Skip to content

chore(deps): bump the rust-dependencies group across 1 directory with 8 updates - #153

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/cargo/rust-dependencies-f71bb73959
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/cargo/rust-dependencies-f71bb73959

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Bumps the rust-dependencies group with 8 updates in the / directory:

Package From To
tokio 1.53.1 1.53.2
clap_complete 4.6.10 4.6.11
thiserror 2.0.20 2.0.21
rmcp 3.3.0 3.5.0
jsonwebtoken 11.0.0 11.1.0
libc 0.2.189 0.2.190
tokio-test 0.4.5 0.4.6
insta 1.48.0 1.49.0

Updates tokio from 1.53.1 to 1.53.2

Release notes

Sourced from tokio's releases.

Tokio v1.53.2

1.53.2 (October 3rd, 2026)

Fixed

  • fs: handle integer overflow in buffered relative seek (#8574)
  • io: revert "always cleanup AsyncFd registration list on deregister" (#8540)
  • process: unregister Windows wait before closing child handle (#8564)
  • rt: drop blocking pool mutex before shutting down rejected task (#8562)
  • sync: fix mpsc index wraparound in block reclamation (#8546)
  • sync: forget mpsc Permit before sending value (#8560)
  • sync: validate MAX_PERMITS in Semaphore::acquire (#8548)
  • sync: wake broadcast Sender::closed outside mutex (#8558)
  • task: drop replaced waker outside lock in JoinSet (#8554)
  • time: drop timer lock before dropping waker in clear_entry (#8552)
  • time: expire timers directly on shutdown without rotating wheel (#8570)

Fixed (unstable)

  • fs: clamp io_uring read length to u32::MAX (#8572)
  • rt: ignore current_thread task dumps from other runtimes (#8544)
  • rt: preserve io_uring context if a completion waker panics (#8566)
  • sync: fix semaphore use-after-free and permit leak on tracing panic (#8542)
  • taskdump: restore deferred leaf wakes during capture (#8445)
  • time: drop stored waker when cancelling alt timer entry (#8550)

#8445: tokio-rs/tokio#8445 #8572: tokio-rs/tokio#8572 #8540: tokio-rs/tokio#8540 #8542: tokio-rs/tokio#8542 #8544: tokio-rs/tokio#8544 #8546: tokio-rs/tokio#8546 #8548: tokio-rs/tokio#8548 #8550: tokio-rs/tokio#8550 #8552: tokio-rs/tokio#8552 #8554: tokio-rs/tokio#8554 #8558: tokio-rs/tokio#8558 #8560: tokio-rs/tokio#8560 #8562: tokio-rs/tokio#8562 #8564: tokio-rs/tokio#8564 #8566: tokio-rs/tokio#8566 #8570: tokio-rs/tokio#8570 #8574: tokio-rs/tokio#8574

Commits
  • ff0c406 chore: prepare Tokio v1.53.2 (#8580)
  • a762700 Merge 'tokio-1.51.5' into 'tokio-1.53.x' (#8577)
  • ec31a9f chore: prepare Tokio v1.51.5 (#8579)
  • 625c851 sync: assign semaphore permits before emitting tracing event (#8542)
  • 832dd23 sync: avoid leaking semaphore permits on tracing panic (#8542)
  • 826954a sync: unlink semaphore waiter before emitting tracing event (#8542)
  • 9a47992 process: unregister Windows wait before closing child handle (#8564)
  • 2fc5972 fs: handle integer overflow in buffered relative seek (#8574)
  • 85a6d13 io: revert "always cleanup AsyncFd registration list on deregister" (#8540)
  • 436faa2 rt: drop blocking pool mutex before shutting down rejected task (#8562)
  • Additional commits viewable in compare view

Updates clap_complete from 4.6.10 to 4.6.11

Commits
  • 2cb76fd chore: Release
  • 0b00b8d docs: Update changelog
  • 3443000 Merge pull request #6526 from bonnefoa/fix-completion-escape
  • a1b6be7 fix(clap_complete): Fix value escape in zsh completion
  • face9e8 test(complete): Add completion test without arg's help
  • 88053ab test(complete): Re-enable complete tests
  • e6adcc2 chore(release): Simplify replacements
  • See full diff in compare view

Updates thiserror from 2.0.20 to 2.0.21

Release notes

Sourced from thiserror's releases.

2.0.21

  • Fix parsing of generic unit variants in display expressions (#459)
Commits
  • b1827ee Release 2.0.21
  • 58037b5 Merge pull request #459 from dtolnay/turbofish
  • f82a0cf Keep track of nested turbofish depth
  • 72ea492 Raise required compiler to Rust 1.77
  • 72eea0d Resolve io_other_error clippy lint in tests
  • 07f09a2 Raise required compiler to Rust 1.74
  • 2715388 Update ui test suite to nightly-2026-09-22
  • 5a306c7 Update ui test suite to nightly-2026-09-05
  • ef9383b Update ui test suite to nightly-2026-08-22
  • 8336b84 Update ui tests for version 2.0.20
  • See full diff in compare view

Updates rmcp from 3.3.0 to 3.5.0

Release notes

Sourced from rmcp's releases.

rmcp-macros-v3.5.0

Fixed

  • (macros) accept const paths and concat! in tool/prompt descriptions (#1243)

rmcp-v3.5.0

Added

  • update LATEST and add LATEST_WITH_INITIALIZE (#1105)

Fixed

  • (model) decode float fields through serde_json::Number (#1300)
  • (rmcp) reject duplicate sep-2243 headers (#1274)
  • (transport) match explicit default ports in Origin allowlist (#1270)
  • (rmcp) tolerate empty cacheScope instead of silently dropping the whole result (#1281)
  • (model) preserve explicit null structuredContent in CallToolResult (#1295)

Other

  • cargo fmt fixes on validate_standard_headers changes (#1275)

rmcp-macros-v3.4.1

Fixed

  • (macros) accept const paths and concat! in tool/prompt descriptions (#1243)

rmcp-v3.4.1

Fixed

  • (transport) fall back after JSON discover rejections (#1288)
  • (macros) accept const paths and concat! in tool/prompt descriptions (#1243)

Other

  • (deps) update rstest requirement from 0.26.1 to 0.27.0 (#1276)

rmcp-macros-v3.4.0

Added

  • (model) add ServerConfig and ClientConfig (#1266)

Fixed

  • (model) deprecate ServerInfo and ClientInfo aliases (#1156)

rmcp-v3.4.0

Added

  • (model) add ServerConfig and ClientConfig (#1266)

... (truncated)

Commits
  • 0cde3c5 chore: release v3.5.0 (#1296)
  • e02efbf fix(model): decode float fields through serde_json::Number (#1300)
  • 972af86 feat: update LATEST and add LATEST_WITH_INITIALIZE (#1105)
  • 6e47ca3 chore(deps): bump the github-actions group with 2 updates (#1297)
  • 6255c37 chore: reduce dependency update noise (#1293)
  • 22ef52a fix(rmcp): reject duplicate sep-2243 headers (#1274)
  • 26f3b2e fix(transport): match explicit default ports in Origin allowlist (#1270)
  • 6677eee style: cargo fmt fixes on validate_standard_headers changes (#1275)
  • fbed447 fix(rmcp): tolerate empty cacheScope instead of silently dropping the whole r...
  • 90516bf fix(model): preserve explicit null structuredContent in CallToolResult (#1295)
  • Additional commits viewable in compare view

Updates jsonwebtoken from 11.0.0 to 11.1.0

Changelog

Sourced from jsonwebtoken's changelog.

11.1.0 (2026-09-16)

  • Add dangerous::insecure_decode_claims
Commits

Updates libc from 0.2.189 to 0.2.190

Release notes

Sourced from libc's releases.

0.2.190

There is now a single config for enabling 64-bit time_t: libc_unstable_time64. This can be set unconditionally; it opts in to 64-bit time_t on the following platforms that use 32-bit by default:

  • 32-bit Linux-GNU
  • 32-bit Linux-uClibc
  • 32-bit Linux-musl. Note that setting this flag also enables some other changes that happend in musl v1.2.
  • 32-bit Windows-GNU
  • ESP-IDF (all targets with this environment are 32-bit)

Most other 32-bit platforms are either already using 64-bit time_t, or are considered legacy and will not be gaining support from their upstream maintainers.

You can enable this using RUSTFLAGS:

RUSTFLAGS='--cfg=libc_unstable_time64' cargo ...

Note that there may still be some changes to features gated by this config option, hence "unstable" in its name. In the near future we will rename it to just libc_time64. Until then, please test it out and report any bugs you find!

Support

  • Add initial support for HelenOS (#4355)

Added

We are slowly filling out the Default implementations, to reduce the need for mem::zeroed() in user code:

  • Unix: Implement Default for a number of structs, especially on Apple platforms (#5576)
  • Linux, NetBSD: Give statvfs a Default impl (#5583)
  • Linux: Add Default to a linux/can.rs structs (#5257)

Other additions:

  • Expose the libc_unstable_time64 cfg (#5411)
  • Android, Glibc: Add pthread_gettid_np (#5359)
  • Android: Add RTLD_NEXT (#5323)
  • Android: Add reuseport BPF socket options (#5366)
  • Apple: Add TCP header flags, options and SACK limits (#5358)
  • Apple: Add NET_RT_DUMP2 (#5442)
  • Apple: Add posix_spawn_file_actions_add(f)chdir(_np) (#5558)
  • BSD: Add BPF_WORDALIGN (#5320)
  • BSD: Add lchmod and lchflags where supported (#5400)
  • BSD: Add minherit and related constants (#4849)
  • Docs: Add more links to public headers and manual pages (#5407), (#5485)

... (truncated)

Changelog

Sourced from libc's changelog.

0.2.190 - 2026-10-02

There is now a single config for enabling 64-bit time_t: libc_unstable_time64. This can be set unconditionally; it opts in to 64-bit time_t on the following platforms that use 32-bit by default:

  • 32-bit Linux-GNU
  • 32-bit Linux-uClibc
  • 32-bit Linux-musl. Note that setting this flag also enables some other changes that happend in musl v1.2.
  • 32-bit Windows-GNU
  • ESP-IDF (all targets with this environment are 32-bit)

Most other 32-bit platforms are either already using 64-bit time_t, or are considered legacy and will not be gaining support from their upstream maintainers.

You can enable this using RUSTFLAGS:

RUSTFLAGS='--cfg=libc_unstable_time64' cargo ...

Note that there may still be some changes to features gated by this config option, hence "unstable" in its name. In the near future we will rename it to just libc_time64. Until then, please test it out and report any bugs you find!

Support

  • Add initial support for HelenOS (#4355)

Added

We are slowly filling out the Default implementations, to reduce the need for mem::zeroed() in user code:

  • Unix: Implement Default for a number of structs, especially on Apple platforms (#5576)
  • Linux, NetBSD: Give statvfs a Default impl (#5583)
  • Linux: Add Default to a linux/can.rs structs (#5257)

Other additions:

  • Expose the libc_unstable_time64 cfg (#5411)
  • Android, Glibc: Add pthread_gettid_np (#5359)
  • Android: Add RTLD_NEXT (#5323)
  • Android: Add reuseport BPF socket options (#5366)
  • Apple: Add TCP header flags, options and SACK limits (#5358)
  • Apple: Add NET_RT_DUMP2 (#5442)
  • Apple: Add posix_spawn_file_actions_add(f)chdir(_np) (#5558)
  • BSD: Add BPF_WORDALIGN (#5320)
  • BSD: Add lchmod and lchflags where supported (#5400)
  • BSD: Add minherit and related constants (#4849)

... (truncated)

Commits
  • 7b0ab55 ci: Rename publish_0.2.yml to release.yaml
  • ac85dde ci: Sync release permissions with main
  • 8f8cd20 libc: Release 0.2.190
  • 052c6e6 changelog: Fix an incorrect commit link
  • ea19fd7 test: Remove explicit libc version
  • 6dbf3a2 dragonfly: Move INHERIT_ZERO to the freebsd module
  • 8a64766 apple: add posix_spawn_file_actions_add(f)chdir(_np)
  • 28de514 linux, netbsd: Give statvfs a Default impl
  • a58a95f cygwin: Change POSIX_SPAWN_* flags to c_short
  • d175264 apple: timeval32 is exhaustive
  • Additional commits viewable in compare view

Updates tokio-test from 0.4.5 to 0.4.6

Commits

Updates insta from 1.48.0 to 1.49.0

Release notes

Sourced from insta's releases.

1.49.0

Release Notes

  • Allow Option<&OsStr> snapshot names, such as Path::file_name(), without explicit string conversion. #929 (@​dislogical)
  • Add prebuilt cargo-insta binaries for ARM64 Linux (aarch64-unknown-linux-gnu). #942 (@​aljohri)
  • Fix JSON serialization of maps keyed by unit enum variants. Keys use the serialized variant name, including serde renames. #934 (@​teddytennant)
  • Remove trailing semicolons from serialization macro bodies to avoid compiler warnings when used in expression position. #940 (@​Tiwalun)
  • Mention INSTA_UPDATE=always in snapshot mismatch hints for file snapshots. #927 (@​hiro-nikaitou)
  • Update the lockfile's tempfile and rustix dependencies to fix builds with newer Rust toolchains. #939
  • Fix cargo insta test --all-targets --test-runner nextest failing with "Can't mix --doc with other target selecting options". Like cargo test --all-targets, it no longer runs doctests. #460

Install cargo-insta 1.49.0

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/mitsuhiko/insta/releases/download/1.49.0/cargo-insta-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/mitsuhiko/insta/releases/download/1.49.0/cargo-insta-installer.ps1 | iex"

Download cargo-insta 1.49.0

File Platform Checksum
cargo-insta-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
cargo-insta-x86_64-apple-darwin.tar.xz Intel macOS checksum
cargo-insta-x86_64-pc-windows-msvc.zip x64 Windows checksum
cargo-insta-aarch64-unknown-linux-gnu.tar.xz ARM64 Linux checksum
cargo-insta-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum
cargo-insta-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum

This was written by Codex on behalf of @​max-sixty

Changelog

Sourced from insta's changelog.

1.49.0

  • Allow Option<&OsStr> snapshot names, such as Path::file_name(), without explicit string conversion. #929 (@​dislogical)
  • Add prebuilt cargo-insta binaries for ARM64 Linux (aarch64-unknown-linux-gnu). #942 (@​aljohri)
  • Fix JSON serialization of maps keyed by unit enum variants. Keys use the serialized variant name, including serde renames. #934 (@​teddytennant)
  • Remove trailing semicolons from serialization macro bodies to avoid compiler warnings when used in expression position. #940 (@​Tiwalun)
  • Mention INSTA_UPDATE=always in snapshot mismatch hints for file snapshots. #927 (@​hiro-nikaitou)
  • Update the lockfile's tempfile and rustix dependencies to fix builds with newer Rust toolchains. #939
  • Fix cargo insta test --all-targets --test-runner nextest failing with "Can't mix --doc with other target selecting options". Like cargo test --all-targets, it no longer runs doctests. #460
Commits
  • 5df39ce Release 1.49.0 (#944)
  • 1c28c19 Skip the separate doctest run for nextest with --all-targets (#941)
  • 064742e Build cargo-insta for aarch64-unknown-linux-gnu (#942)
  • 08b67d9 Remove trailing semicolons from macro bodies (#940)
  • 06858e1 fix: regenerate Cargo.lock to avoid broken rustix 0.37.27 (#939)
  • 70be034 Serialize unit enum variants used as JSON map keys (#934)
  • 54d0b96 feat: implement From for SnapshotValue with OsStr (#929)
  • 3d62572 [fix] Mention INSTA_UPDATE variable in snapshot mismatch errors (#927)
  • 1712876 ci: run CI on a pinned toolchain via rust-toolchain.toml; fix format-arg lint...
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

… 8 updates

Bumps the rust-dependencies group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [tokio](https://github.com/tokio-rs/tokio) | `1.53.1` | `1.53.2` |
| [clap_complete](https://github.com/clap-rs/clap) | `4.6.10` | `4.6.11` |
| [thiserror](https://github.com/dtolnay/thiserror) | `2.0.20` | `2.0.21` |
| [rmcp](https://github.com/modelcontextprotocol/rust-sdk) | `3.3.0` | `3.5.0` |
| [jsonwebtoken](https://github.com/Keats/jsonwebtoken) | `11.0.0` | `11.1.0` |
| [libc](https://github.com/rust-lang/libc) | `0.2.189` | `0.2.190` |
| [tokio-test](https://github.com/tokio-rs/tokio) | `0.4.5` | `0.4.6` |
| [insta](https://github.com/mitsuhiko/insta) | `1.48.0` | `1.49.0` |



Updates `tokio` from 1.53.1 to 1.53.2
- [Release notes](https://github.com/tokio-rs/tokio/releases)
- [Commits](tokio-rs/tokio@tokio-1.53.1...tokio-1.53.2)

Updates `clap_complete` from 4.6.10 to 4.6.11
- [Release notes](https://github.com/clap-rs/clap/releases)
- [Changelog](https://github.com/clap-rs/clap/blob/main/CHANGELOG.md)
- [Commits](clap-rs/clap@clap_complete-v4.6.10...clap_complete-v4.6.11)

Updates `thiserror` from 2.0.20 to 2.0.21
- [Release notes](https://github.com/dtolnay/thiserror/releases)
- [Commits](dtolnay/thiserror@2.0.20...2.0.21)

Updates `rmcp` from 3.3.0 to 3.5.0
- [Release notes](https://github.com/modelcontextprotocol/rust-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/rust-sdk/blob/main/release-plz.toml)
- [Commits](modelcontextprotocol/rust-sdk@rmcp-v3.3.0...rmcp-v3.5.0)

Updates `jsonwebtoken` from 11.0.0 to 11.1.0
- [Changelog](https://github.com/Keats/jsonwebtoken/blob/master/CHANGELOG.md)
- [Commits](Keats/jsonwebtoken@v11.0.0...v11.1.0)

Updates `libc` from 0.2.189 to 0.2.190
- [Release notes](https://github.com/rust-lang/libc/releases)
- [Changelog](https://github.com/rust-lang/libc/blob/0.2.190/CHANGELOG.md)
- [Commits](rust-lang/libc@0.2.189...0.2.190)

Updates `tokio-test` from 0.4.5 to 0.4.6
- [Release notes](https://github.com/tokio-rs/tokio/releases)
- [Commits](tokio-rs/tokio@tokio-test-0.4.5...tokio-test-0.4.6)

Updates `insta` from 1.48.0 to 1.49.0
- [Release notes](https://github.com/mitsuhiko/insta/releases)
- [Changelog](https://github.com/mitsuhiko/insta/blob/master/CHANGELOG.md)
- [Commits](mitsuhiko/insta@1.48.0...1.49.0)

---
updated-dependencies:
- dependency-name: tokio
  dependency-version: 1.53.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: clap_complete
  dependency-version: 4.6.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: thiserror
  dependency-version: 2.0.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: rmcp
  dependency-version: 3.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-dependencies
- dependency-name: jsonwebtoken
  dependency-version: 11.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-dependencies
- dependency-name: libc
  dependency-version: 0.2.190
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: tokio-test
  dependency-version: 0.4.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: insta
  dependency-version: 1.49.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants