Skip to content

chore(deps): bump the rust-dependencies group across 1 directory with 11 updates - #5566

Merged
jedel1043 merged 1 commit into
mainfrom
dependabot/cargo/rust-dependencies-5ff2a76f0b
Oct 10, 2026
Merged

jedel1043 merged 1 commit into
mainfrom
dependabot/cargo/rust-dependencies-5ff2a76f0b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps the rust-dependencies group with 11 updates in the / directory:

Package From To
arbitrary 1.4.2 1.5.0
thin-vec 0.2.19 0.2.20
comfy-table 8.0.0 8.0.1
syn 3.0.5 3.0.6
rand 0.10.2 0.10.3
thiserror 2.0.20 2.0.21
cfg-if 1.0.4 1.0.5
either 1.18.0 1.19.0
test-case 3.3.1 3.4.0
tokio 1.53.1 1.53.2
insta 1.48.0 1.49.0

Updates arbitrary from 1.4.2 to 1.5.0

Changelog

Sourced from arbitrary's changelog.

1.5.0

Released 2026-10-05.

Added

  • Added support for deriving Arbitrary for types with raw identifiers.

Changed

  • Updated derive_arbitrary to syn 3. This raises the MSRV from 1.63.0 to 1.71.0, which is the MSRV of syn 3.

Fixed

  • Fixed soundness when generating arrays.
  • Fixed nonzero integer generation to always produce a nonzero value.
  • Updated derive_arbitrary to include fixes for fully qualified paths.

Commits
  • 9807b59 Merge pull request #243 from fitzgen/bump-to-1.5.0
  • 7a49e61 Bump to version 1.5.0
  • aa2802b Merge pull request #242 from drakeo338/claude/241-fix
  • a9f7ca5 Update derive_arbitrary to syn 3 and raise MSRV to 1.71
  • cd35bd2 Merge pull request #239 from Manishearth/fix-soundness
  • 53a651d agent-driven: Fix soundness in try_create_array
  • df8afe9 Merge pull request #238 from baloo/baloo/push-lopsmyosqnpv
  • 15f5c08 Bring fix for fully qualified path
  • 341a8fd Merge pull request #237 from ngildenhuys/downgrading_msrv_deps
  • 9b68ef4 ci: adding update commands to downgrade dependencies to fix MSRV test
  • Additional commits viewable in compare view

Updates thin-vec from 0.2.19 to 0.2.20

Changelog

Sourced from thin-vec's changelog.

Version 0.2.20 (2026-09-16)

  • Make const_new the default, and bump MSRV to 1.85. const_new feature is still available but does nothing.
  • Forbid ZSTs for gecko-ffi mode (#94).
  • Avoid allocating for ZSTs (#92).
Commits
  • 79452c2 chore: Release 0.2.20
  • 696791e Remove allocation for ZSTs (#92)
  • 7fd48b6 chore: Fix a few CI warnings.
  • 4281a0b gecko: Prevent ZSTs with ThinVec when in gecko-ffi mode.
  • af669a2 chore: Document some of the recent changes.
  • 75e4a40 chore: Bump edition to Rust 2024.
  • 8cbb905 lib: Make const_new the default, and bump MSRV.
  • See full diff in compare view

Updates comfy-table from 8.0.0 to 8.0.1

Changelog

Sourced from comfy-table's changelog.

[8.0.1] - 2026-09-25

  • Set MSRV to 1.88
Commits
  • b947cb6 chore: Release comfy-table version 8.0.1
  • 283fed2 chore: Set msrv to 1.88
  • bbd884f Merge pull request #212 from Nukesor/dependabot/cargo/rstest-0.27
  • f3c6d7e build(deps): update rstest requirement from 0.26 to 0.27
  • See full diff in compare view

Updates syn from 3.0.5 to 3.0.6

Release notes

Sourced from syn's releases.

3.0.6

  • Fix parsing interpolated lifetime at statement start (#2082)
Commits
  • 559cab5 Release 3.0.6
  • 9088cad Merge pull request #2082 from dtolnay/lifetimevar
  • 3eb43bb Fix parsing interpolated lifetime at statement start
  • 7b2f6f9 Add regression test for issue 2081
  • d55bcd2 Update test suite to nightly-2026-09-13
  • 8e37bca Resolve non_kebab_case_bins warning
  • 4dfd88f Update test suite to nightly-2026-09-06
  • See full diff in compare view

Updates rand from 0.10.2 to 0.10.3

Changelog

Sourced from rand's changelog.

[0.10.3] — 2026-09-20

Fixes

  • Fix WeightedIndex panic when the sum of float weights is infinite; return Error::Overflow instead (#1808)
  • Fix spurious Error::NonFinite from Uniform::new_inclusive on large finite float ranges such as 0.0..=f64::MAX (#1821)
  • Fix possible panic due to sampling a deserialized Uniform<char> (#1831)

Changes

  • Report exact remaining lengths from WeightedIndex::weights() and reduce overhead when reading weights (#1838)

#1808: rust-random/rand#1808 #1821: rust-random/rand#1821 #1831: rust-random/rand#1831 #1838: rust-random/rand#1838

Commits
  • 9e7d328 Prepare rand 0.10.3 (#1840)
  • f73ce74 Optimize WeightedIndex weight lookup and iteration (#1838)
  • ef9e044 Avoid panic from deserialized Uniform\<char> where range == 0 (#1831)
  • c994eb1 docs: fix angle unit in quick start example (#1839)
  • 33dea4f Test that WeightedIndex rejects INFINITY with Error::Overflow (#1822)
  • 94c9078 Fix Uniform::new_inclusive overflow on large finite float ranges (#1821)
  • bb1262f Use Xoshiro256PlusPlus in examples/rayon-monte-carlo.rs (#1805)
  • 521fab6 Stop pinning dependencies (#1820)
  • 3f7c433 Stop pinning dependencies
  • cf4f73e sample_efraimidis_spirakis: error on more than amount non-finite weights (#1814)
  • Additional commits viewable in compare view

Updates thiserror from 2.0.20 to 2.0.21

Release notes

Sourced from thiserror's releases.

2.0.21

  • Fix parsing of generic unit variants in display expressions (#459)
Commits
  • b1827ee Release 2.0.21
  • 58037b5 Merge pull request #459 from dtolnay/turbofish
  • f82a0cf Keep track of nested turbofish depth
  • 72ea492 Raise required compiler to Rust 1.77
  • 72eea0d Resolve io_other_error clippy lint in tests
  • 07f09a2 Raise required compiler to Rust 1.74
  • 2715388 Update ui test suite to nightly-2026-09-22
  • 5a306c7 Update ui test suite to nightly-2026-09-05
  • ef9383b Update ui test suite to nightly-2026-08-22
  • 8336b84 Update ui tests for version 2.0.20
  • See full diff in compare view

Updates cfg-if from 1.0.4 to 1.0.5

Release notes

Sourced from cfg-if's releases.

v1.0.5

  • Add a note that this crate is deprecated, suggesting cfg_select! instead
Changelog

Sourced from cfg-if's changelog.

1.0.5 - 2026-09-16

  • Add a note that this crate is deprecated, suggesting cfg_select! instead
Commits
  • 8b0a2b0 Deprecation notice + crate version bump
  • efabe3f Add a changelog entry for the upcoming deprecation notice
  • a66c2d4 Bump actions/checkout from 6 to 7
  • bda9677 Bump actions/checkout from 5 to 6
  • See full diff in compare view

Updates either from 1.18.0 to 1.19.0

Changelog

Sourced from either's changelog.

Commits

Updates test-case from 3.3.1 to 3.4.0

Release notes

Sourced from test-case's releases.

Test Case - v3.4.0

Changelog

3.4.0

Changes

  • Adds test case number to automatically distinguish test cases with the same generated name (#151) Instead of having a conflict in example like this:
#[test_case(42)]
#[test_case("42")]
fn cases_are_enumerated(value: impl std::fmt::Display) {
   assert_eq!("42", &value.to_string())
}

It now generates prefix name for each test case. In all cases:

test cases_are_enumerated::test_case_1_42_expects ... ok
test cases_are_enumerated::test_case_2_42_expects ... ok
  • Inverts the left and right output for simple test cases. Generates assert_eq!(result, expectation) instead of previous assert_eq!(expectation, result);
  • Upgrades edition to 2024
  • Updates:
    • regex to 1.9
    • insta to 1.43
    • itertools to 0.15
    • syn to 3.0
Changelog

Sourced from test-case's changelog.

3.4.0

Changes

  • Adds test case number to automatically distinguish test cases with the same generated name (#151) Instead of having a conflict in example like this:
#[test_case(42)]
#[test_case("42")]
fn cases_are_enumerated(value: impl std::fmt::Display) {
   assert_eq!("42", &value.to_string())
}

It now generates prefix name for each test case. In all cases:

test cases_are_enumerated::test_case_1_42_expects ... ok
test cases_are_enumerated::test_case_2_42_expects ... ok
  • Inverts the left and right output for simple test cases. Generates assert_eq!(result, expectation) instead of previous assert_eq!(expectation, result);
  • Upgrades edition to 2024
  • Updates:
    • regex to 1.9
    • insta to 1.43
    • itertools to 0.15
    • syn to 3.0
Commits

Updates tokio from 1.53.1 to 1.53.2

Release notes

Sourced from tokio's releases.

Tokio v1.53.2

1.53.2 (October 3rd, 2026)

Fixed

  • fs: handle integer overflow in buffered relative seek (#8574)
  • io: revert "always cleanup AsyncFd registration list on deregister" (#8540)
  • process: unregister Windows wait before closing child handle (#8564)
  • rt: drop blocking pool mutex before shutting down rejected task (#8562)
  • sync: fix mpsc index wraparound in block reclamation (#8546)
  • sync: forget mpsc Permit before sending value (#8560)
  • sync: validate MAX_PERMITS in Semaphore::acquire (#8548)
  • sync: wake broadcast Sender::closed outside mutex (#8558)
  • task: drop replaced waker outside lock in JoinSet (#8554)
  • time: drop timer lock before dropping waker in clear_entry (#8552)
  • time: expire timers directly on shutdown without rotating wheel (#8570)

Fixed (unstable)

  • fs: clamp io_uring read length to u32::MAX (#8572)
  • rt: ignore current_thread task dumps from other runtimes (#8544)
  • rt: preserve io_uring context if a completion waker panics (#8566)
  • sync: fix semaphore use-after-free and permit leak on tracing panic (#8542)
  • taskdump: restore deferred leaf wakes during capture (#8445)
  • time: drop stored waker when cancelling alt timer entry (#8550)

#8445: tokio-rs/tokio#8445 #8572: tokio-rs/tokio#8572 #8540: tokio-rs/tokio#8540 #8542: tokio-rs/tokio#8542 #8544: tokio-rs/tokio#8544 #8546: tokio-rs/tokio#8546 #8548: tokio-rs/tokio#8548 #8550: tokio-rs/tokio#8550 #8552: tokio-rs/tokio#8552 #8554: tokio-rs/tokio#8554 #8558: tokio-rs/tokio#8558 #8560: tokio-rs/tokio#8560 #8562: tokio-rs/tokio#8562 #8564: tokio-rs/tokio#8564 #8566: tokio-rs/tokio#8566 #8570: tokio-rs/tokio#8570 #8574: tokio-rs/tokio#8574

Commits
  • ff0c406 chore: prepare Tokio v1.53.2 (#8580)
  • a762700 Merge 'tokio-1.51.5' into 'tokio-1.53.x' (#8577)
  • ec31a9f chore: prepare Tokio v1.51.5 (#8579)
  • 625c851 sync: assign semaphore permits before emitting tracing event (#8542)
  • 832dd23 sync: avoid leaking semaphore permits on tracing panic (#8542)
  • 826954a sync: unlink semaphore waiter before emitting tracing event (#8542)
  • 9a47992 process: unregister Windows wait before closing child handle (#8564)
  • 2fc5972 fs: handle integer overflow in buffered relative seek (#8574)
  • 85a6d13 io: revert "always cleanup AsyncFd registration list on deregister" (#8540)
  • 436faa2 rt: drop blocking pool mutex before shutting down rejected task (#8562)
  • Additional commits viewable in compare view

Updates insta from 1.48.0 to 1.49.0

Release notes

Sourced from insta's releases.

1.49.0

Release Notes

  • Allow Option<&OsStr> snapshot names, such as Path::file_name(), without explicit string conversion. #929 (@​dislogical)
  • Add prebuilt cargo-insta binaries for ARM64 Linux (aarch64-unknown-linux-gnu). #942 (@​aljohri)
  • Fix JSON serialization of maps keyed by unit enum variants. Keys use the serialized variant name, including serde renames. #934 (@​teddytennant)
  • Remove trailing semicolons from serialization macro bodies to avoid compiler warnings when used in expression position. #940 (@​Tiwalun)
  • Mention INSTA_UPDATE=always in snapshot mismatch hints for file snapshots. #927 (@​hiro-nikaitou)
  • Update the lockfile's tempfile and rustix dependencies to fix builds with newer Rust toolchains. #939
  • Fix cargo insta test --all-targets --test-runner nextest failing with "Can't mix --doc with other target selecting options". Like cargo test --all-targets, it no longer runs doctests. #460

Install cargo-insta 1.49.0

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/mitsuhiko/insta/releases/download/1.49.0/cargo-insta-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/mitsuhiko/insta/releases/download/1.49.0/cargo-insta-installer.ps1 | iex"

Download cargo-insta 1.49.0

File Platform Checksum
cargo-insta-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
cargo-insta-x86_64-apple-darwin.tar.xz Intel macOS checksum
cargo-insta-x86_64-pc-windows-msvc.zip x64 Windows checksum
cargo-insta-aarch64-unknown-linux-gnu.tar.xz ARM64 Linux checksum
cargo-insta-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum
cargo-insta-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum

This was written by Codex on behalf of @​max-sixty

Changelog

Sourced from insta's changelog.

1.49.0

  • Allow Option<&OsStr> snapshot names, such as Path::file_name(), without explicit string conversion. #929 (@​dislogical)
  • Add prebuilt cargo-insta binaries for ARM64 Linux (aarch64-unknown-linux-gnu). #942 (@​aljohri)
  • Fix JSON serialization of maps keyed by unit enum variants. Keys use the serialized variant name, including serde renames. #934 (@​teddytennant)
  • Remove trailing semicolons from serialization macro bodies to avoid compiler warnings when used in expression position. #940 (@​Tiwalun)
  • Mention INSTA_UPDATE=always in snapshot mismatch hints for file snapshots. #927 (@​hiro-nikaitou)
  • Update the lockfile's tempfile and rustix dependencies to fix builds with newer Rust toolchains. #939
  • Fix cargo insta test --all-targets --test-runner nextest failing with "Can't mix --doc with other target selecting options". Like cargo test --all-targets, it no longer runs doctests. #460
Commits
  • 5df39ce Release 1.49.0 (#944)
  • 1c28c19 Skip the separate doctest run for nextest with --all-targets (#941)
  • 064742e Build cargo-insta for aarch64-unknown-linux-gnu (#942)
  • 08b67d9 Remove trailing semicolons from macro bodies (#940)
  • 06858e1 fix: regenerate Cargo.lock to avoid broken rustix 0.37.27 (#939)
  • 70be034 Serialize unit enum variants used as JSON map keys (#934)
  • 54d0b96 feat: implement From for SnapshotValue with OsStr (#929)
  • 3d62572 [fix] Mention INSTA_UPDATE variable in snapshot mismatch errors (#927)
  • 1712876 ci: run CI on a pinned toolchain via rust-toolchain.toml; fix format-arg lint...
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

… 11 updates

Bumps the rust-dependencies group with 11 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [arbitrary](https://github.com/rust-fuzz/arbitrary) | `1.4.2` | `1.5.0` |
| [thin-vec](https://github.com/mozilla/thin-vec) | `0.2.19` | `0.2.20` |
| [comfy-table](https://github.com/nukesor/comfy-table) | `8.0.0` | `8.0.1` |
| [syn](https://github.com/dtolnay/syn) | `3.0.5` | `3.0.6` |
| [rand](https://github.com/rust-random/rand) | `0.10.2` | `0.10.3` |
| [thiserror](https://github.com/dtolnay/thiserror) | `2.0.20` | `2.0.21` |
| [cfg-if](https://github.com/rust-lang/cfg-if) | `1.0.4` | `1.0.5` |
| [either](https://github.com/rayon-rs/either) | `1.18.0` | `1.19.0` |
| [test-case](https://github.com/frondeus/test-case) | `3.3.1` | `3.4.0` |
| [tokio](https://github.com/tokio-rs/tokio) | `1.53.1` | `1.53.2` |
| [insta](https://github.com/mitsuhiko/insta) | `1.48.0` | `1.49.0` |



Updates `arbitrary` from 1.4.2 to 1.5.0
- [Changelog](https://github.com/rust-fuzz/arbitrary/blob/main/CHANGELOG.md)
- [Commits](rust-fuzz/arbitrary@v1.4.2...v1.5.0)

Updates `thin-vec` from 0.2.19 to 0.2.20
- [Changelog](https://github.com/mozilla/thin-vec/blob/main/RELEASES.md)
- [Commits](mozilla/thin-vec@v0.2.19...v0.2.20)

Updates `comfy-table` from 8.0.0 to 8.0.1
- [Release notes](https://github.com/nukesor/comfy-table/releases)
- [Changelog](https://github.com/Nukesor/comfy-table/blob/main/CHANGELOG.md)
- [Commits](Nukesor/comfy-table@v8.0.0...v8.0.1)

Updates `syn` from 3.0.5 to 3.0.6
- [Release notes](https://github.com/dtolnay/syn/releases)
- [Commits](dtolnay/syn@3.0.5...3.0.6)

Updates `rand` from 0.10.2 to 0.10.3
- [Release notes](https://github.com/rust-random/rand/releases)
- [Changelog](https://github.com/rust-random/rand/blob/master/CHANGELOG.md)
- [Commits](rust-random/rand@0.10.2...0.10.3)

Updates `thiserror` from 2.0.20 to 2.0.21
- [Release notes](https://github.com/dtolnay/thiserror/releases)
- [Commits](dtolnay/thiserror@2.0.20...2.0.21)

Updates `cfg-if` from 1.0.4 to 1.0.5
- [Release notes](https://github.com/rust-lang/cfg-if/releases)
- [Changelog](https://github.com/rust-lang/cfg-if/blob/main/CHANGELOG.md)
- [Commits](rust-lang/cfg-if@v1.0.4...v1.0.5)

Updates `either` from 1.18.0 to 1.19.0
- [Changelog](https://github.com/rayon-rs/either/blob/main/RELEASES.md)
- [Commits](rayon-rs/either@1.18.0...1.19.0)

Updates `test-case` from 3.3.1 to 3.4.0
- [Release notes](https://github.com/frondeus/test-case/releases)
- [Changelog](https://github.com/frondeus/test-case/blob/master/CHANGELOG.md)
- [Commits](frondeus/test-case@v3.3.1...v3.4.0)

Updates `tokio` from 1.53.1 to 1.53.2
- [Release notes](https://github.com/tokio-rs/tokio/releases)
- [Commits](tokio-rs/tokio@tokio-1.53.1...tokio-1.53.2)

Updates `insta` from 1.48.0 to 1.49.0
- [Release notes](https://github.com/mitsuhiko/insta/releases)
- [Changelog](https://github.com/mitsuhiko/insta/blob/master/CHANGELOG.md)
- [Commits](mitsuhiko/insta@1.48.0...1.49.0)

---
updated-dependencies:
- dependency-name: arbitrary
  dependency-version: 1.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-dependencies
- dependency-name: thin-vec
  dependency-version: 0.2.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: comfy-table
  dependency-version: 8.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: syn
  dependency-version: 3.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: rand
  dependency-version: 0.10.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: thiserror
  dependency-version: 2.0.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: cfg-if
  dependency-version: 1.0.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: either
  dependency-version: 1.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-dependencies
- dependency-name: test-case
  dependency-version: 3.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-dependencies
- dependency-name: tokio
  dependency-version: 1.53.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
- dependency-name: insta
  dependency-version: 1.49.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from a team as a code owner October 9, 2026 23:20
@dependabot dependabot Bot added the C-Dependencies Pull requests that update a dependency file label Oct 9, 2026
@github-actions github-actions Bot added the Waiting On Review Waiting on reviews from the maintainers label Oct 9, 2026
@github-actions github-actions Bot added this to the v0.23 milestone Oct 9, 2026
@jedel1043
jedel1043 enabled auto-merge October 9, 2026 23:24
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

Test262 conformance changes

Test result main count PR count difference
Total 53,578 53,578 0
Passed 51,447 51,447 0
Ignored 1,648 1,648 0
Failed 483 483 0
Panics 0 0 0
Conformance 96.02% 96.02% 0.00%

Tested main commit: ef40c63283e1bb73f371d93372e9e95217a36945
Tested PR commit: 46d33a4a1f462e14fcd843985367d5269d9a8b6a
Compare commits: ef40c63...46d33a4

@jedel1043
jedel1043 added this pull request to the merge queue Oct 9, 2026
Merged via the queue into main with commit 3a3177f Oct 10, 2026
21 checks passed
@jedel1043
jedel1043 deleted the dependabot/cargo/rust-dependencies-5ff2a76f0b branch October 10, 2026 00:05
@github-actions github-actions Bot removed the Waiting On Review Waiting on reviews from the maintainers label Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

C-Dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant