Skip to content

chore(deps): bump the rust-dependencies group with 5 updates - #139

Merged
escott- merged 1 commit into
mainfrom
dependabot/cargo/rust-dependencies-29182909d9
Oct 3, 2026
Merged

escott- merged 1 commit into
mainfrom
dependabot/cargo/rust-dependencies-29182909d9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Contributor

Bumps the rust-dependencies group with 5 updates:

Package From To
hyper-util 0.1.20 0.1.21
tiktoken-rs 0.12.0 0.12.1
ignore 0.4.32 0.4.33
tokio-test 0.4.5 0.4.6
console 0.16.4 0.16.6

Updates hyper-util from 0.1.20 to 0.1.21

Release notes

Sourced from hyper-util's releases.

v0.1.21

Additions

  • Add crate-level documentation. (#327)
  • Add client::legacy::Builder::http2_header_table_size() method. (#274)
  • Add client::legacy::Builder::http2_max_concurrent_streams() method. (#274)
  • Add client::legacy::Builder::http2_max_local_error_reset_streams() method. (#277)
  • Add client::legacy::connect::HttpConnector::set_mark() method. (#303)
  • Add rt::tracing::WithSpanExecutor<E>, hyper_util::rt::tracing::CurrentSpanExecutor<E>, and hyper_util::rt::tracing::MkSpanExecutor<E, F> executors. (#323)

Fixes

  • Fix client::legacy::Client so that it properly validates CONNECT responses. (#315)
  • Fix client::legacy::Client to cancel the idle interval once its pool empties. (#292)
  • Fix client::legacy::Client to properly handle IPv6 addresses when using a SOCKS proxy. (#302)
  • Fix client::pool::cache to preserve readiness with clones. (#297)
  • Fix client::pool::cache to wake its waiters in FIFO order. (#298)
  • Fix client::pool::singleton::Singleton to properly handle cancellation. (#299)
  • Fix client::pool::singleton::Singleton to share errors with all waiters. (#296)
  • Fix client::proxy::matcher handling for IP wildcards. (#309)
  • The tokio/net feature is narrowed to the client-legacy feature flag, from the client feature flag. (#276)
  • Various fixes to the client::legacy::Client's SOCKS proxying. (#302) (#307) (#308) (#310)

Changes

This release contains a minor behavioral change for users of the tracing feature flag to be aware of.

This feature flag was introduced in v0.1.11. When enabled, rt::TokioExecutor<E> began propagating the currently active tracing::Span to spawned tasks when hyper::rt::Executor::execute() is called. This caused issues for some users, due to background tasks keeping a span open for the duration of a long-lived connection.

This behavior has now been removed from rt::TokioExecutor<E> (#322) by default. A collection of executor wrappers have been added to a new rt::tracing submodule, to provide facilities for instrumenting a client or server's spawned tasks. See the module-level documentation of rt::tracing for more information.

To temporarily preserve the previous rt::TokioExecutor<E> span propagation behavior, enable the rt-tracing-exec-force feature. Note that this feature flag will be removed in a future release.

This release bumps the minimal supported Rust version (MSRV) from 1.64 to 1.85.

This release bumps the rust edition from 2021 to 2024.

... (truncated)

Changelog

Sourced from hyper-util's changelog.

0.1.21 (2026-09-24)

This release bumps the minimal supported Rust version (MSRV) from 1.64 to 1.85.

This release bumps the rust edition from 2021 to 2024.

Additions

  • Add crate-level documentation. (#327)
  • Add client::legacy::Builder::http2_header_table_size() method. (#274)
  • Add client::legacy::Builder::http2_max_concurrent_streams() method. (#274)
  • Add client::legacy::Builder::http2_max_local_error_reset_streams() method. (#277)
  • Add client::legacy::connect::HttpConnector::set_mark() method. (#303)
  • Add rt::tracing::WithSpanExecutor<E>, hyper_util::rt::tracing::CurrentSpanExecutor<E>, and hyper_util::rt::tracing::MkSpanExecutor<E, F> executors. (#323)

Fixes

  • Fix client::legacy::Client so that it properly validates CONNECT responses. (#315)
  • Fix client::legacy::Client to cancel the idle interval once its pool empties. (#292)
  • Fix client::legacy::Client to properly handle IPv6 addresses when using a SOCKS proxy. (#302)
  • Fix client::pool::cache to preserve readiness with clones. (#297)
  • Fix client::pool::cache to wake its waiters in FIFO order. (#298)
  • Fix client::pool::singleton::Singleton to properly handle cancellation. (#299)
  • Fix client::pool::singleton::Singleton to share errors with all waiters. (#296)
  • Fix client::proxy::matcher handling for IP wildcards. (#309)
  • The tokio/net feature is narrowed to the client-legacy feature flag, from the client feature flag. (#276)
  • Various fixes to the client::legacy::Client's SOCKS proxying. (#302) (#307) (#308) (#310)

Changes

This release contains a minor behavioral change for users of the tracing feature flag to be aware of.

This feature flag was introduced in v0.1.11. When enabled, rt::TokioExecutor<E> began propagating the currently active tracing::Span to spawned tasks when hyper::rt::Executor::execute() is called. This caused issues for some users, due to background tasks keeping a span open for the duration of a long-lived connection.

This behavior has now been removed from rt::TokioExecutor<E> (#322) by default. A collection of executor wrappers have been added to a new rt::tracing submodule, to provide facilities for instrumenting a client or server's spawned tasks. See the module-level documentation of rt::tracing for more information.

To temporarily preserve the previous rt::TokioExecutor<E> span propagation behavior, enable the rt-tracing-exec-force feature. Note that this feature flag will be removed in a future release.

Commits
  • 23a8689 v0.1.21
  • cdb2346 doc(client/pool): add broken_intra_doc_links allowance (#326)
  • 13b6110 chore(error): remove disabled hyper_util::error submodule (#325)
  • b9ee451 docs(lib): add crate-level documentation (#327)
  • d6b7d7e feat(rt/tracing): introduce tracing executors (#323)
  • f2da915 feat(client): add HttpConnector::set_mark for SO_MARK (#303)
  • 4dbd494 feat(rt): change TokioExecutor to not trace, add rt-tracing-exec-force feat...
  • d480d9f fix(client): parse proxy CONNECT response with httparse (#315)
  • 7e0958b chore(ci): simplify msrv check (#317)
  • 0734568 chore(ci): update to actions/checkout@v7 (#316)
  • Additional commits viewable in compare view

Updates tiktoken-rs from 0.12.0 to 0.12.1

Release notes

Sourced from tiktoken-rs's releases.

v0.12.1

A maintenance release that refreshes upstream tiktoken and restores compatibility with the declared Rust 1.85 minimum. Existing public function signatures are unchanged.

Changes

  • Refresh the vendor snapshot to OpenAI tiktoken 0.14.0 and align regex dependencies. GPT-5 tokenizer lookup follows upstream's family-prefix matching. (#173)
  • Use a 1,050,000-token context-window default for gpt-6* names. This adds context metadata only; GPT-6 tokenizer lookup and token-budget helpers remain unsupported. (#174)
  • Fix Rust 1.85 compilation and the default-feature README doctest; test both default and all features across supported platforms. (#170)
  • Replace lazy_static with the standard library's LazyLock. (#165)
  • Clarify README instructions and remove release-specific wording. (#172)
  • Fail release detection on registry errors and remove inactive upload jobs. (#171)

The minimum supported Rust version remains 1.85.

Thanks to @​Expyron for their first contribution in #165.

Full changelog: zurawiki/tiktoken-rs@v0.12.0...v0.12.1

Commits
  • 72a5a80 Release tiktoken-rs 0.12.1 (#175)
  • bd5afd0 Add a default context window for GPT-6 models (#174)
  • 8759c56 Refresh vendored tiktoken to 0.14.0 (#173)
  • f1d1dc3 Clarify README wording and remove release-specific prose (#172)
  • 8364775 Fail release detection on registry errors and remove empty upload jobs (#171)
  • c0961ee Fix and test Rust 1.85 and default-feature support (#170)
  • a79050e Replace lazy_static dependency (#165)
  • See full diff in compare view

Updates ignore from 0.4.32 to 0.4.33

Commits

Updates tokio-test from 0.4.5 to 0.4.6

Commits

Updates console from 0.16.4 to 0.16.6

Release notes

Sourced from console's releases.

0.16.6

What's Changed

0.16.5

What's Changed

Commits
  • 4329b77 Bump version to 0.16.6
  • bdf46b0 utils: wrap tests in module
  • 4f54213 fix: measure the truncation tail in visible columns
  • ed342d0 test: consolidate text width regression coverage
  • 48b99e9 perf: accelerate printable ASCII text width
  • abf0358 Fix truncate_str panicking mid-character without ansi-parsing
  • ac3cb73 Bump version to 0.16.5
  • 97a91ae ansi: strip OSC and DCS sequences
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the rust-dependencies group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [hyper-util](https://github.com/hyperium/hyper-util) | `0.1.20` | `0.1.21` |
| [tiktoken-rs](https://github.com/zurawiki/tiktoken-rs) | `0.12.0` | `0.12.1` |
| [ignore](https://github.com/BurntSushi/ripgrep) | `0.4.32` | `0.4.33` |
| [tokio-test](https://github.com/tokio-rs/tokio) | `0.4.5` | `0.4.6` |
| [console](https://github.com/console-rs/console) | `0.16.4` | `0.16.6` |


Updates `hyper-util` from 0.1.20 to 0.1.21
- [Release notes](https://github.com/hyperium/hyper-util/releases)
- [Changelog](https://github.com/hyperium/hyper-util/blob/master/CHANGELOG.md)
- [Commits](hyperium/hyper-util@v0.1.20...v0.1.21)

Updates `tiktoken-rs` from 0.12.0 to 0.12.1
- [Release notes](https://github.com/zurawiki/tiktoken-rs/releases)
- [Commits](zurawiki/tiktoken-rs@v0.12.0...v0.12.1)

Updates `ignore` from 0.4.32 to 0.4.33
- [Release notes](https://github.com/BurntSushi/ripgrep/releases)
- [Changelog](https://github.com/BurntSushi/ripgrep/blob/master/CHANGELOG.md)
- [Commits](BurntSushi/ripgrep@ignore-0.4.32...ignore-0.4.33)

Updates `tokio-test` from 0.4.5 to 0.4.6
- [Release notes](https://github.com/tokio-rs/tokio/releases)
- [Commits](tokio-rs/tokio@tokio-test-0.4.5...tokio-test-0.4.6)

Updates `console` from 0.16.4 to 0.16.6
- [Release notes](https://github.com/console-rs/console/releases)
- [Changelog](https://github.com/console-rs/console/blob/main/CHANGELOG.md)
- [Commits](console-rs/console@0.16.4...0.16.6)

---
updated-dependencies:
- dependency-name: hyper-util
  dependency-version: 0.1.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: tiktoken-rs
  dependency-version: 0.12.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: ignore
  dependency-version: 0.4.33
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: tokio-test
  dependency-version: 0.4.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: console
  dependency-version: 0.16.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 29, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 29, 2026
@escott-
escott- merged commit 93ec17c into main Oct 3, 2026
0 of 9 checks passed
escott- pushed a commit that referenced this pull request Oct 3, 2026
Bumps actions/checkout 7.0.1, actions/setup-node 7.0.0, actions-rust-lang/setup-rust-toolchain 2.0.0, Swatinem/rust-cache 2.9.2, actions/upload-artifact 7.0.1, actions/download-artifact 8.0.1 and actions/attest-build-provenance 3.0.0. Every pinned SHA was checked against the upstream tag or commit it names. The old rust-cache and attest-build-provenance pins were annotated tag object ids, not commit ids; the new pins are commit ids.

Checked on ovh-desktop with #139, #140, #144 and #145 applied together on main 086e8f5: cargo fmt --check, clippy --locked --workspace --all-targets -D warnings, cargo test --locked --workspace --all-targets (2940 passed, 0 failed), account_connection_smoke (9 tests), plus the public-boundary, release-contract, DCO, workflow, grounding and adoption script tests and npm test.

Signed-off-by: escott- <escott05@gmail.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@dependabot
dependabot Bot deleted the dependabot/cargo/rust-dependencies-29182909d9 branch October 3, 2026 06:22
escott- added a commit that referenced this pull request Oct 3, 2026
Starting or resuming a second session in the same checkout could reset the shared initialization gate and block an already initialized session with "First call required". Initialization is now tracked by the top-level host session id in a separate, locked state file with atomic replacement. Replayed session-start events keep a completed init, and each fresh session still has to initialize. A successful init or context result is recorded in PostToolUse, and the managed post-tool matcher now includes context and session so quick-start grounding is observed.

Checked on ovh-desktop with #139, #140, #144 and #145 applied together on main 086e8f5: cargo fmt --check, clippy --locked --workspace --all-targets -D warnings, cargo test --locked --workspace --all-targets (2940 passed, 0 failed), account_connection_smoke (9 tests), plus the public-boundary, release-contract, DCO, workflow, grounding and adoption script tests and npm test.

Signed-off-by: escott- <escott05@gmail.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
escott- added a commit that referenced this pull request Oct 3, 2026
Bumps the workspace, npm package, MCP Registry metadata, and the boundary self-test to 1.0.12, and adds the 1.0.12 changelog covering #139, #140, #144, and #145.

Updates rustls 0.23.40 -> 0.23.45 and rustls-webpki 0.103.13 -> 0.103.15 for RUSTSEC-2026-0285. The advisory predates 1.0.10 and was present in 1.0.10 and 1.0.11. No other lockfile entries change.

Checked on ovh-desktop against main 7918768 plus this change: cargo fmt --check, clippy -D warnings, cargo test (2940 passed, 0 failed), account_connection_smoke (9 tests), cargo audit and cargo deny (clean), plus the public-boundary, release-contract, DCO, workflow, grounding and adoption script tests and npm test.

Signed-off-by: escott- <escott05@gmail.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant