Repository navigation
chore(deps): bump the rust-dependencies group with 5 updates - #139
Merged
Merged
Conversation
Bumps the rust-dependencies group with 5 updates: | Package | From | To | | --- | --- | --- | | [hyper-util](https://github.com/hyperium/hyper-util) | `0.1.20` | `0.1.21` | | [tiktoken-rs](https://github.com/zurawiki/tiktoken-rs) | `0.12.0` | `0.12.1` | | [ignore](https://github.com/BurntSushi/ripgrep) | `0.4.32` | `0.4.33` | | [tokio-test](https://github.com/tokio-rs/tokio) | `0.4.5` | `0.4.6` | | [console](https://github.com/console-rs/console) | `0.16.4` | `0.16.6` | Updates `hyper-util` from 0.1.20 to 0.1.21 - [Release notes](https://github.com/hyperium/hyper-util/releases) - [Changelog](https://github.com/hyperium/hyper-util/blob/master/CHANGELOG.md) - [Commits](hyperium/hyper-util@v0.1.20...v0.1.21) Updates `tiktoken-rs` from 0.12.0 to 0.12.1 - [Release notes](https://github.com/zurawiki/tiktoken-rs/releases) - [Commits](zurawiki/tiktoken-rs@v0.12.0...v0.12.1) Updates `ignore` from 0.4.32 to 0.4.33 - [Release notes](https://github.com/BurntSushi/ripgrep/releases) - [Changelog](https://github.com/BurntSushi/ripgrep/blob/master/CHANGELOG.md) - [Commits](BurntSushi/ripgrep@ignore-0.4.32...ignore-0.4.33) Updates `tokio-test` from 0.4.5 to 0.4.6 - [Release notes](https://github.com/tokio-rs/tokio/releases) - [Commits](tokio-rs/tokio@tokio-test-0.4.5...tokio-test-0.4.6) Updates `console` from 0.16.4 to 0.16.6 - [Release notes](https://github.com/console-rs/console/releases) - [Changelog](https://github.com/console-rs/console/blob/main/CHANGELOG.md) - [Commits](console-rs/console@0.16.4...0.16.6) --- updated-dependencies: - dependency-name: hyper-util dependency-version: 0.1.21 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: rust-dependencies - dependency-name: tiktoken-rs dependency-version: 0.12.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: rust-dependencies - dependency-name: ignore dependency-version: 0.4.33 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: rust-dependencies - dependency-name: tokio-test dependency-version: 0.4.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: rust-dependencies - dependency-name: console dependency-version: 0.16.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: rust-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
escott-
pushed a commit
that referenced
this pull request
Oct 3, 2026
Bumps actions/checkout 7.0.1, actions/setup-node 7.0.0, actions-rust-lang/setup-rust-toolchain 2.0.0, Swatinem/rust-cache 2.9.2, actions/upload-artifact 7.0.1, actions/download-artifact 8.0.1 and actions/attest-build-provenance 3.0.0. Every pinned SHA was checked against the upstream tag or commit it names. The old rust-cache and attest-build-provenance pins were annotated tag object ids, not commit ids; the new pins are commit ids. Checked on ovh-desktop with #139, #140, #144 and #145 applied together on main 086e8f5: cargo fmt --check, clippy --locked --workspace --all-targets -D warnings, cargo test --locked --workspace --all-targets (2940 passed, 0 failed), account_connection_smoke (9 tests), plus the public-boundary, release-contract, DCO, workflow, grounding and adoption script tests and npm test. Signed-off-by: escott- <escott05@gmail.com> Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
dependabot
Bot
deleted the
dependabot/cargo/rust-dependencies-29182909d9
branch
October 3, 2026 06:22
escott-
added a commit
that referenced
this pull request
Oct 3, 2026
Starting or resuming a second session in the same checkout could reset the shared initialization gate and block an already initialized session with "First call required". Initialization is now tracked by the top-level host session id in a separate, locked state file with atomic replacement. Replayed session-start events keep a completed init, and each fresh session still has to initialize. A successful init or context result is recorded in PostToolUse, and the managed post-tool matcher now includes context and session so quick-start grounding is observed. Checked on ovh-desktop with #139, #140, #144 and #145 applied together on main 086e8f5: cargo fmt --check, clippy --locked --workspace --all-targets -D warnings, cargo test --locked --workspace --all-targets (2940 passed, 0 failed), account_connection_smoke (9 tests), plus the public-boundary, release-contract, DCO, workflow, grounding and adoption script tests and npm test. Signed-off-by: escott- <escott05@gmail.com> Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
escott-
added a commit
that referenced
this pull request
Oct 3, 2026
Bumps the workspace, npm package, MCP Registry metadata, and the boundary self-test to 1.0.12, and adds the 1.0.12 changelog covering #139, #140, #144, and #145. Updates rustls 0.23.40 -> 0.23.45 and rustls-webpki 0.103.13 -> 0.103.15 for RUSTSEC-2026-0285. The advisory predates 1.0.10 and was present in 1.0.10 and 1.0.11. No other lockfile entries change. Checked on ovh-desktop against main 7918768 plus this change: cargo fmt --check, clippy -D warnings, cargo test (2940 passed, 0 failed), account_connection_smoke (9 tests), cargo audit and cargo deny (clean), plus the public-boundary, release-contract, DCO, workflow, grounding and adoption script tests and npm test. Signed-off-by: escott- <escott05@gmail.com> Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the rust-dependencies group with 5 updates:
0.1.200.1.210.12.00.12.10.4.320.4.330.4.50.4.60.16.40.16.6Updates
hyper-utilfrom 0.1.20 to 0.1.21Release notes
Sourced from hyper-util's releases.
... (truncated)
Changelog
Sourced from hyper-util's changelog.
Commits
23a8689v0.1.21cdb2346doc(client/pool): addbroken_intra_doc_linksallowance (#326)13b6110chore(error): remove disabledhyper_util::errorsubmodule (#325)b9ee451docs(lib): add crate-level documentation (#327)d6b7d7efeat(rt/tracing): introduce tracing executors (#323)f2da915feat(client): add HttpConnector::set_mark for SO_MARK (#303)4dbd494feat(rt): changeTokioExecutorto not trace, add rt-tracing-exec-force feat...d480d9ffix(client): parse proxy CONNECT response with httparse (#315)7e0958bchore(ci): simplify msrv check (#317)0734568chore(ci): update to actions/checkout@v7 (#316)Updates
tiktoken-rsfrom 0.12.0 to 0.12.1Release notes
Sourced from tiktoken-rs's releases.
Commits
72a5a80Release tiktoken-rs 0.12.1 (#175)bd5afd0Add a default context window for GPT-6 models (#174)8759c56Refresh vendored tiktoken to 0.14.0 (#173)f1d1dc3Clarify README wording and remove release-specific prose (#172)8364775Fail release detection on registry errors and remove empty upload jobs (#171)c0961eeFix and test Rust 1.85 and default-feature support (#170)a79050eReplacelazy_staticdependency (#165)Updates
ignorefrom 0.4.32 to 0.4.33Commits
3fce3b5ignore-0.4.335055264globset-0.4.20020687aignore,globset: increase pool capacityUpdates
tokio-testfrom 0.4.5 to 0.4.6Commits
f987088chore: prepare tokio-test 0.4.6 (#8508)1daf3c5io: add inspect adapter accessors (#8486)ec6d2afstream: implementFusedStreamforThrottle(#8485)3930bd1net: add Safety docs and Default impls for named pipe options (#8378)e37e284io: retry onInterruptedin more operations (#8460)e43fb07rt: suggest.awaitin nestedblock_onpanic (#8501)2ebac75stream: implementFusedStreamfor MPSC receiver wrappers (#8500)9bc516astream: clarify readiness docs for basic streams (#8495)5d5ca11rt: avoid overflow inshutdown_timeout()(#8497)dd826efio: reject zero capacity in BufReader (#8494)Updates
consolefrom 0.16.4 to 0.16.6Release notes
Sourced from console's releases.
Commits
4329b77Bump version to 0.16.6bdf46b0utils: wrap tests in module4f54213fix: measure the truncation tail in visible columnsed342d0test: consolidate text width regression coverage48b99e9perf: accelerate printable ASCII text widthabf0358Fix truncate_str panicking mid-character without ansi-parsingac3cb73Bump version to 0.16.597a91aeansi: strip OSC and DCS sequencesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions