Skip to content

ci(deps): bump the cargo group across 1 directory with 2 updates - #47

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-157702ef96
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-157702ef96

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Bumps the cargo group with 2 updates in the / directory: aws-sigv4 and tokio.

Updates aws-sigv4 from 1.5.3 to 1.6.0

Changelog

Sourced from aws-sigv4's changelog.

September 30th, 2026

September 30th, 2026

New this release:

September 24th, 2026

New this release:

  • 🎉 (all, smithy-rs#4473) Add Smithy RPC v2 CBOR serialization and deserialization support for BigDecimal values.

  • 🐛🎉 (all) A response header value that is not valid UTF-8 no longer fails the whole response.

    An HTTP header value may contain any octet in 0x80..=0xFF (obs-text, RFC 7230), and an arbitrary sequence of those is not necessarily valid UTF-8, so a service can send a value that is not representable as a Rust String. Previously one such value failed the entire response during the HTTP-to-SDK conversion. That happened before deserialization, whether or not anything read that header, and surfaced as a non-retryable DispatchFailure.

    Header values are now stored as received, and the encoding requirement applies where a value is bound to a modeled member. A header bound to no member is harmless. A header bound to a member reports an error naming that member on the client, or a 400 on the server. Nothing is dropped silently.

    For servers this narrows what gets rejected rather than changing the status. A non-UTF-8 value bound to a member was already a 400 and still is; it is now detected at the member binding instead of when the request was converted. A request carrying a non-UTF-8 header that no modeled member is bound to used to be rejected and is now accepted.

    Headers gained byte accessors that return every value, alongside the existing string accessors, which now skip values that are not valid UTF-8:

    • Headers::get_bytes, Headers::get_all_bytes, Headers::iter_bytes
    • HeaderValue::as_bytes, HeaderValue::try_as_str

    Headers::get returns None both for an absent header and for one whose value is not valid UTF-8. Use Headers::try_get where the difference matters: it returns Some(Ok(_)), Some(Err(raw_octets)) and None respectively. Note also that Headers::len and Headers::contains_key count and report values the string accessors skip.

    To tolerate an unreadable value rather than fail, put NonUtf8HeaderHandling::Skip in the config bag from an interceptor. The member then deserializes as if the header were absent, and because the header is left in place the octets stay readable, so a caller that needs the value can decode it however its service encodes it:

    /// Whatever decoding this service's encoding calls for.
    fn decode_latin1(bytes: &[u8]) -> String { /* ... */ }
    #[derive(Clone, Debug, Default)]
    struct ContentDispositionAsLatin1 {
    value: Arc<Mutex<Option<String>>>,
    }
    impl Intercept for ContentDispositionAsLatin1 {
    fn name(&self) -> &'static str {
    "ContentDispositionAsLatin1"
    }
    fn read_before_execution(
        &amp;self,
        _context: &amp;BeforeSerializationInterceptorContextRef&lt;'_&gt;,
        cfg: &amp;mut ConfigBag,
    ) -&gt; Result&lt;(), BoxError&gt; {

... (truncated)

Commits

Updates tokio from 1.53.1 to 1.53.2

Release notes

Sourced from tokio's releases.

Tokio v1.53.2

1.53.2 (October 3rd, 2026)

Fixed

  • fs: handle integer overflow in buffered relative seek (#8574)
  • io: revert "always cleanup AsyncFd registration list on deregister" (#8540)
  • process: unregister Windows wait before closing child handle (#8564)
  • rt: drop blocking pool mutex before shutting down rejected task (#8562)
  • sync: fix mpsc index wraparound in block reclamation (#8546)
  • sync: forget mpsc Permit before sending value (#8560)
  • sync: validate MAX_PERMITS in Semaphore::acquire (#8548)
  • sync: wake broadcast Sender::closed outside mutex (#8558)
  • task: drop replaced waker outside lock in JoinSet (#8554)
  • time: drop timer lock before dropping waker in clear_entry (#8552)
  • time: expire timers directly on shutdown without rotating wheel (#8570)

Fixed (unstable)

  • fs: clamp io_uring read length to u32::MAX (#8572)
  • rt: ignore current_thread task dumps from other runtimes (#8544)
  • rt: preserve io_uring context if a completion waker panics (#8566)
  • sync: fix semaphore use-after-free and permit leak on tracing panic (#8542)
  • taskdump: restore deferred leaf wakes during capture (#8445)
  • time: drop stored waker when cancelling alt timer entry (#8550)

#8445: tokio-rs/tokio#8445 #8572: tokio-rs/tokio#8572 #8540: tokio-rs/tokio#8540 #8542: tokio-rs/tokio#8542 #8544: tokio-rs/tokio#8544 #8546: tokio-rs/tokio#8546 #8548: tokio-rs/tokio#8548 #8550: tokio-rs/tokio#8550 #8552: tokio-rs/tokio#8552 #8554: tokio-rs/tokio#8554 #8558: tokio-rs/tokio#8558 #8560: tokio-rs/tokio#8560 #8562: tokio-rs/tokio#8562 #8564: tokio-rs/tokio#8564 #8566: tokio-rs/tokio#8566 #8570: tokio-rs/tokio#8570 #8574: tokio-rs/tokio#8574

Commits
  • ff0c406 chore: prepare Tokio v1.53.2 (#8580)
  • a762700 Merge 'tokio-1.51.5' into 'tokio-1.53.x' (#8577)
  • ec31a9f chore: prepare Tokio v1.51.5 (#8579)
  • 625c851 sync: assign semaphore permits before emitting tracing event (#8542)
  • 832dd23 sync: avoid leaking semaphore permits on tracing panic (#8542)
  • 826954a sync: unlink semaphore waiter before emitting tracing event (#8542)
  • 9a47992 process: unregister Windows wait before closing child handle (#8564)
  • 2fc5972 fs: handle integer overflow in buffered relative seek (#8574)
  • 85a6d13 io: revert "always cleanup AsyncFd registration list on deregister" (#8540)
  • 436faa2 rt: drop blocking pool mutex before shutting down rejected task (#8562)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the cargo group with 2 updates in the / directory: [aws-sigv4](https://github.com/smithy-lang/smithy-rs) and [tokio](https://github.com/tokio-rs/tokio).


Updates `aws-sigv4` from 1.5.3 to 1.6.0
- [Release notes](https://github.com/smithy-lang/smithy-rs/releases)
- [Changelog](https://github.com/smithy-lang/smithy-rs/blob/main/CHANGELOG.md)
- [Commits](https://github.com/smithy-lang/smithy-rs/commits)

Updates `tokio` from 1.53.1 to 1.53.2
- [Release notes](https://github.com/tokio-rs/tokio/releases)
- [Commits](tokio-rs/tokio@tokio-1.53.1...tokio-1.53.2)

---
updated-dependencies:
- dependency-name: aws-sigv4
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo
- dependency-name: tokio
  dependency-version: 1.53.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants