167 (#531)
  • c9cf542 chore(deps): update dependency taiki-e/install-action to v2.87.12 (#530)
  • c4d7bf6 fix: support Gitea runners without GitHub identity lookup (#528)
  • Additional commits viewable in compare view

Details from Bump async-trait from 0.1.89 to 0.1.92

Release notes

Sourced from async-trait's releases.

0.1.92

  • Resolve double_must_use clippy lint in generated code (#303)

0.1.91

  • Update to syn 3 (#299)
  • Fix mutability for by-reference receivers (#301)

0.1.90

(yanked)

Commits
  • 82e7e9e Release 0.1.92
  • 9a35cb8 Merge pull request #303 from dtolnay/mustuse
  • 875ceec Resolve double_must_use clippy lint
  • 62993a5 Raise minimum tested compiler to rust 1.88
  • d049ee0 Release 0.1.91
  • 7a0961f Merge pull request #301 from dtolnay/mutability
  • 740f86f Ignore mut_mut pedantic clippy lint in test
  • 4699cd3 Fix mutability for by-reference receivers
  • 6dd3573 Add regression test for issue 300
  • 2371797 Release 0.1.90
  • Additional commits viewable in compare view

Details from Bump fs-err from 3.3.0 to 3.3.1

Changelog

Sourced from fs-err's changelog.

3.3.1

  • Fix debug_tokio feature so it works as documented. (#92)
Commits

Details from Bump prost-wkt from 0.7.1 to 0.7.2

Release notes

Sourced from prost-wkt's releases.

Release v0.7.2

What's Changed

  • Raise the minimum Rust version to 1.85 by @​LucaCappelletti94 in fdeantoni/prost-wkt#87
  • Ship the imported google.protobuf schemas by @​LucaCappelletti94 in fdeantoni/prost-wkt#86
  • Add utoipa feature to prost-wkt-types by @​AlJohri in fdeantoni/prost-wkt#88
  • Corrected the schemars and utoipa schemas: Duration accepts negative values and no longer claims format: duration, Timestamp no longer claims format: date-time, and Any only requires @type. utoipa components are registered as google.protobuf.*.
  • The schemars and utoipa features are now built and tested in CI and enabled on docs.rs

Notes

  • prost-wkt-types now vendors the google.protobuf well-known type schemas (protobuf v35.1), so the generated code no longer depends on the installed protoc or on protox. These files are BSD-3-Clause, so the crate's license expression is now Apache-2.0 AND BSD-3-Clause.
  • The minimum supported Rust version is now 1.85.

Full Changelog: fdeantoni/prost-wkt@v0.7.1...v0.7.2

Changelog

Sourced from prost-wkt's changelog.

Release 0.7.2

What's Changed

  • Raise the minimum Rust version to 1.85 by @​LucaCappelletti94 in fdeantoni/prost-wkt#87
  • Ship the imported google.protobuf schemas by @​LucaCappelletti94 in fdeantoni/prost-wkt#86
  • Add utoipa feature to prost-wkt-types by @​AlJohri in fdeantoni/prost-wkt#88
  • Corrected the schemars and utoipa schemas: Duration accepts negative values and no longer claims format: duration, Timestamp no longer claims format: date-time, and Any only requires @type. utoipa components are registered as google.protobuf.*.
  • The schemars and utoipa features are now built and tested in CI and enabled on docs.rs

Notes

  • prost-wkt-types now vendors the google.protobuf well-known type schemas (protobuf v35.1), so the generated code no longer depends on the installed protoc or on protox. These files are BSD-3-Clause, so the crate's license expression is now Apache-2.0 AND BSD-3-Clause.
  • The minimum supported Rust version is now 1.85.

Full Changelog: fdeantoni/prost-wkt@v0.7.1...v0.7.2

Commits
  • 2f30fc6 Merge pull request #90 from fdeantoni/pr88-fixes
  • 0ce88c9 Prepare for release 0.7.2
  • 2d7bff4 Declare schema features explicitly and document their scope
  • ee2cf86 Share schema descriptions and examples between schemars and utoipa
  • 14fb204 Build and test the schemars and utoipa features in CI
  • 19d7c4d Namespace utoipa component names as google.protobuf.*
  • efb019b Fix the Any schema to match what the crate actually serializes
  • 14a0a66 Fix Duration/Timestamp schema contracts for schemars and utoipa
  • 51d1bdf Merge pull request #88 from AlJohri/utoipa-feature
  • 253bd25 Merge pull request #86 from LucaCappelletti94/ship-well-known-type-schemas
  • Additional commits viewable in compare view

Details from Bump prost-wkt-types from 0.7.1 to 0.7.2

Release notes

Sourced from prost-wkt-types's releases.

Release v0.7.2

What's Changed

  • Raise the minimum Rust version to 1.85 by @​LucaCappelletti94 in fdeantoni/prost-wkt#87
  • Ship the imported google.protobuf schemas by @​LucaCappelletti94 in fdeantoni/prost-wkt#86
  • Add utoipa feature to prost-wkt-types by @​AlJohri in fdeantoni/prost-wkt#88
  • Corrected the schemars and utoipa schemas: Duration accepts negative values and no longer claims format: duration, Timestamp no longer claims format: date-time, and Any only requires @type. utoipa components are registered as google.protobuf.*.
  • The schemars and utoipa features are now built and tested in CI and enabled on docs.rs

Notes

  • prost-wkt-types now vendors the google.protobuf well-known type schemas (protobuf v35.1), so the generated code no longer depends on the installed protoc or on protox. These files are BSD-3-Clause, so the crate's license expression is now Apache-2.0 AND BSD-3-Clause.
  • The minimum supported Rust version is now 1.85.

Full Changelog: fdeantoni/prost-wkt@v0.7.1...v0.7.2

Changelog

Sourced from prost-wkt-types's changelog.

Release 0.7.2

What's Changed

  • Raise the minimum Rust version to 1.85 by @​LucaCappelletti94 in fdeantoni/prost-wkt#87
  • Ship the imported google.protobuf schemas by @​LucaCappelletti94 in fdeantoni/prost-wkt#86
  • Add utoipa feature to prost-wkt-types by @​AlJohri in fdeantoni/prost-wkt#88
  • Corrected the schemars and utoipa schemas: Duration accepts negative values and no longer claims format: duration, Timestamp no longer claims format: date-time, and Any only requires @type. utoipa components are registered as google.protobuf.*.
  • The schemars and utoipa features are now built and tested in CI and enabled on docs.rs

Notes

  • prost-wkt-types now vendors the google.protobuf well-known type schemas (protobuf v35.1), so the generated code no longer depends on the installed protoc or on protox. These files are BSD-3-Clause, so the crate's license expression is now Apache-2.0 AND BSD-3-Clause.
  • The minimum supported Rust version is now 1.85.

Full Changelog: fdeantoni/prost-wkt@v0.7.1...v0.7.2

Commits
  • 2f30fc6 Merge pull request #90 from fdeantoni/pr88-fixes
  • 0ce88c9 Prepare for release 0.7.2
  • 2d7bff4 Declare schema features explicitly and document their scope
  • ee2cf86 Share schema descriptions and examples between schemars and utoipa
  • 14fb204 Build and test the schemars and utoipa features in CI
  • 19d7c4d Namespace utoipa component names as google.protobuf.*
  • efb019b Fix the Any schema to match what the crate actually serializes
  • 14a0a66 Fix Duration/Timestamp schema contracts for schemars and utoipa
  • 51d1bdf Merge pull request #88 from AlJohri/utoipa-feature
  • 253bd25 Merge pull request #86 from LucaCappelletti94/ship-well-known-type-schemas
  • Additional commits viewable in compare view

Details from Bump http from 1.4.2 to 1.5.0

Release notes

Sourced from http's releases.

v1.5.0

What's Changed

New Contributors

Full Changelog: hyperium/http@v1.4.2...v1.5.0

Changelog

Sourced from http's changelog.

1.5.0 (July 29, 2026)

  • Add Method::QUERY constant for the new QUERY method defined in RFC 10008.
  • Fix uri::Builder::path_and_query() to allow empty strings to mean no path.
  • Fix uri::PathAndQuery parsing to enforce URI max length.
Commits

dependabot Bot and others added 12 commits September 28, 2026 14:52
Bumps [release-plz/action](https://github.com/release-plz/action) from 0.5.136 to 0.5.139.
- [Release notes](https://github.com/release-plz/action/releases)
- [Commits](release-plz/action@a80d79e...b8d6b54)

---
updated-dependencies:
- dependency-name: release-plz/action
  dependency-version: 0.5.139
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [async-trait](https://github.com/dtolnay/async-trait) from 0.1.89 to 0.1.92.
- [Release notes](https://github.com/dtolnay/async-trait/releases)
- [Commits](dtolnay/async-trait@0.1.89...0.1.92)

---
updated-dependencies:
- dependency-name: async-trait
  dependency-version: 0.1.92
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [fs-err](https://github.com/andrewhickman/fs-err) from 3.3.0 to 3.3.1.
- [Changelog](https://github.com/andrewhickman/fs-err/blob/main/CHANGELOG.md)
- [Commits](https://github.com/andrewhickman/fs-err/commits)

---
updated-dependencies:
- dependency-name: fs-err
  dependency-version: 3.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [prost-wkt](https://github.com/fdeantoni/prost-wkt) from 0.7.1 to 0.7.2.
- [Release notes](https://github.com/fdeantoni/prost-wkt/releases)
- [Changelog](https://github.com/fdeantoni/prost-wkt/blob/master/CHANGELOG.md)
- [Commits](fdeantoni/prost-wkt@v0.7.1...v0.7.2)

---
updated-dependencies:
- dependency-name: prost-wkt
  dependency-version: 0.7.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [prost-wkt-types](https://github.com/fdeantoni/prost-wkt) from 0.7.1 to 0.7.2.
- [Release notes](https://github.com/fdeantoni/prost-wkt/releases)
- [Changelog](https://github.com/fdeantoni/prost-wkt/blob/master/CHANGELOG.md)
- [Commits](fdeantoni/prost-wkt@v0.7.1...v0.7.2)

---
updated-dependencies:
- dependency-name: prost-wkt-types
  dependency-version: 0.7.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [http](https://github.com/hyperium/http) from 1.4.2 to 1.5.0.
- [Release notes](https://github.com/hyperium/http/releases)
- [Changelog](https://github.com/hyperium/http/blob/master/CHANGELOG.md)
- [Commits](hyperium/http@v1.4.2...v1.5.0)

---
updated-dependencies:
- dependency-name: http
  dependency-version: 1.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Copilot AI balanced review requested due to automatic review settings October 2, 2026 07:07
@code-search-bot
code-search-bot requested a review from a team as a code owner October 2, 2026 07:07

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

Static review found no blocking dependency compatibility or workflow issues; builds and tests were not run.

Review effort: Balanced
Findings: None

What changed in this PR

Combines six Dependabot updates for the Rust workspace and release automation.

Changes:

  • Updates five locked Rust dependencies: async-trait, fs-err, http, prost-wkt, and prost-wkt-types.
  • Upgrades release-plz/action to v0.5.139 in both release workflows, retaining full commit pins.
File Description
Cargo.lock Updates Rust dependency versions and checksums.
.github/​workflows/​publish-release.yml Updates the pinned action used to publish releases.
.github/​workflows/​create-release-pr.yml Updates the pinned action used to create release PRs.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@jorendorff jorendorff closed this Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants