Skip to content

Bump the cargo-dependencies group across 1 directory with 23 updates - #577

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-dependencies-1ffc3da22b
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-dependencies-1ffc3da22b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the cargo-dependencies group with 23 updates in the / directory:

Package From To
mail-parser 0.11.5 0.11.9
mail-send 0.6.1 0.6.2
mail-auth 0.11.2 0.13.3
mail-builder 0.4.4 1.0.0
smtp-proto 0.2.2 0.2.4
thiserror 2.0.19 2.0.21
tokio-rustls 0.26.4 0.26.5
futures 0.3.33 0.3.34
tokio-tungstenite 0.29.0 0.30.0
tower-http 0.7.0 0.7.1
uuid 1.24.0 1.26.1
http 1.4.2 1.5.0
cookie 0.18.1 0.18.2
memory-serve 2.3.0 2.4.0
rand 0.10.2 0.10.3
hickory-resolver 0.26.1 0.26.3
aws-lc-rs 1.17.3 1.18.1
totp-rs 5.7.2 6.0.0
async-trait 0.1.91 0.1.92
kube 4.0.0 4.2.0
utoipa 5.5.0 6.0.0
utoipa-axum 0.2.0 0.3.0
askama 0.16.0 0.16.1

Updates mail-parser from 0.11.5 to 0.11.9

Changelog

Sourced from mail-parser's changelog.

[0.11.9] - 2026-09-09

Added

  • Added base64_decode_slice behind the new base64_slice feature, which adds a memchr dependency.

[0.11.8] - 2026-08-22

Fixed

  • HeaderName breaks rkyv serialization from <= 0.11.6.

[0.11.7] - 2026-08-20

Added

  • Added more IANA headers.

Fixed

  • DateTime::to_timezone corrupting non-whole-hour offsets by storing leftover seconds in tz_minute (#158)

[0.11.6] - 2026-08-10

Fixed

  • Missing whitespace between a quoted name and a following encoded word (#150)
  • panic when a Received header ends with a folded line (#155)
  • Received header tokens losing their last character at the end of the input, retaining folding characters, and failing to parse a clause folded before its value (#155)
  • Multi-word display names followed by a comment no longer produce a fabricated address (#153)
Commits

Updates mail-send from 0.6.1 to 0.6.2

Changelog

Sourced from mail-send's changelog.

mail-send 0.6.2

  • Bump mail-builder dependency to 0.5.
  • Bump mail-auth dependency to 0.12.
Commits

Updates mail-auth from 0.11.2 to 0.13.3

Changelog

Sourced from mail-auth's changelog.

[0.13.3] - 2026-09-18

Fixed

  • DMARC: Aggregate reports serialise at most one spf element per record, dropping helo scoped results, as RFC 9990 Appendix A caps AuthResultType/spf at maxOccurs="1" and Section 3.1.1.13 restricts it to the MAIL FROM identity with mfrom as the only valid scope.
  • DMARC: The aggregate report version element is written as 1.0 rather than 1, per RFC 9990 Section 3.1.1.2.

[0.13.2] - 2026-09-13

Added

  • DMARC: New DmarcOutput::result returns the overall DMARC result: fail when a policy record exists but no Authenticated Identifier aligns (RFC 9989 Section 5.3.5).

Fixed

  • SPF: SpfParameters::verify now checks the MAIL FROM identity whenever the HELO check does not return fail, instead of only when it returns pass (#61).
  • DMARC: A temperror SPF result or DKIM signature whose identifier aligns with the Author Domain, or a DNS error while resolving an Organizational Domain for relaxed alignment, yields temperror instead of fail (RFC 9989 Section 5.3.6).
  • DMARC: A policy record without a p tag is treated as p=none when it has a rua tag and ignored otherwise, regardless of its sp and np tags (RFC 9989 Section 4.10.1).
  • DNS: A name that cannot be encoded as a DNS name, such as one with a label longer than 63 bytes, is reported as Error::ParseError instead of a resolver error.

[0.13.1] - 2026-09-12

Changed

  • Bump mail-builder to 1.0.0.

[0.13.0] - 2026-09-09

Changed

  • Performance enhancements.

[0.12.2] - 2026-08-18

Changed

  • Bump mail-builder dependency to 0.5.

[0.12.1] - 2026-08-16

Changed

  • MX and PTR records are now returned as A-labels.

Fixed

  • DMARC: Identifiers are converted to their A-label form before alignment, and alignment is no longer case sensitive.
  • DMARC: External reporting addresses are compared to the policy domain in their A-label form.

[0.12.0] - 2026-08-12

Added

  • DKIM2: Cap the signature chain at 50 DKIM2-Signature / Message-Instance header fields, reported as Dkim2Error::ChainTooLong.
  • DKIM2: Accept an imaginary hop (nd=) that follows a real hop, provided its d= matches a recipient of the previous hop (draft-ietf-dkim-dkim2-spec-04 §9.3).

Changed

  • Report::parse_rfc5322 and TlsReport::parse_rfc5322 now take a max_size argument, which bounds the size of a decompressed report.

... (truncated)

Commits

Updates mail-builder from 0.4.4 to 1.0.0

Changelog

Sourced from mail-builder's changelog.

[1.0.0] - 2026-09-12

Added

  • base64_encode_slice and base64_encoded_len, an allocation-free base64 primitive 2 to 3 times faster than the previous encoder.
  • Base64Encoder::encode_into and QuotedPrintableEncoder::encode_into.
  • Date::write_rfc822 and mime::write_boundary.

Changed

  • Breaking: Serialization writes into the new Writer sink (implemented for Vec<u8>, with IoWriter adapting any std::io::Write). Header::write_header now takes &mut impl Writer and a column, MimePart::write_part takes &mut impl Writer, and generate_message_id_header takes &mut impl Writer and returns nothing. MessageBuilder::write_to, write_body, write_to_vec and write_to_string are unchanged; serialize and serialize_body write into any Writer.
  • Breaking: Requires Rust 1.88 or later.
  • Base64, quoted-printable, 7bit and header serialization rewritten to work on runs instead of bytes; no format! or per-byte writer calls remain on the serialization path; fixed per-message costs (hostname lookup, boundary generation, date formatting, output growth) removed.
  • Header folding follows RFC 5322 and RFC 2047 (folds are CRLF followed by whitespace, no trailing whitespace before a fold, encoded-words at most 75 characters and never split inside a UTF-8 character).
  • Boundaries keep their shape but are generated from a per-thread counter instead of a hash of the thread id; the hostname used for generated Message-IDs is read once per process.
  • Content-Type and Content-Disposition parameter values that contain non-ASCII or control characters are written as RFC 2231 extended parameters (filename*=UTF-8''..., split into *0*, *1* sections when long) instead of RFC 2047 encoded-words inside a quoted string, which RFC 2047 forbids.

Fixed

  • Bare CR or LF in display names, group names, subjects, raw header values and parameter values can no longer reach the output.
  • A raw multipart Content-Type header value that already contains boundary=" is written instead of being dropped, and multipart parts with an unexpected Content-Type header value no longer panic.

[0.5.0] - 2026-08-18

Changed

  • Breaking: The base64_encode, base64_encode_mime, get_encoding_type, rfc2047_encode, quoted_printable_encode, quoted_printable_encode_byte and inline_quoted_printable_encode functions are no longer public. Use the new Base64Encoder and QuotedPrintableEncoder types instead (#50).
  • Breaking: EncodingType is no longer part of the public API.
  • Breaking: Updated to Rust edition 2024, which requires Rust 1.85 or later.

Fixed

  • Display names are no longer wrapped in a quoted-string when RFC 2047 encoded, and Q-encoded phrases now escape all characters outside the restricted set.
Commits

Updates smtp-proto from 0.2.2 to 0.2.4

Commits

Updates thiserror from 2.0.19 to 2.0.21

Release notes

Sourced from thiserror's releases.

2.0.21

  • Fix parsing of generic unit variants in display expressions (#459)

2.0.20

  • Suppress redundant_field_names clippy lint in generated code (#454)
Commits
  • b1827ee Release 2.0.21
  • 58037b5 Merge pull request #459 from dtolnay/turbofish
  • f82a0cf Keep track of nested turbofish depth
  • 72ea492 Raise required compiler to Rust 1.77
  • 72eea0d Resolve io_other_error clippy lint in tests
  • 07f09a2 Raise required compiler to Rust 1.74
  • 2715388 Update ui test suite to nightly-2026-09-22
  • 5a306c7 Update ui test suite to nightly-2026-09-05
  • ef9383b Update ui test suite to nightly-2026-08-22
  • 8336b84 Update ui tests for version 2.0.20
  • Additional commits viewable in compare view

Updates tokio-rustls from 0.26.4 to 0.26.5

Release notes

Sourced from tokio-rustls's releases.

0.26.5

What's Changed

Commits
  • f8832d2 Bump version to 0.26.5
  • c0fad2f return more data at once from TlsStream::poll_read (#198)
  • edc7306 build(deps): bump futures-util from 0.3.33 to 0.3.34
  • baeadaa build(deps): bump rcgen from 0.14.8 to 0.14.9
  • 1e138ad build(deps): bump taiki-e/cache-cargo-install-action from 3.0.7 to 3.0.8
  • b4ecff6 build(deps): bump taiki-e/cache-cargo-install-action from 3 to 3.0.7
  • f47a689 build(deps): bump rustls from 0.23.42 to 0.23.43
  • e25578e build(deps): bump tokio from 1.53.0 to 1.53.1
  • d2a6d98 server: add rustdoc hinting towards timeout wrapping
  • c2e9b4a client: add rustdoc hinting towards timeout wrapping
  • Additional commits viewable in compare view

Updates futures from 0.3.33 to 0.3.34

Release notes

Sourced from futures's releases.

0.3.34

  • Preserve cloned waker identity. (#3032)
  • Updato syn to 3. (#3028)
Changelog

Sourced from futures's changelog.

0.3.34 - 2026-08-11

  • Preserve cloned waker identity. (#3032)
  • Updato syn to 3. (#3028)
Commits

Updates tokio-tungstenite from 0.29.0 to 0.30.0

Changelog

Sourced from tokio-tungstenite's changelog.

0.30.0

Commits

Updates tower-http from 0.7.0 to 0.7.1

Release notes

Sourced from tower-http's releases.

tower-http-0.7.1

Added

  • fs: add ServeDir::redirect_to_trailing_slash() to serve directory indexes directly instead of first redirecting to the trailing-slash path. The redirect remains the default (#728)
  • fs: add ignore_multi_range_requests() to ServeDir and ServeFile, serving the full representation when a request asks for multiple byte ranges. The existing 416 Range Not Satisfiable response remains the default (#727)
  • request-id: the constructors and accessors on the request-id layers, services, and RequestId are now const fn, so they can be used in const context (#716)

Changed

  • fs: the minimum http-range-header requirement is now 0.4.2 (#661)

Fixed

  • behavioral change: fs: make ServeDir::try_call propagate expected filesystem I/O errors when no fallback is configured, as documented, instead of converting them to 404 Not Found responses (#718)
  • decompression: don't end the body when a data frame with no remaining bytes arrives after the decompressor reports end-of-stream. Trailers following such a frame were dropped and could not be recovered (#722)
  • decompression: return a body error when a data frame with remaining bytes arrives after the decompressor reports end-of-stream, rather than silently truncating. This regressed in 0.7.0 (#712)
  • fs: multipart range requests are now rejected before range validation, so they consistently return 416 Range Not Satisfiable with a Cannot serve multipart range requests body instead of a generic unsatisfiable-range response (#661)
  • fs: range error responses no longer carry representation headers such as Content-Type and Content-Encoding (#727)
  • set-header: SetMultipleResponseHeadersLayer and SetMultipleResponseHeader are now Clone regardless of the response body type, matching the fix applied to the request-side types in 0.7.0 (#714)

#661: tower-rs/tower-http#661 #712: tower-rs/tower-http#712 #714: tower-rs/tower-http#714 #716: tower-rs/tower-http#716 #718: tower-rs/tower-http#718 #722: tower-rs/tower-http#722 #727: tower-rs/tower-http#727 #728: tower-rs/tower-http#728

All the changes

... (truncated)

Commits
  • c941451 chore(release): prepare 0.7.1 (#729)
  • 9697702 chore(deps): bump taiki-e/install-action from 2.86.3 to 2.86.8 (#730)
  • e2582e2 Allow ignoring multi-range requests (#727)
  • 888f7fe feat(services): configure directory redirects (#728)
  • 5ad7654 chore(deps): bump taiki-e/install-action from 2.85.12 to 2.86.3 (#726)
  • d154adb fix: reject multipart ranges before validation (#661)
  • d9e5c8a ci: Update to cargo-check-external-types 0.5.0 (#724)
  • 90c072b Propagate ServeDir::try_call I/O errors (#718)
  • 860922e fix(decompression): don't end the body on an empty data frame (#722)
  • 8532252 docs(example)/custom future with multiple bodies (#711)
  • Additional commits viewable in compare view

Updates uuid from 1.24.0 to 1.26.1

Release notes

Sourced from uuid's releases.

v1.26.1

What's Changed

New Contributors

Full Changelog: uuid-rs/uuid@v1.26.0...v1.26.1

v1.26.0

What's Changed

Full Changelog: uuid-rs/uuid@1.25.0...v1.26.0

1.25.0

What's Changed

New Contributors

Full Changelog: uuid-rs/uuid@v1.24.1...1.25.0

v1.24.1

What's Changed

New Contributors

Full Changelog: uuid-rs/uuid@v1.24.0...v1.24.1

Commits
  • 9f92712 Merge pull request #910 from uuid-rs/cargo/v1.26.1
  • d4df8f0 prepare for 1.26.1 release
  • 5613f23 Merge pull request #909 from uuid-rs/fix/ts-conversion-overflow
  • fda00eb don't panic in overflowing Timestamp to SystemTime conversion
  • c82e88c Merge pull request #907 from lenamonj/v7-counter-placement
  • ac065a6 Align the counter diagram
  • 34ec102 Seat the v7 counter below the version nibble
  • cdc96a8 Merge pull request #905 from uuid-rs/cargo/v1.26.0
  • 34e4f49 don't test macros under miri
  • d9e7242 update nightly used for miri
  • Additional commits viewable in compare view

Updates http from 1.4.2 to 1.5.0

Release notes

Sourced from http's releases.

v1.5.0

What's Changed

New Contributors

Full Changelog: hyperium/http@v1.4.2...v1.5.0

Changelog

Sourced from http's changelog.

1.5.0 (July 29, 2026)

  • Add Method::QUERY constant for the new QUERY method defined in RFC 10008.
  • Fix uri::Builder::path_and_query() to allow empty strings to mean no path.
  • Fix uri::PathAndQuery parsing to enforce URI max length.
Commits

Updates cookie from 0.18.1 to 0.18.2

Changelog

Sourced from cookie's changelog.

Version 0.18.2 (Aug 8, 2026)

Changes and Fixes

  • Stopped using internal time APIs.

  • Expires parsing is more RFC 6265-compliant.

    • Weekday prefixes are now optional.
    • Two-digit years follow the RFC boundary: 69 is 2069 (not 1969).
  • The manifest now declares rust-version = "1.56".

Commits
  • 1ec8fde New version: 0.18.2.
  • 2b61005 Make weekdays optional when parsing 'Expires'.
  • d4472e3 Stop using internal time APIs; preserve MSRV.
  • See full diff in compare view

Updates memory-serve from 2.3.0 to 2.4.0

Commits

Updates rand from 0.10.2 to 0.10.3

Changelog

Sourced from rand's changelog.

[0.10.3] — 2026-09-20

Fixes

  • Fix WeightedIndex panic when the sum of float weights is infinite; return Error::Overflow instead (#1808)
  • Fix spurious Error::NonFinite from Uniform::new_inclusive on large finite float ranges such as 0.0..=f64::MAX (#1821)
  • Fix possible panic due to sampling a deserialized Uniform<char> (#1831)

Changes

  • Report exact remaining lengths from WeightedIndex::weights() and reduce overhead when reading weights (#1838)

#1808: rust-random/rand#1808 #1821: rust-random/rand#1821 #1831: rust-random/rand#1831 #1838: rust-random/rand#1838

Commits
  • 9e7d328 Prepare rand 0.10.3 (#1840)
  • f73ce74 Optimize WeightedIndex weight lookup and iteration (#1838)
  • ef9e044 Avoid panic from deserialized Uniform\<char> where range == 0 (#1831)
  • c994eb1 docs: fix angle unit in quick start example (#1839)
  • 33dea4f Test that WeightedIndex rejects INFINITY with Error::Overflow (#1822)
  • 94c9078 Fix Uniform::new_inclusive overflow on large finite float ranges (#1821)
  • bb1262f Use Xoshiro256PlusPlus in examples/rayon-monte-carlo.rs (#1805)
  • 521fab6 Stop pinning dependencies (#1820)
  • 3f7c433 Stop pinning dependencies
  • cf4f73e sample_efraimidis_spirakis: error on more than amount non-finite weights (#1814)
  • Additional commits viewable in compare view

Updates hickory-resolver from 0.26.1 to 0.26.3

Release notes

Sourced from hickory-resolver's releases.

v0.26.3

This release fixes regressions introduced in v0.26.2 related to DNSSEC verification, QUIC servers, HTTP/3 servers, and minimum dependency versions.

What's Changed

Full Changelog: hickory-dns/hickory-dns@v0.26.2...v0.26.3

v0.26.2

This release fixes a large number of security vulnerabilities. Most of the issues were related to DNSSEC validation, denial of service and resource consumption attacks, and reachable panics in parsers. Other issues were related to UDP spoofing defenses, caching issues, and general DNS protocol correctness issues.

This is our first post-vulnpocalypse release, and most of these vulnerabilities were discovered through LLM-based workflows. The sheer volume of reports has been a challenge for our volunteer maintainers.

Resolved advisories:

  • GHSA-2vgh-3wfw-qj7c: RRSIG Signer's Name not checked against the RRset's zone
  • GHSA-57pw-897j-v4j6: Improper check of signature validity of NSEC and NSEC3 records
  • GHSA-wjgj-fvg9-65w9: DNSSEC validation ignores bogus records with a DNS class other than IN
  • GHSA-588m-chg6-8jqj: Inverted NSEC3 comparison allows forgery of proofs of nonexistence
  • GHSA-qw83-5pm2-ggp5: DNSSEC nonexistence forgery via incorrect handling of wraparound NSEC records
  • GHSA-3jvh-8vj5-65rq: NSEC3 apex NODATA accepted as secure with no QNAME-matching NSEC3
  • GHSA-3r6v-f3jh-vvqm: ancestor-delegation NSEC accepted as proof of nonexistence below the zone cut
  • GHSA-624w-vvww-xvpw: ancestor-delegation NSEC3 accepted as proof of nonexistence at and below the zone cut
  • GHSA-7php-9j59-g3ch: DNSSEC validation is missing RFC 6840 §4.4 checks
  • GHSA-vrv5-968r-5ggm: DNSSEC validation accepts bogus positive response with wildcard expansion
  • GHSA-p2jv-r3m3-7wf4: Nonexistence proof forgery due to insufficient checks on NSEC3 record names
  • GHSA-86vr-jm6c-7cpg: NSEC validator accepts NXDOMAIN for an empty non-terminal (ENT) that the covering NSEC proves exists
  • GHSA-8hq4-5836-w6q4: Server does not check validation status of SOA record in negative responses
  • GHSA-5j98-2g5x-46v6: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures
  • GHSA-929p-gjf6-5hqj: DNSSEC validation accepts responses with the wrong RRset as a positive answer
  • GHSA-j2rc-wxwh-62g9: TrustAnchors does not check name of DNSKEY
  • GHSA-rx82-4p2j-j5cv: Name::hash discards label boundaries; ValidationCacheKey(u64) reuses the digest in Eq implementation, leaking an Insecure DNSSEC verdict across distinct owner names
  • GHSA-2hxp-x833-73f7: Hickory DNS recursor: ghost domain attack via child-side NS RRset queries
  • GHSA-x962-5xwx-fr8x: Unchecked subtraction in TSIG RDATA decoding panics when overflow checks are enabled
  • GHSA-wgfr-mphw-j5g4: Panic in zone file parser for SVCB and HTTPS
  • GHSA-hx8c-fjhc-hmf5: Panic in zone file parser for SVCB and HTTPS
  • GHSA-4rph-pmrw-mwpw: Zone file parser panics when parsing long lines
  • GHSA-3w89-7rx5-hpwx: Responses with QDCOUNT=0 bypass check for matching question section
  • GHSA-vcjp-57rr-mpfw: Out-of-bailiwick filtering is not applied to negative responses
  • GHSA-6w6g-hm98-mhgm: Unbounded TC-retry loop in NameServerPool::try_send (resource-exhaustion DoS)
  • GHSA-cx5j-p54p-q756: Cyclic sibling domain name server referrals without glue records cause exponential upstream query amplification in the recursor
  • GHSA-6h5c-jjg5-wj59: Glueless-NS referral fan-out without per-query work budget
  • GHSA-v44v-c8m4-gc43: Denial of service of client UDP connections via spoofed malformed responses
  • GHSA-67wc-6jq8-ghrc: Remote memory-amplification DoS via attacker-controlled RR counts in DNS message parsing

... (truncated)

Commits
  • bd37caf net: require authenticated insecure-delegation proofs
  • 5a79511 Add conformance test for regression
  • c268442 net: fix ancestor delegation issues
  • 9488e8e Exclude accepting QUIC connections from timeouts
  • 4ad16c3 Bump version to 0.26.3
  • cfab556 proto: ignore RRSIGs in DnssecSummary::from_records
  • 819a6bc net: try every RRSIG before marking an RRset bogus
  • 688231e resolver: use lenient resolv.conf parsing
  • ca5d1a1 resolver: Fix 'unused method' with features blocklist,tls-ring
  • 678b01b Fix unnecessary qualification warning
  • Additional commits viewable in compare view

Updates aws-lc-rs from 1.17.3 to 1.18.1

Release notes

Sourced from aws-lc-rs's releases.

aws-lc-rs v1.18.1

What's Changed

  • Add ECDSA P-256 SHA-1 ASN.1 signature verification by @​assafvayner in aws/aws-lc-rs#1214
    • Adds ECDSA_P256_SHA1_ASN1 for verifying ASN.1 DER-encoded ECDSA P-256 signatures over SHA-1, so applications can verify legacy signatures such as CloudFront signed URLs using ECDSA P-256 with the default SHA-1 hash.
    • SHA-1 remains available for legacy verification only. This release does not add a corresponding signing algorithm.
  • Tighten AEAD, cipher IV, HKDF, ECDH, and RSA API contracts by @​justsmth in aws/aws-lc-rs#1215
    • In-place AEAD sealing now verifies that Extend produced exactly enough space for the plaintext and authentication tag before passing the buffer to AWS-LC. Non-conforming custom buffers now return Err(Unspecified).
    • Streaming cipher constructors now reject missing or mismatched IV contexts, matching the validation already performed by the one-shot APIs.
    • Salt::from(Okm) now uses the output algorithm selected by the Okm, rather than the algorithm from the source PRK.
    • ECDH shared-secret storage is now zeroized on fallible derive paths.
    • RSA verify_digest_sig now requires the supplied digest to match the digest configured by RsaParameters, for both parsed and unparsed public keys.
    • Valid inputs are unaffected. Calls using inconsistent algorithms, IV contexts, or custom AEAD buffers now fail closed with Err(Unspecified).

Upstream AWS-LC

  • aws-lc-sys v0.45.0 aligns with AWS-LC v5.7.0 (previously v5.5.0). See also the release notes for v5.6.0.
    • v5.7.0 corrects EVP_DecryptUpdate for padded block ciphers so it modifies only the output range reported through out_len. aws-lc-rs now includes canary-based regression coverage around the documented minimum output-buffer sizes.
  • aws-lc-fips-sys v0.14.2 moves to AWS-LC FIPS v4.2.0.
    • Includes the equivalent EVP_DecryptUpdate correction for FIPS builds.
    • Restores FIPS builds with Clang 20 and newer.
    • Removes the FIPS compiler wrapper's dependency on /usr/bin/env, fixing builds in Nix and similar sandboxed environments.

Build Improvements

  • Export cargo:root metadata when linking against a system-installed AWS-LC by @​weihanglo in aws/aws-lc-rs#1208
    • The system-library path now exposes the installation prefix through DEP_AWS_LC_*_ROOT, consistently with the CC and CMake builders, so downstream build scripts can rely on the metadata regardless of how AWS-LC was built.
  • Fix -Wa,--debug-prefix-map handling with Clang and LTO by @​justsmth in aws/aws-lc-rs#1212
    • Fixes Clang builds when CFLAGS contains -flto or -flto=thin. The assembler-specific flag is now used only with GCC; Clang's integrated assembler uses -ffile-prefix-map directly.
  • Filter raw target-triple CFLAGS spellings when compiling jitterentropy by @​justsmth in aws/aws-lc-rs#1207
    • Prevents inherited optimization flags from overriding jitterentropy's required -O0, including when environment variables are set by a parent process using raw or legacy-normalized target triples.

Issues Being Closed

Other Merged PRs

... (truncated)

Commits

Bumps the cargo-dependencies group with 23 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [mail-parser](https://github.com/stalwartlabs/mail-parser) | `0.11.5` | `0.11.9` |
| [mail-send](https://github.com/stalwartlabs/mail-send) | `0.6.1` | `0.6.2` |
| [mail-auth](https://github.com/stalwartlabs/mail-auth) | `0.11.2` | `0.13.3` |
| [mail-builder](https://github.com/stalwartlabs/mail-builder) | `0.4.4` | `1.0.0` |
| [smtp-proto](https://github.com/stalwartlabs/smtp-proto) | `0.2.2` | `0.2.4` |
| [thiserror](https://github.com/dtolnay/thiserror) | `2.0.19` | `2.0.21` |
| [tokio-rustls](https://github.com/rustls/tokio-rustls) | `0.26.4` | `0.26.5` |
| [futures](https://github.com/rust-lang/futures-rs) | `0.3.33` | `0.3.34` |
| [tokio-tungstenite](https://github.com/snapview/tokio-tungstenite) | `0.29.0` | `0.30.0` |
| [tower-http](https://github.com/tower-rs/tower-http) | `0.7.0` | `0.7.1` |
| [uuid](https://github.com/uuid-rs/uuid) | `1.24.0` | `1.26.1` |
| [http](https://github.com/hyperium/http) | `1.4.2` | `1.5.0` |
| [cookie](https://github.com/SergioBenitez/cookie-rs) | `0.18.1` | `0.18.2` |
| [memory-serve](https://github.com/tweedegolf/memory-serve) | `2.3.0` | `2.4.0` |
| [rand](https://github.com/rust-random/rand) | `0.10.2` | `0.10.3` |
| [hickory-resolver](https://github.com/hickory-dns/hickory-dns) | `0.26.1` | `0.26.3` |
| [aws-lc-rs](https://github.com/aws/aws-lc-rs) | `1.17.3` | `1.18.1` |
| [totp-rs](https://github.com/constantoine/totp-rs) | `5.7.2` | `6.0.0` |
| [async-trait](https://github.com/dtolnay/async-trait) | `0.1.91` | `0.1.92` |
| [kube](https://github.com/kube-rs/kube) | `4.0.0` | `4.2.0` |
| [utoipa](https://github.com/juhaku/utoipa) | `5.5.0` | `6.0.0` |
| [utoipa-axum](https://github.com/juhaku/utoipa) | `0.2.0` | `0.3.0` |
| [askama](https://github.com/askama-rs/askama) | `0.16.0` | `0.16.1` |



Updates `mail-parser` from 0.11.5 to 0.11.9
- [Release notes](https://github.com/stalwartlabs/mail-parser/releases)
- [Changelog](https://github.com/stalwartlabs/mail-parser/blob/main/CHANGELOG.md)
- [Commits](https://github.com/stalwartlabs/mail-parser/commits)

Updates `mail-send` from 0.6.1 to 0.6.2
- [Release notes](https://github.com/stalwartlabs/mail-send/releases)
- [Changelog](https://github.com/stalwartlabs/mail-send/blob/main/CHANGELOG.md)
- [Commits](https://github.com/stalwartlabs/mail-send/commits)

Updates `mail-auth` from 0.11.2 to 0.13.3
- [Release notes](https://github.com/stalwartlabs/mail-auth/releases)
- [Changelog](https://github.com/stalwartlabs/mail-auth/blob/main/CHANGELOG.md)
- [Commits](https://github.com/stalwartlabs/mail-auth/commits)

Updates `mail-builder` from 0.4.4 to 1.0.0
- [Release notes](https://github.com/stalwartlabs/mail-builder/releases)
- [Changelog](https://github.com/stalwartlabs/mail-builder/blob/main/CHANGELOG.md)
- [Commits](https://github.com/stalwartlabs/mail-builder/commits)

Updates `smtp-proto` from 0.2.2 to 0.2.4
- [Commits](https://github.com/stalwartlabs/smtp-proto/commits)

Updates `thiserror` from 2.0.19 to 2.0.21
- [Release notes](https://github.com/dtolnay/thiserror/releases)
- [Commits](dtolnay/thiserror@2.0.19...2.0.21)

Updates `tokio-rustls` from 0.26.4 to 0.26.5
- [Release notes](https://github.com/rustls/tokio-rustls/releases)
- [Commits](rustls/tokio-rustls@v/0.26.4...v/0.26.5)

Updates `futures` from 0.3.33 to 0.3.34
- [Release notes](https://github.com/rust-lang/futures-rs/releases)
- [Changelog](https://github.com/rust-lang/futures-rs/blob/main/CHANGELOG.md)
- [Commits](rust-lang/futures-rs@0.3.33...0.3.34)

Updates `tokio-tungstenite` from 0.29.0 to 0.30.0
- [Changelog](https://github.com/snapview/tokio-tungstenite/blob/master/CHANGELOG.md)
- [Commits](snapview/tokio-tungstenite@v0.29.0...v0.30.0)

Updates `tower-http` from 0.7.0 to 0.7.1
- [Release notes](https://github.com/tower-rs/tower-http/releases)
- [Commits](tower-rs/tower-http@tower-http-0.7.0...tower-http-0.7.1)

Updates `uuid` from 1.24.0 to 1.26.1
- [Release notes](https://github.com/uuid-rs/uuid/releases)
- [Commits](uuid-rs/uuid@v1.24.0...v1.26.1)

Updates `http` from 1.4.2 to 1.5.0
- [Release notes](https://github.com/hyperium/http/releases)
- [Changelog](https://github.com/hyperium/http/blob/master/CHANGELOG.md)
- [Commits](hyperium/http@v1.4.2...v1.5.0)

Updates `cookie` from 0.18.1 to 0.18.2
- [Changelog](https://github.com/rwf2/cookie-rs/blob/0.18.2/CHANGELOG.md)
- [Commits](rwf2/cookie-rs@0.18.1...0.18.2)

Updates `memory-serve` from 2.3.0 to 2.4.0
- [Commits](tweedegolf/memory-serve@v2.3.0...v2.4.0)

Updates `rand` from 0.10.2 to 0.10.3
- [Release notes](https://github.com/rust-random/rand/releases)
- [Changelog](https://github.com/rust-random/rand/blob/master/CHANGELOG.md)
- [Commits](rust-random/rand@0.10.2...0.10.3)

Updates `hickory-resolver` from 0.26.1 to 0.26.3
- [Release notes](https://github.com/hickory-dns/hickory-dns/releases)
- [Changelog](https://github.com/hickory-dns/hickory-dns/blob/main/CHANGELOG.md)
- [Commits](hickory-dns/hickory-dns@v0.26.1...v0.26.3)

Updates `aws-lc-rs` from 1.17.3 to 1.18.1
- [Release notes](https://github.com/aws/aws-lc-rs/releases)
- [Commits](aws/aws-lc-rs@v1.17.3...v1.18.1)

Updates `totp-rs` from 5.7.2 to 6.0.0
- [Release notes](https://github.com/constantoine/totp-rs/releases)
- [Changelog](https://github.com/constantoine/totp-rs/blob/master/CHANGELOG.md)
- [Commits](constantoine/totp-rs@v5.7.2...v6.0.0)

Updates `async-trait` from 0.1.91 to 0.1.92
- [Release notes](https://github.com/dtolnay/async-trait/releases)
- [Commits](dtolnay/async-trait@0.1.91...0.1.92)

Updates `kube` from 4.0.0 to 4.2.0
- [Release notes](https://github.com/kube-rs/kube/releases)
- [Changelog](https://github.com/kube-rs/kube/blob/main/CHANGELOG.md)
- [Commits](kube-rs/kube@4.0.0...4.2.0)

Updates `utoipa` from 5.5.0 to 6.0.0
- [Release notes](https://github.com/juhaku/utoipa/releases)
- [Changelog](https://github.com/juhaku/utoipa/blob/master/utoipa-rapidoc/CHANGELOG.md)
- [Commits](juhaku/utoipa@utoipa-5.5.0...utoipa-6.0.0)

Updates `utoipa-axum` from 0.2.0 to 0.3.0
- [Release notes](https://github.com/juhaku/utoipa/releases)
- [Changelog](https://github.com/juhaku/utoipa/blob/master/utoipa-rapidoc/CHANGELOG.md)
- [Commits](juhaku/utoipa@utoipa-axum-0.2.0...utoipa-axum-0.3.0)

Updates `askama` from 0.16.0 to 0.16.1
- [Release notes](https://github.com/askama-rs/askama/releases)
- [Commits](askama-rs/askama@v0.16.0...v0.16.1)

---
updated-dependencies:
- dependency-name: mail-parser
  dependency-version: 0.11.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-dependencies
- dependency-name: mail-send
  dependency-version: 0.6.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-dependencies
- dependency-name: mail-auth
  dependency-version: 0.13.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-dependencies
- dependency-name: mail-builder
  dependency-version: 1.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: cargo-dependencies
- dependency-name: smtp-proto
  dependency-version: 0.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-dependencies
- dependency-name: thiserror
  dependency-version: 2.0.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-dependencies
- dependency-name: tokio-rustls
  dependency-version: 0.26.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-dependencies
- dependency-name: futures
  dependency-version: 0.3.34
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-dependencies
- dependency-name: tokio-tungstenite
  dependency-version: 0.30.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-dependencies
- dependency-name: tower-http
  dependency-version: 0.7.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-dependencies
- dependency-name: uuid
  dependency-version: 1.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-dependencies
- dependency-name: http
  dependency-version: 1.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-dependencies
- dependency-name: cookie
  dependency-version: 0.18.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-dependencies
- dependency-name: memory-serve
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-dependencies
- dependency-name: rand
  dependency-version: 0.10.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-dependencies
- dependency-name: hickory-resolver
  dependency-version: 0.26.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-dependencies
- dependency-name: aws-lc-rs
  dependency-version: 1.18.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-dependencies
- dependency-name: totp-rs
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: cargo-dependencies
- dependency-name: async-trait
  dependency-version: 0.1.92
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-dependencies
- dependency-name: kube
  dependency-version: 4.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-dependencies
- dependency-name: utoipa
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: cargo-dependencies
- dependency-name: utoipa-axum
  dependency-version: 0.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-dependencies
- dependency-name: askama
  dependency-version: 0.16.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants