Skip to content

chore(deps): bump the rust-dependencies group in /rsworkspace with 17 updates - #590

Merged
yordis merged 1 commit into
mainfrom
dependabot/cargo/rsworkspace/rust-dependencies-29aef8e279
Oct 3, 2026
Merged

yordis merged 1 commit into
mainfrom
dependabot/cargo/rsworkspace/rust-dependencies-29aef8e279

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the rust-dependencies group in /rsworkspace with 17 updates:

Package From To
rmcp 3.2.0 3.5.0
async-compat 0.2.5 0.2.6
buffa 0.9.1 0.9.2
buffa-types 0.9.1 0.9.2
futures 0.3.33 0.3.34
tower-http 0.7.0 0.7.1
clap 4.6.6 4.6.7
opentelemetry 0.32.0 0.33.0
opentelemetry-appender-tracing 0.32.0 0.33.0
opentelemetry-otlp 0.32.0 0.33.0
opentelemetry_sdk 0.32.1 0.33.0
tracing-opentelemetry 0.33.0 0.34.0
thiserror 2.0.20 2.0.21
toml 1.1.4+spec-1.1.0 1.1.6+spec-1.1.0
wit-bindgen 0.61.1 0.62.0
jsonwebtoken 11.0.0 11.1.0
rustls 0.23.43 0.23.45

Updates rmcp from 3.2.0 to 3.5.0

Release notes

Sourced from rmcp's releases.

rmcp-macros-v3.5.0

Fixed

  • (macros) accept const paths and concat! in tool/prompt descriptions (#1243)

rmcp-v3.5.0

Added

  • update LATEST and add LATEST_WITH_INITIALIZE (#1105)

Fixed

  • (model) decode float fields through serde_json::Number (#1300)
  • (rmcp) reject duplicate sep-2243 headers (#1274)
  • (transport) match explicit default ports in Origin allowlist (#1270)
  • (rmcp) tolerate empty cacheScope instead of silently dropping the whole result (#1281)
  • (model) preserve explicit null structuredContent in CallToolResult (#1295)

Other

  • cargo fmt fixes on validate_standard_headers changes (#1275)

rmcp-macros-v3.4.1

Fixed

  • (macros) accept const paths and concat! in tool/prompt descriptions (#1243)

rmcp-v3.4.1

Fixed

  • (transport) fall back after JSON discover rejections (#1288)
  • (macros) accept const paths and concat! in tool/prompt descriptions (#1243)

Other

  • (deps) update rstest requirement from 0.26.1 to 0.27.0 (#1276)

rmcp-macros-v3.4.0

Added

  • (model) add ServerConfig and ClientConfig (#1266)

Fixed

  • (model) deprecate ServerInfo and ClientInfo aliases (#1156)

rmcp-v3.4.0

Added

  • (model) add ServerConfig and ClientConfig (#1266)

... (truncated)

Commits
  • 0cde3c5 chore: release v3.5.0 (#1296)
  • e02efbf fix(model): decode float fields through serde_json::Number (#1300)
  • 972af86 feat: update LATEST and add LATEST_WITH_INITIALIZE (#1105)
  • 6e47ca3 chore(deps): bump the github-actions group with 2 updates (#1297)
  • 6255c37 chore: reduce dependency update noise (#1293)
  • 22ef52a fix(rmcp): reject duplicate sep-2243 headers (#1274)
  • 26f3b2e fix(transport): match explicit default ports in Origin allowlist (#1270)
  • 6677eee style: cargo fmt fixes on validate_standard_headers changes (#1275)
  • fbed447 fix(rmcp): tolerate empty cacheScope instead of silently dropping the whole r...
  • 90516bf fix(model): preserve explicit null structuredContent in CallToolResult (#1295)
  • Additional commits viewable in compare view

Updates async-compat from 0.2.5 to 0.2.6

Release notes

Sourced from async-compat's releases.

v0.2.6

  • Add a multi-thread feature for the fallback runtime.
  • Bump MSRV to 1.71.
  • Migrate to Rust 2021.
  • Update reqwest requirement from 0.12 to 0.13 (#48).
  • Update warp requirement from 0.3 to 0.4 (#45).
Changelog

Sourced from async-compat's changelog.

Version 0.2.6

  • Add a multi-thread feature for the fallback runtime.
  • Bump MSRV to 1.71.
  • Migrate to Rust 2021.
  • Update reqwest requirement from 0.12 to 0.13 (#48).
  • Update warp requirement from 0.3 to 0.4 (#45).
Commits
  • 2e5a5d0 Merge pull request #51 from zeenix/release-0.2.6
  • eddbd39 Release 0.2.6
  • 0dfe2dc Merge pull request #50 from MrImmortal09/multi-thread-fallback-runtime
  • 3f5482b Add a multi-thread feature for the fallback runtime
  • 338b0b0 Update reqwest requirement from 0.12 to 0.13 (#48)
  • 32b3569 Bump MSRV to 1.71
  • 165d6e2 ci: Use taiki-e/checkout-action action
  • 22dc95c ci: Add MSRV check
  • aa7d9dd Migrate to Rust 2021
  • 9a179a9 ci: Use reusable workflows for clippy
  • Additional commits viewable in compare view

Updates buffa from 0.9.1 to 0.9.2

Release notes

Sourced from buffa's releases.

v0.9.2

What's Changed

... (truncated)

Changelog

Sourced from buffa's changelog.

[0.9.2] - 2026-09-03

A patch release, and a large one: 55 pull requests from twelve contributors, most of them closing gaps in how buffa bounds untrusted input. 0.9.0 introduced the element-memory budget for the binary decoder; an audit of everything downstream of that decoder found the same fail-open shape repeated — the view and lazy-view entry points, the reflective decoder's packed scalars and enums, the textproto parser, extension records, nested unknown groups, descriptor-pool construction, and serialization of nested google.protobuf.Any — and each is now bounded. That includes the CVE-2026-55407 follow-up reported in #357, where the extension-merge path gave every wire record its own full allowance. The two entries under Security are the stack overflow in reflective Any serialization and the map-entry parser differential between view and owned decoding. If your service decodes protobuf from the network, this is the release to take.

Regenerate your code with a version-matched buffa-codegen. Several fixes live on the generated path: decode_view now attaches the element budget, the view decoders merge split map values the way the owned decoder does, to_dynamic no longer rejects large messages the process built itself, generated enums carry #[allow(non_camel_case_types)], and generated code reaches core::fmt and serde through absolute paths so a proto package named core or serde compiles. buffa-build users pick these up on the next build; protoc-gen-buffa and buf generate users must reinstall the plugin and regenerate — code generated by 0.9.1 still builds and runs against this runtime and gets every runtime-side fix, but keeps the old view decoders until it is regenerated.

The API is additive and MSRV is unchanged at 1.75; the migration surface is behavioural. Every hardening entry turns input that was previously unbounded into a limit error, and beyond those, five changes tighten what ordinary use could previously rely on, each called out in its own entry: the textproto parser applies an element budget by default, so a very large checked-in fixture can now fail to parse until the bound is raised; DynamicMessage charges packed scalars, so a reflective decode of a columnar payload above roughly half a million elements needs with_element_memory_limit raised; DescriptorPool rejects descriptor sets that reuse a reserved name or number, place a field in the 19000–19999 band, start an open enum at a non-zero value, or alias enum values without allow_alias — protoc never emits those, so only hand-built sets are affected; PartialEq for DynamicMessage compares unknown fields, so two messages that differ only in unknown content no longer compare equal; and the ProtoJSON FieldMask helpers now round-trip a leading underscore and reject malformed path components on both codecs. One addition can break a build rather than a decode: buffa-types gains google::protobuf::Option, which shadows the prelude Option in any module that glob-imports google::protobuf::*.

Beyond the hardening: SharedCorpusContext and shared_descriptor_pool cut codegen time and duplicated descriptor bytes for workspaces that generate one crate per package; DynamicMessage::try_from_message is a fallible bridge from a generated message; buffa-types now ships the complete well-known set, so googleapis compiles; exclude_package drops packages from a buffa-build run; the plugin gains unbox_oneof and shared_descriptor_pool options; and SizeCache panic sites are gated on debug_assertions, shrinking generated compute_size.

Added

  • CodeGenConfig::shared_descriptor_pool emits the reflection descriptor set once at the module-tree root instead of once per package (#311). When enabled, per-package __buffa::reflect modules delegate to a single shared __buffa_fds module; every consumer path (pkg::descriptor_pool(), pkg::FILE_DESCRIPTOR_SET_BYTES) keeps resolving as an alias, and all packages observe one DescriptorPool. Adds the encode_descriptor_set, shared_descriptor_root_module, FdsEmbedding, and CodeGenConfig::reflect_feature_gate surface that front-ends use to emit the shared module.

  • shared_descriptor_pool=true plugin option on protoc-gen-buffa and protoc-gen-buffa-packaging (#370) — enables the shared descriptor pool (see CodeGenConfig::shared_descriptor_pool) on the plugin path. Set it on both plugins (same name on both, like exclude_package). Rejected together with feature overrides, feature-gating, or file_per_package, which the plugin path cannot support.

  • buffa_build::Config::shared_descriptor_pool enables the shared descriptor pool from build.rs (#369). The descriptor set is written once as a binary sidecar next to the generated tree and include_bytes!-d by the shared __buffa_fds module, removing both the per-package duplication and the byte-literal source expansion. Requires reflection and .include_file(...). With a checked-in out_dir, commit the emitted *.descriptor_set.binpb sidecar alongside the generated .rs.

  • DynamicMessage::decode_with_options and merge_with_options decode under caller-supplied limits (#341), mirroring DescriptorPool::decode_with_options.

  • TextDecoder::with_element_memory_limit and buffa::text::decode_from_str_with_element_memory_limit raise the textproto parser bound above the default (#344), reported past the limit as the new ParseErrorKind::ElementMemoryLimitExceeded variant.

  • A defaulted SingularCodec::decode_one_ctx lets repeated extension elements share one decode budget (#345). Existing implementations need no change; the default forwards to decode_one, which is correct for any codec with a fixed per-record cost. A codec whose value can materialize an unbounded subtree must override it.

  • buffa_descriptor::MAX_SYMBOL_LEN and the PoolError::NameTooLong variant (#347). PoolError is #[non_exhaustive], so the variant is additive.

  • generate_with_diagnostics warns when a kept file references a type from an excluded or unmapped package (#352, closes #292). generate_with_diagnostics now emits a CodeGenWarning::ExcludedPackageFieldRef when a field in a kept file references a type that is neither being generated nor covered by an extern_path. The warning precedes the consumer's build, so the dangling super::…::Type compile error is accompanied by an actionable diagnostic that names the file, message, and field where the reference appears, the missing package, and the exact extern_path or .files() fix. Detection is type-granular: references to a specific type from a partially-generated package are correctly flagged even when other types in the same package are being generated.

  • buffa-build: Config::exclude_package knob (#383, closes #293). Config::exclude_package("buf.validate") (or .exclude_package(".buf.validate")) drops all .proto files in that package — and any sub-packages — from code generation. Multiple calls accumulate. The same knob is exposed as exclude_package=<pkg> in the protoc-gen-buffa plugin option string and as CodeGenConfig::exclude_packages for direct codegen users. An entry that matches no package in the input now raises CodeGenWarning::ExcludePackageMatchedNothing (a cargo:warning from buffa-build).

  • protoc-gen-buffa gains unbox_oneof=true and repeatable unbox_oneof_in=<path> options (#392), the plugin equivalents of buffa_build::Config::unbox_oneof() / unbox_oneof_in(&[..]), opting non-recursive message/group oneof variants into inline storage. Paths are normalized like the other path-scoped options (leading dot optional, whitespace and trailing dots stripped); an empty path is rejected rather than treated as the blanket rule.

  • buffa-types ships google.protobuf.Api, Type, Enum, and SourceContext (#394, closes #382). Codegen auto-maps the whole .google.protobuf package to buffa-types, so compiling googleapis (or any schema importing api.proto / type.proto / source_context.proto) failed with cannot find type Api / TypeView / EnumView. The three files are the rest of the official well-known set; they are vendored at protobuf v33.5 and generated next to Timestamp/Any, with binary, view, and text codecs and textproto Any expansion. They have no Serialize/Deserialize impls, so a json = true message that embeds one of them does not compile; map the type to a locally generated copy with extern_path if JSON is needed. One of the new types is google::protobuf::Option, which is not re-exported at the crate root: a module that glob-imports buffa_types::google::protobuf::* now has it shadowing the prelude Option, and Option<T> there fails with E0107 — import the types you use by name.

  • SharedCorpusContext lets a workspace that generates one crate per proto package pay the corpus-wide codegen analysis once (#401, closes #400). generate() re-derives which oneof variants are unboxed, which message fields are stored inline, and the per-symbol comment map from the whole FileDescriptorSet on every call, although none of that depends on the per-package extern_paths; a ~2900-package workspace paid that walk 2900 times. Build a SharedCorpusContext::new(&files, &config) once and set CodeGenConfig::shared_corpus_context on each per-package config; the output is byte-identical, and a context built from a different corpus or different oneof/pointer-repr rules is refused with CodeGenError::SharedCorpusContextMismatch rather than silently resolving against the wrong one. The corpus comparison is structural, not by file name, so a regenerated FileDescriptorSet with edited content is refused too; it costs O(corpus) per call, measured at roughly a quarter of the name-only comparison's saving on that workspace and still well ahead of not sharing. Off by default.

  • CodeGenConfig::shared_descriptor_pool_root (#399): override the computed super::-relative path to the shared __buffa_fds root in shared-pool mode (shared_descriptor_pool) with a caller-supplied path, for workspaces where one crate does not host the whole package tree as nested modules (e.g. one independent Cargo crate per proto package). None (the default) keeps the existing super::-relative behaviour — purely additive, no change to any existing consumer. Reachable only by direct buffa-codegen callers this release; buffa-build and the protoc-gen-buffa* plugins do not expose it yet.

  • DynamicMessage::try_from_message: a fallible, name-resolving bridge from a generated message (#414, refs #413). Resolves the descriptor from the type's MessageName and returns a new BridgeError (MessageNotFound / MessageTooLarge / Decode, re-exported from buffa_descriptor::reflect and the crate root) instead of panicking when the pool lacks the type or the encoded bytes fail to decode against its descriptor. DynamicMessage::try_from_message_with_index is the fallible form for callers that already hold a MessageIndex; from_message now shares its decode step. The bridge uses the same encoded-length-scaled memory budgets as generated ReflectMessage::to_dynamic, so large generated messages avoid false ElementMemoryLimitExceeded failures without making the second representation unbounded.

Changed

  • Two decode-limit documentation claims corrected (#349). The unknown-field count limit was described as capping overhead at roughly limit x 40 bytes; that holds for flat input only, and nested groups are now charged separately (see the Fixed entry for #349). And the Map hasher docs described the foldhash process-wide seed as mixing ASLR addresses with process start time; that holds on std, but no_std builds drop the clock and allocator entropy, and on a bare-metal target with no ASLR the seed is a link-time constant, so a colliding key set can be precomputed from the firmware image. These two corrections are documentation-only.

  • SizeCache panic locations are now gated on debug_assertions, shrinking generated code (#366). Generated compute_size calls SizeCache::set once per length-delimited sub-message field, and generated write_to calls consume_next once as well, so a large schema produces hundreds to thousands of call sites for each. Both carried #[track_caller], which materializes a Location record at every one of them, and set inlined a formatted assert! panic block on top of that. The attribute is now gated on debug_assertions and set's panic joins consume_next's out of line. Measured on a ~1000-message schema linked into a 13.2 MiB binary (fat LTO, codegen-units = 1, panic = "abort", stripped): 1068 Location records removed, and 106 KiB (0.79%) off the linked binary. Both bound checks still run, with the same conditions and messages as before. What changes is that a violation reports a location inside buffa rather than in your compute_size / write_to. The gate follows the profile buffa itself was compiled with; to get caller locations back in a release build, set [profile.release.package.buffa] debug-assertions = true (which also enables buffa's other debug assertions, so treat it as a diagnostic setting).

... (truncated)

Commits
  • 1f5d80e release: v0.9.2 (#424)
  • 5a3f293 codegen: precompute corpus-wide context once and share across generate() call...
  • 71fed8c reflect: add DynamicMessage::try_from_message and BridgeError (#414)
  • 8adabe1 descriptor: reject duplicate enum numbers without aliases (#410)
  • 836a39f descriptor: reject reserved enum values (#405)
  • 0c617a9 descriptor: reject nonzero first value for open enums (#411)
  • 32f4cea descriptor: reject message-reserved fields (#412)
  • d0ee852 codegen: suppress non_camel_case_types warning on enums (#408) (#409)
  • f004f70 text: accept comments in signed special floats (#404)
  • dd37a9b json: reject empty Any type name (#402)
  • Additional commits viewable in compare view

Updates buffa-types from 0.9.1 to 0.9.2

Release notes

Sourced from buffa-types's releases.

v0.9.2

What's Changed

... (truncated)

Changelog

Sourced from buffa-types's changelog.

[0.9.2] - 2026-09-03

A patch release, and a large one: 55 pull requests from twelve contributors, most of them closing gaps in how buffa bounds untrusted input. 0.9.0 introduced the element-memory budget for the binary decoder; an audit of everything downstream of that decoder found the same fail-open shape repeated — the view and lazy-view entry points, the reflective decoder's packed scalars and enums, the textproto parser, extension records, nested unknown groups, descriptor-pool construction, and serialization of nested google.protobuf.Any — and each is now bounded. That includes the CVE-2026-55407 follow-up reported in #357, where the extension-merge path gave every wire record its own full allowance. The two entries under Security are the stack overflow in reflective Any serialization and the map-entry parser differential between view and owned decoding. If your service decodes protobuf from the network, this is the release to take.

Regenerate your code with a version-matched buffa-codegen. Several fixes live on the generated path: decode_view now attaches the element budget, the view decoders merge split map values the way the owned decoder does, to_dynamic no longer rejects large messages the process built itself, generated enums carry #[allow(non_camel_case_types)], and generated code reaches core::fmt and serde through absolute paths so a proto package named core or serde compiles. buffa-build users pick these up on the next build; protoc-gen-buffa and buf generate users must reinstall the plugin and regenerate — code generated by 0.9.1 still builds and runs against this runtime and gets every runtime-side fix, but keeps the old view decoders until it is regenerated.

The API is additive and MSRV is unchanged at 1.75; the migration surface is behavioural. Every hardening entry turns input that was previously unbounded into a limit error, and beyond those, five changes tighten what ordinary use could previously rely on, each called out in its own entry: the textproto parser applies an element budget by default, so a very large checked-in fixture can now fail to parse until the bound is raised; DynamicMessage charges packed scalars, so a reflective decode of a columnar payload above roughly half a million elements needs with_element_memory_limit raised; DescriptorPool rejects descriptor sets that reuse a reserved name or number, place a field in the 19000–19999 band, start an open enum at a non-zero value, or alias enum values without allow_alias — protoc never emits those, so only hand-built sets are affected; PartialEq for DynamicMessage compares unknown fields, so two messages that differ only in unknown content no longer compare equal; and the ProtoJSON FieldMask helpers now round-trip a leading underscore and reject malformed path components on both codecs. One addition can break a build rather than a decode: buffa-types gains google::protobuf::Option, which shadows the prelude Option in any module that glob-imports google::protobuf::*.

Beyond the hardening: SharedCorpusContext and shared_descriptor_pool cut codegen time and duplicated descriptor bytes for workspaces that generate one crate per package; DynamicMessage::try_from_message is a fallible bridge from a generated message; buffa-types now ships the complete well-known set, so googleapis compiles; exclude_package drops packages from a buffa-build run; the plugin gains unbox_oneof and shared_descriptor_pool options; and SizeCache panic sites are gated on debug_assertions, shrinking generated compute_size.

Added

  • CodeGenConfig::shared_descriptor_pool emits the reflection descriptor set once at the module-tree root instead of once per package (#311). When enabled, per-package __buffa::reflect modules delegate to a single shared __buffa_fds module; every consumer path (pkg::descriptor_pool(), pkg::FILE_DESCRIPTOR_SET_BYTES) keeps resolving as an alias, and all packages observe one DescriptorPool. Adds the encode_descriptor_set, shared_descriptor_root_module, FdsEmbedding, and CodeGenConfig::reflect_feature_gate surface that front-ends use to emit the shared module.

  • shared_descriptor_pool=true plugin option on protoc-gen-buffa and protoc-gen-buffa-packaging (#370) — enables the shared descriptor pool (see CodeGenConfig::shared_descriptor_pool) on the plugin path. Set it on both plugins (same name on both, like exclude_package). Rejected together with feature overrides, feature-gating, or file_per_package, which the plugin path cannot support.

  • buffa_build::Config::shared_descriptor_pool enables the shared descriptor pool from build.rs (#369). The descriptor set is written once as a binary sidecar next to the generated tree and include_bytes!-d by the shared __buffa_fds module, removing both the per-package duplication and the byte-literal source expansion. Requires reflection and .include_file(...). With a checked-in out_dir, commit the emitted *.descriptor_set.binpb sidecar alongside the generated .rs.

  • DynamicMessage::decode_with_options and merge_with_options decode under caller-supplied limits (#341), mirroring DescriptorPool::decode_with_options.

  • TextDecoder::with_element_memory_limit and buffa::text::decode_from_str_with_element_memory_limit raise the textproto parser bound above the default (#344), reported past the limit as the new ParseErrorKind::ElementMemoryLimitExceeded variant.

  • A defaulted SingularCodec::decode_one_ctx lets repeated extension elements share one decode budget (#345). Existing implementations need no change; the default forwards to decode_one, which is correct for any codec with a fixed per-record cost. A codec whose value can materialize an unbounded subtree must override it.

  • buffa_descriptor::MAX_SYMBOL_LEN and the PoolError::NameTooLong variant (#347). PoolError is #[non_exhaustive], so the variant is additive.

  • generate_with_diagnostics warns when a kept file references a type from an excluded or unmapped package (#352, closes #292). generate_with_diagnostics now emits a CodeGenWarning::ExcludedPackageFieldRef when a field in a kept file references a type that is neither being generated nor covered by an extern_path. The warning precedes the consumer's build, so the dangling super::…::Type compile error is accompanied by an actionable diagnostic that names the file, message, and field where the reference appears, the missing package, and the exact extern_path or .files() fix. Detection is type-granular: references to a specific type from a partially-generated package are correctly flagged even when other types in the same package are being generated.

  • buffa-build: Config::exclude_package knob (#383, closes #293). Config::exclude_package("buf.validate") (or .exclude_package(".buf.validate")) drops all .proto files in that package — and any sub-packages — from code generation. Multiple calls accumulate. The same knob is exposed as exclude_package=<pkg> in the protoc-gen-buffa plugin option string and as CodeGenConfig::exclude_packages for direct codegen users. An entry that matches no package in the input now raises CodeGenWarning::ExcludePackageMatchedNothing (a cargo:warning from buffa-build).

  • protoc-gen-buffa gains unbox_oneof=true and repeatable unbox_oneof_in=<path> options (#392), the plugin equivalents of buffa_build::Config::unbox_oneof() / unbox_oneof_in(&[..]), opting non-recursive message/group oneof variants into inline storage. Paths are normalized like the other path-scoped options (leading dot optional, whitespace and trailing dots stripped); an empty path is rejected rather than treated as the blanket rule.

  • buffa-types ships google.protobuf.Api, Type, Enum, and SourceContext (View with [code]smith Autofix with [code]smith
    Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Bumps the rust-dependencies group in /rsworkspace with 17 updates:

| Package | From | To |
| --- | --- | --- |
| [rmcp](https://github.com/modelcontextprotocol/rust-sdk) | `3.2.0` | `3.5.0` |
| [async-compat](https://github.com/smol-rs/async-compat) | `0.2.5` | `0.2.6` |
| [buffa](https://github.com/anthropics/buffa) | `0.9.1` | `0.9.2` |
| [buffa-types](https://github.com/anthropics/buffa) | `0.9.1` | `0.9.2` |
| [futures](https://github.com/rust-lang/futures-rs) | `0.3.33` | `0.3.34` |
| [tower-http](https://github.com/tower-rs/tower-http) | `0.7.0` | `0.7.1` |
| [clap](https://github.com/clap-rs/clap) | `4.6.6` | `4.6.7` |
| [opentelemetry](https://github.com/open-telemetry/opentelemetry-rust) | `0.32.0` | `0.33.0` |
| [opentelemetry-appender-tracing](https://github.com/open-telemetry/opentelemetry-rust) | `0.32.0` | `0.33.0` |
| [opentelemetry-otlp](https://github.com/open-telemetry/opentelemetry-rust) | `0.32.0` | `0.33.0` |
| [opentelemetry_sdk](https://github.com/open-telemetry/opentelemetry-rust) | `0.32.1` | `0.33.0` |
| [tracing-opentelemetry](https://github.com/tokio-rs/tracing-opentelemetry) | `0.33.0` | `0.34.0` |
| [thiserror](https://github.com/dtolnay/thiserror) | `2.0.20` | `2.0.21` |
| [toml](https://github.com/toml-rs/toml) | `1.1.4+spec-1.1.0` | `1.1.6+spec-1.1.0` |
| [wit-bindgen](https://github.com/bytecodealliance/wit-bindgen) | `0.61.1` | `0.62.0` |
| [jsonwebtoken](https://github.com/Keats/jsonwebtoken) | `11.0.0` | `11.1.0` |
| [rustls](https://github.com/rustls/rustls) | `0.23.43` | `0.23.45` |


Updates `rmcp` from 3.2.0 to 3.5.0
- [Release notes](https://github.com/modelcontextprotocol/rust-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/rust-sdk/blob/main/release-plz.toml)
- [Commits](modelcontextprotocol/rust-sdk@rmcp-v3.2.0...rmcp-v3.5.0)

Updates `async-compat` from 0.2.5 to 0.2.6
- [Release notes](https://github.com/smol-rs/async-compat/releases)
- [Changelog](https://github.com/smol-rs/async-compat/blob/master/CHANGELOG.md)
- [Commits](smol-rs/async-compat@v0.2.5...v0.2.6)

Updates `buffa` from 0.9.1 to 0.9.2
- [Release notes](https://github.com/anthropics/buffa/releases)
- [Changelog](https://github.com/anthropics/buffa/blob/main/CHANGELOG.md)
- [Commits](anthropics/buffa@v0.9.1...v0.9.2)

Updates `buffa-types` from 0.9.1 to 0.9.2
- [Release notes](https://github.com/anthropics/buffa/releases)
- [Changelog](https://github.com/anthropics/buffa/blob/main/CHANGELOG.md)
- [Commits](anthropics/buffa@v0.9.1...v0.9.2)

Updates `futures` from 0.3.33 to 0.3.34
- [Release notes](https://github.com/rust-lang/futures-rs/releases)
- [Changelog](https://github.com/rust-lang/futures-rs/blob/main/CHANGELOG.md)
- [Commits](rust-lang/futures-rs@0.3.33...0.3.34)

Updates `tower-http` from 0.7.0 to 0.7.1
- [Release notes](https://github.com/tower-rs/tower-http/releases)
- [Commits](tower-rs/tower-http@tower-http-0.7.0...tower-http-0.7.1)

Updates `clap` from 4.6.6 to 4.6.7
- [Release notes](https://github.com/clap-rs/clap/releases)
- [Changelog](https://github.com/clap-rs/clap/blob/main/CHANGELOG.md)
- [Commits](clap-rs/clap@clap_complete-v4.6.6...clap_complete-v4.6.7)

Updates `opentelemetry` from 0.32.0 to 0.33.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-rust/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-rust/blob/opentelemetry-0.33.0/docs/release_0.33.md)
- [Commits](open-telemetry/opentelemetry-rust@opentelemetry-0.32.0...opentelemetry-0.33.0)

Updates `opentelemetry-appender-tracing` from 0.32.0 to 0.33.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-rust/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-rust/blob/opentelemetry-appender-tracing-0.33.0/docs/release_0.33.md)
- [Commits](open-telemetry/opentelemetry-rust@opentelemetry-appender-tracing-0.32.0...opentelemetry-appender-tracing-0.33.0)

Updates `opentelemetry-otlp` from 0.32.0 to 0.33.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-rust/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-rust/blob/opentelemetry-otlp-0.33.0/docs/release_0.33.md)
- [Commits](open-telemetry/opentelemetry-rust@opentelemetry-otlp-0.32.0...opentelemetry-otlp-0.33.0)

Updates `opentelemetry_sdk` from 0.32.1 to 0.33.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-rust/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-rust/blob/opentelemetry_sdk-0.33.0/docs/release_0.33.md)
- [Commits](open-telemetry/opentelemetry-rust@opentelemetry-semantic-conventions-0.32.1...opentelemetry_sdk-0.33.0)

Updates `tracing-opentelemetry` from 0.33.0 to 0.34.0
- [Release notes](https://github.com/tokio-rs/tracing-opentelemetry/releases)
- [Changelog](https://github.com/tokio-rs/tracing-opentelemetry/blob/v0.1.x/CHANGELOG.md)
- [Commits](https://github.com/tokio-rs/tracing-opentelemetry/commits)

Updates `thiserror` from 2.0.20 to 2.0.21
- [Release notes](https://github.com/dtolnay/thiserror/releases)
- [Commits](dtolnay/thiserror@2.0.20...2.0.21)

Updates `toml` from 1.1.4+spec-1.1.0 to 1.1.6+spec-1.1.0
- [Commits](toml-rs/toml@toml-v1.1.4...toml-v1.1.6)

Updates `wit-bindgen` from 0.61.1 to 0.62.0
- [Release notes](https://github.com/bytecodealliance/wit-bindgen/releases)
- [Commits](bytecodealliance/wit-bindgen@v0.61.1...v0.62.0)

Updates `jsonwebtoken` from 11.0.0 to 11.1.0
- [Changelog](https://github.com/Keats/jsonwebtoken/blob/master/CHANGELOG.md)
- [Commits](Keats/jsonwebtoken@v11.0.0...v11.1.0)

Updates `rustls` from 0.23.43 to 0.23.45
- [Release notes](https://github.com/rustls/rustls/releases)
- [Changelog](https://github.com/rustls/rustls/blob/main/CHANGELOG.md)
- [Commits](rustls/rustls@v/0.23.43...v/0.23.45)

---
updated-dependencies:
- dependency-name: rmcp
  dependency-version: 3.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-dependencies
- dependency-name: async-compat
  dependency-version: 0.2.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: buffa
  dependency-version: 0.9.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: buffa-types
  dependency-version: 0.9.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: futures
  dependency-version: 0.3.34
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: tower-http
  dependency-version: 0.7.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: clap
  dependency-version: 4.6.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: opentelemetry
  dependency-version: 0.33.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-dependencies
- dependency-name: opentelemetry-appender-tracing
  dependency-version: 0.33.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-dependencies
- dependency-name: opentelemetry-otlp
  dependency-version: 0.33.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-dependencies
- dependency-name: opentelemetry_sdk
  dependency-version: 0.33.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-dependencies
- dependency-name: tracing-opentelemetry
  dependency-version: 0.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-dependencies
- dependency-name: thiserror
  dependency-version: 2.0.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: toml
  dependency-version: 1.1.6+spec-1.1.0
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: wit-bindgen
  dependency-version: 0.62.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-dependencies
- dependency-name: jsonwebtoken
  dependency-version: 11.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-dependencies
- dependency-name: rustls
  dependency-version: 0.23.45
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 1, 2026
@cursor

cursor Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Touches TLS (rustls), JWT validation, protobuf decoding limits (buffa), MCP protocol handling (rmcp), WASM bindings (wit-bindgen), and telemetry export (OpenTelemetry)—areas where patch/minor releases can change runtime behavior even without code edits.

Overview
Updates workspace dependency pins in rsworkspace/Cargo.toml and regenerates Cargo.lock for a batch of third-party bumps (Dependabot “rust-dependencies” group).

Notable version changes: rmcp 3.2→3.5 (MCP transport/model fixes), buffa / buffa-types 0.9.1→0.9.2 (protobuf decode hardening and related behavioral limits), OpenTelemetry crates 0.32→0.33 plus tracing-opentelemetry 0.33→0.34, wit-bindgen 0.61→0.62 (WASM guest/decider toolchain), rustls 0.23.43→0.23.45 and jsonwebtoken 11.0→11.1, plus smaller bumps (futures, clap, tower-http, thiserror, toml, async-compat, etc.).

The lockfile also drops crates that are no longer pulled into the resolved graph (e.g. some gateway/scheduler/sqlx/twilight-related entries), alongside transitive updates such as syn 3.0.6 and simplified tower-http / WebSocket dependency edges—without application source changes in this diff.

Reviewed by Cursor Bugbot for commit e8eee87. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 189e13be-ea37-4d8a-af10-8039305d24f1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@yordis
yordis merged commit 25829fb into main Oct 3, 2026
11 of 18 checks passed
@yordis
yordis deleted the dependabot/cargo/rsworkspace/rust-dependencies-29aef8e279 branch October 3, 2026 08:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant