Skip to content

chore(deps): bump the prod-deps group across 1 directory with 35 updates - #233

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/cargo/prod-deps-c756232eda
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/cargo/prod-deps-c756232eda

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the prod-deps group with 35 updates in the / directory:

Package From To
clap 4.6.1 4.6.7
serde 1.0.228 1.0.229
serde-saphyr 0.0.27 1.3.0
serde_json 1.0.150 1.0.151
thiserror 2.0.18 2.0.21
minijinja 2.21.0 2.24.0
dirs 6.0.0 7.0.0
reqwest 0.13.4 0.13.5
rustls 0.23.40 0.23.45
tokio-rustls 0.26.4 0.26.6
rcgen 0.14.9 0.14.10
tokio 1.52.3 1.53.1
which 8.0.4 8.0.6
turso 0.7.2 0.8.0
rmcp 1.7.0 2.2.0
futures 0.3.32 0.3.34
http 1.4.2 1.5.0
http-body-util 0.1.3 0.1.5
hyper 1.10.1 1.11.1
hyper-util 0.1.20 0.1.21
sse-stream 0.2.3 0.3.0
schemars 1.2.1 1.2.2
uuid 1.23.3 1.26.1
tokio-util 0.7.18 0.7.19
flate2 1.1.9 1.1.10
cron 0.16.0 0.17.0
cron-descriptor 0.1.1 0.1.2
rand 0.10.2 0.10.3
base64 0.22.1 0.23.1
owo-colors 4.3.0 4.4.0
anyhow 1.0.102 1.0.104
arc-swap 1.9.1 1.9.2
zeroize 1.8.2 1.9.0
fastrand 2.4.1 2.5.0
syn 3.0.3 3.0.6

Updates clap from 4.6.1 to 4.6.7

Release notes

Sourced from clap's releases.

v4.6.7

[4.6.7] - 2026-09-14

Features

  • (derive) Add #[command(defer = <bool>)] attribute to opt-in to lazy initialisation of subcommands

v4.6.6

[4.6.6] - 2026-08-06

Features

  • Add Command::get_overridden_usage

v4.6.5

[4.6.5] - 2026-07-31

Fixes

  • (help) Correctly mark which value_names are optional with num_args

v4.6.4

[4.6.4] - 2026-07-21

Internal

  • Update to syn v3

v4.6.3

[4.6.3] - 2026-07-20

Fixes

  • (derive) Allow "literal".function() as attribute values

v4.6.2

[4.6.2] - 2026-07-15

Fixes

  • (help) Say alias when there is only one
Changelog

Sourced from clap's changelog.

[4.6.7] - 2026-09-14

Features

  • (derive) Add #[command(defer = <bool>)] attribute to opt-in to lazy initialisation of subcommands

[4.6.6] - 2026-08-06

Features

  • Add Command::get_overridden_usage

[4.6.5] - 2026-07-31

Fixes

  • (help) Correctly mark which value_names are optional with num_args

[4.6.4] - 2026-07-21

Internal

  • Update to syn v3

[4.6.3] - 2026-07-20

Fixes

  • (derive) Allow "literal".function() as attribute values

[4.6.2] - 2026-07-15

Fixes

  • (help) Say alias when there is only one
Commits
  • d3e59a9 chore: Release
  • d997f87 docs: Update changelog
  • fb6058c Merge pull request #6409 from heaths/pwsh-support
  • 2310870 test(complete): Add tests for completer_for_path
  • 5967c17 refactor(complete): Move shell detection to Shells
  • 594602b fix(complete): Detect pwsh for PowerShell
  • 3a4f2d0 Merge pull request #6427 from clap-rs/renovate/shlex-2.x
  • 67ebaed Merge pull request #6426 from clap-rs/renovate/actions-checkout-7.x
  • c968b13 chore(deps): Update Rust crate shlex to v2
  • 8f247cb chore(deps): Update actions/checkout action to v7
  • Additional commits viewable in compare view

Updates serde from 1.0.228 to 1.0.229

Release notes

Sourced from serde's releases.

v1.0.229

  • Update to syn 3
Commits
  • 7fc3b4c Release 1.0.229
  • 6d6e9a1 Merge pull request #3085 from dtolnay/syn3
  • 6dec3b7 Update to syn 3
  • cfe6692 Resolve mut_mut pedantic clippy lint
  • 1023d07 Update actions/upload-artifact@v6 -> v7
  • dd682c2 Update actions/checkout@v6 -> v7
  • 5f0f18b Update ui test suite to nightly-2026-06-01
  • 63a1498 Regenerate stderr with trybuild normalization fixes
  • fa7da4a Fix unused_features warning
  • 6b1a178 Unpin CI miri toolchain
  • Additional commits viewable in compare view

Updates serde-saphyr from 0.0.27 to 1.3.0

Release notes

Sourced from serde-saphyr's releases.

1.3.0 Maintenance and performance release

  • Integer mapping keys now compare by their parsed numeric value for duplicate detection and merge resolution, including inside composite keys (0xB and 11 compare equal). Deserializing to strings preserves the original spelling; FirstWins and LastWins retain the selected key's spelling and associated value.
  • Composite keys containing null-like strings now preserve both the key and its associated value; for example, {{"null": 1}: 2} now round-trips correctly.
  • Null mapping keys now remain distinct from null-like string keys during duplicate detection and merge resolution, including inside composite keys.
  • Null detection now respects string tags and scalar styles, preserving null-like strings such as !!str null, including when deserializing to Option<String>.
  • Explicit numeric tags (!!int and !!float) now deserialize correctly through deserialize_any, including quoted and block scalars.
  • Floating-point deserialization now rejects incompatible core tags; for example, from_str::<f64>("!!str 1.5") now returns an error.
  • Serialization now escapes U+FFFE and U+FFFF as \uFFFE and \uFFFF.
  • Serialization now preserves newline-only strings in literal block scalars, including LitStr and LitString, by using keep chomping and retaining every empty line.
  • Updated the granit-parser revision to preserve document boundaries after zero-indented root literal and folded block scalars, including empty strings.
  • Preserve string scalars across YAML 1.1 readers (PR #90, thanks @​NiklasRosenstein)
  • The version increased to 1.3 because it uses granit-parser 1.3, and that is because granit-parser added two methods to Input for performance improvements. As serde-saphyr re-exports it, the version number must be increased to 1.3 as well, even if no new features are added to this crate itself.

1.2.0 It's all about !!tags this time

This release focuses on enhanced tag support.

  • Implemented tag capturing (#183). Applications can use custom tags to express units, priorities, accessibility, or other application-specific semantics for a node. This is supported by new Tagged<T> wrapper that is similar to Commented<T>.
  • Unsupported tags can now be rejected rather than ignored (new option reject_unsupported_tags, #180). This aligns the behavior with ruamel.yaml that rejects tags for which it has no constructor (serde-saphyr does not construct this way) that caused discussion on prek.
  • Clearly wrongly placed tags like !!int [1] or !!map [1] are now an error.
  • Documentation was revised to make sure all examples compile (are not fragments).

1.1.0 Maintenance release

Added

  • Added granit-parser resource limits to Budget (#172):

    • max_buffered_comment_events (default: 32)
    • simple_key_max_lookahead (default: 1,024 characters)
    • flow_nesting_limit (default: 255)

    The limits are applied to parsers created for strings, readers, standalone budget checks, and included YAML sources. When the serde_derived_types feature is enabled, deserializing an older Budget representation that omits these fields uses the documented defaults.

Fixes

  • Fixed enums tags for struct variants (#177)
  • Improved error message wording (#178)

... (truncated)

Changelog

Sourced from serde-saphyr's changelog.

1.3.0 Maintenance and performance release

Fixed

  • Integer mapping keys now compare by their parsed numeric value for duplicate detection and merge resolution, including inside composite keys (0xB and 11 compare equal). Deserializing to strings preserves the original spelling; FirstWins and LastWins retain the selected key's spelling and associated value.
  • Composite keys containing null-like strings now preserve both the key and its associated value; for example, {{"null": 1}: 2} now round-trips correctly.
  • Null mapping keys now remain distinct from null-like string keys during duplicate detection and merge resolution, including inside composite keys.
  • Null detection now respects string tags and scalar styles, preserving null-like strings such as !!str null, including when deserializing to Option<String>.
  • Explicit numeric tags (!!int and !!float) now deserialize correctly through deserialize_any, including quoted and block scalars.
  • Floating-point deserialization now rejects incompatible core tags; for example, from_str::<f64>("!!str 1.5") now returns an error.
  • Serialization now escapes U+FFFE and U+FFFF as \uFFFE and \uFFFF.
  • Serialization now preserves newline-only strings in literal block scalars, including LitStr and LitString, by using keep chomping and retaining every empty line.
  • Updated the granit-parser revision to preserve document boundaries after zero-indented root literal and folded block scalars, including empty strings.
  • Preserve string scalars across YAML 1.1 readers (PR #90, thanks @​NiklasRosenstein)
  • The version increased to 1.3 because it uses granit-parser 1.3, and that is because granit-parser added two methods to Input for performance improvements. As serde-saphyr re-exports it, the version number must be increased to 1.3 as well, even if no new features are added to this crate itself.

1.2.0 Maintenance release

Changed

  • Folded property-interpolation depth and work limits into Budget; property resource-limit failures are now reported through Error::Budget and BudgetBreach.
  • Added the opt-in Options::reject_unsupported_tags strict mode. It rejects explicitly tagged scalar, sequence, and mapping nodes when their tag is unknown to serde-saphyr; the default remains permissive for compatibility with custom tagged enums. YAML 1.1 !!merge and !!value are accepted in this mode only as the exact scalar mapping keys << and =, respectively, while robotics-only !degrees and !radians require both the robotics crate feature and angle_conversions, and !include requires both the include crate feature and a configured resolver.
  • Enforced the scalar, sequence, or mapping node kinds required by recognized tags even when reject_unsupported_tags is disabled.
  • Hardened serializer indentation handling: indent_step is now limited to 1..=64, all serializer entry points validate it, and indentation arithmetic returns an error instead of overflowing. We do not consider this breaking because values outside this range does not look sane.
  • Validated custom anchor-generator names before emission. Names must be 1–256 bytes and cannot contain whitespace, control characters, or YAML flow punctuation; unsupported names now return a serialization error.

... (truncated)

Commits
  • 93e634c Switching to 1.3.0
  • b94505a Miri fix
  • aa4adad We will need to go 1.3
  • 7a1646e Update CHANGELOG.md
  • b17fc43 Extend the quoting check to signed lowercase 0o forms
  • 8aae8fe Preserve string scalars across YAML 1.1 readers (#190)
  • de014b0 Bump rstest from 0.26.1 to 0.27.0 (#191)
  • bbd93a8 Switch to released granit parser.
  • 49ecf1b Next release start automatically on tag push
  • 6bcee83 Fix pirate formatter test
  • Additional commits viewable in compare view

Updates serde_json from 1.0.150 to 1.0.151

Release notes

Sourced from serde_json's releases.

v1.0.151

Commits
  • de85007 Release 1.0.151
  • 3b2b3c5 Merge pull request #1331 from WonderLawrence/rawvalue-from-string-unchecked
  • 0406d96 Debug-assert well-formedness and no-whitespace in from_string_unchecked
  • cf16f75 Add RawValue::from_string_unchecked
  • 827a315 Update actions/upload-artifact@v6 -> v7
  • cea36a5 Update actions/checkout@v6 -> v7
  • See full diff in compare view

Updates thiserror from 2.0.18 to 2.0.21

Release notes

Sourced from thiserror's releases.

2.0.21

  • Fix parsing of generic unit variants in display expressions (#459)

2.0.20

  • Suppress redundant_field_names clippy lint in generated code (#454)

2.0.19

  • Update to syn 3
Commits
  • b1827ee Release 2.0.21
  • 58037b5 Merge pull request #459 from dtolnay/turbofish
  • f82a0cf Keep track of nested turbofish depth
  • 72ea492 Raise required compiler to Rust 1.77
  • 72eea0d Resolve io_other_error clippy lint in tests
  • 07f09a2 Raise required compiler to Rust 1.74
  • 2715388 Update ui test suite to nightly-2026-09-22
  • 5a306c7 Update ui test suite to nightly-2026-09-05
  • ef9383b Update ui test suite to nightly-2026-08-22
  • 8336b84 Update ui tests for version 2.0.20
  • Additional commits viewable in compare view

Updates minijinja from 2.21.0 to 2.24.0

Changelog

Sourced from minijinja's changelog.

2.24.0

  • Added the wordwrap filter to the Python bindings. #885
  • Fixed conditional expressions in keyword argument values for Jinja2 compatibility in Rust and Go. #921
  • Fixed context! sorting keys when the preserve_order feature is enabled. #920
  • Limited string repetition to 100 MB in Rust and Go to prevent excessive memory allocations.

2.23.0

  • Fixed Unicode identifiers in templates rendered through the Python bindings.

2.22.0

  • Changed rendering of none and boolean values to None, True, and False for Jinja2 compatibility in Rust and Go. #913
  • Added StringInput for custom Rust filters and functions that transform strings while preserving safety provenance.
  • Fixed safety handling in string-transforming and composing filters to preserve safe strings and escape unsafe fragments in Rust and Go.
  • Fixed the split filter to return a sequence, enabling negative indexing and slicing in Rust and Go. #909
  • Fixed Python-compatible dict methods being shadowed by same-named map keys. #903
  • Fixed loop-local assignments leaking into subsequent iterations in Rust and Go. #912
Commits
  • 0ca749f chore(release): 2.24.0
  • 0f2989a feat(python): expose wordwrap filter
  • 3eac8fa docs(changelog): document context key ordering fix
  • c867352 fix(macros): preserve context key order
  • a9e1813 fix(parser): allow conditionals in keyword arguments
  • c6fa683 fix(value): limit repeated strings to 100 MB
  • 19af7d4 chore(release): 2.23.0
  • 7f63616 docs(changelog): document Python Unicode identifiers
  • 179652f ref: Remove CLAUDE.md
  • 52b1cc6 ref: Move claude stuff
  • Additional commits viewable in compare view

Updates dirs from 6.0.0 to 7.0.0

Updates reqwest from 0.13.4 to 0.13.5

Release notes

Sourced from reqwest's releases.

v0.13.5

tl;dr

  • Add Error::is_dns() to identify errors caused by DNS resolution failures.
  • Add ClientBuilder::http1_max_headers(usize) to configure the maximum number of headers accepted in an HTTP/1 response (default 100).
  • Add TLS version to TlsInfo extension.
  • Fix hickory-dns feature to use Ipv6AndIpv4 strategy to prefer IPv6.
  • Fix sending wrong proxy-auth if multiple proxies intercept a given URL.

What's Changed

New Contributors

Full Changelog: seanmonstar/reqwest@v0.13.4...v0.13.5

Changelog

Sourced from reqwest's changelog.

v0.13.5

  • Add Error::is_dns() to identify errors caused by DNS resolution failures.
  • Add ClientBuilder::http1_max_headers(usize) to configure the maximum number of headers accepted in an HTTP/1 response (default 100).
  • Add TLS version to TlsInfo extension.
  • Fix hickory-dns feature to use Ipv6AndIpv4 strategy to prefer IPv6.
  • Fix sending wrong proxy-auth if multiple proxies intercept a given URL.
Commits
  • de55373 v0.13.5
  • 4d3fe12 fix: proxy could use wrong credentials if many matched (#3098)
  • 9f06fd2 docs: improve description of JSON method (#3082)
  • 5bdb2f0 perf(cookie): avoid cloning store and url on Poll::Pending in ResponseFuture:...
  • ffda263 perf(body): reuse tokio::time::Sleep timer via reset() in ReadTimeoutBody (#3...
  • 4e9a3c7 chore: add pull request template for human-written content
  • 17e9bcb chore(deps): upgrade base64 to 0.23 (#3074)
  • 221abe9 chore: Remove unnecessary clones and a cast (#3071)
  • 99996a1 fix(error): detect timeouts wrapped in body decode errors (#3064)
  • fc99bd5 feat: expose the negotiated TLS version via TlsInfo (#3067)
  • Additional commits viewable in compare view

Updates rustls from 0.23.40 to 0.23.45

Commits
  • 2976d90 Prepare 0.23.45
  • f9d4ee9 Handshake "alignment" check covers previously-received messages
  • c4e92e8 Keep data needed for HRR processing together
  • e553a7a server: TLS1.2 is not available after a HRR
  • 5dff9da Test whether server negotiates TLS1.2 after HRR
  • 185a063 reject a second ClientHello that changes the cipher suite
  • 9fafe6d reject a second ClientHello that drops pre_shared_key
  • 1b42c5f providers: zeroize private key DER
  • 64ad386 Bump version to 0.23.44
  • 1efbf66 bogo: remove PostQuantum setup
  • Additional commits viewable in compare view

Updates tokio-rustls from 0.26.4 to 0.26.6

Release notes

Sourced from tokio-rustls's releases.

0.26.6

0.26.5 added an optimization to batch multiple reads which could swallow some errors. Buffer errors so that they propagate to the caller as soon as the caller next reads from the stream.

What's Changed

0.26.5

What's Changed

Commits
  • 8aebb7c Bump version to 0.26.6
  • 6f8509a Rename buffered_err to error
  • bd0494d Buffer and propagate errors from transport
  • a781340 Add regression test for issue 204
  • 9d0dae6 build(deps): bump rustls from 0.23.44 to 0.23.45
  • 0ad049e build(deps): bump rustls from 0.23.43 to 0.23.44
  • 4f913c7 build(deps): bump rcgen from 0.14.9 to 0.14.10
  • f8832d2 Bump version to 0.26.5
  • c0fad2f return more data at once from TlsStream::poll_read (#198)
  • edc7306 build(deps): bump futures-util from 0.3.33 to 0.3.34
  • Additional commits viewable in compare view

Updates rcgen from 0.14.9 to 0.14.10

Release notes

Sourced from rcgen's releases.

0.14.10

What's Changed

Commits
  • f4a3b16 Bump version to 0.14.10
  • dea3d4d Upgrade to botan 0.13
  • 788b093 Upgrade to pem 4
  • 7ce21f4 Take advantage of stable ML-DSA in aws-lc-rs
  • e2dba45 Remove unused RSASSA-PSS signature algorithm
  • 37070de Omit reasonCode unspecified(0) from CRL entry extensions
  • b247a87 Write extensions for certs that only set KeyUsage or CRLDP
  • 85eafdd Reject empty CRL distribution point URIs
  • 3a99b50 Encode CRL invalidityDate as GeneralizedTime
  • See full diff in compare view

Updates tokio from 1.52.3 to 1.53.1

Release notes

Sourced from tokio's releases.

Tokio v1.53.1

1.53.1 (July 20th, 2026)

Fixed

  • signal: restore MSRV by removing OnceLock::wait from the Windows handler (#8300)

Fixed (unstable)

  • time: fix alt timer cancellation and insertion race (#8252)

Documented

  • runtime: remove dead link definition in Runtime::block_on (#8301)

#8252: tokio-rs/tokio#8252 #8300: tokio-rs/tokio#8300 #8301: tokio-rs/tokio#8301

Tokio v1.53.0

1.53.0 (July 17th, 2026)

Added

  • fs: implement From<OwnedFd> and From<OwnedHandle> for File (#8266)
  • metrics: add task schedule latency metric (#7986)
  • net: add SocketAddr methods to Unix sockets (#8144)

Changed

  • io: add #[inline] to IO trait impls for in-memory types (#8242)
  • net: implement UCred::pid on FreeBSD (#8086)
  • net: support Nuttx target os (#8259)
  • signal: refactor global variables on Windows (#8231)
  • sync: mpsc::{Receiver,UnboundedReceiver} now drops waker on drop, even if there are still senders (#8095)
  • taskdump: support taskdumps on s390x (#8192)
  • time: add #[track_caller] to timeout_at() (#8077)
  • time: consolidate mutex locks on spurious poll (#8124)
  • time: defer waker clone on spurious poll (#8107)
  • time: move lazy-registration state into Sleep (#8132)
  • tracing: remove unnecessary span clone (#8126)

Fixed

  • io: do not treat zero-length reads as EOF in Chain (#8251)
  • net: use getpeereid for QNX peer credentials (#8270)
  • runtime: avoid illegal state in FastRand (#8078)
  • sync: wake mpsc receiver when a queued reserve[_many] returns permits (#8260)
  • taskdump: skip double wake on Trace::capture/Trace::trace_with (#8043)
  • time: avoid stack overflow in runtime constructor (#8093)

... (truncated)

Commits

Updates which from 8.0.4 to 8.0.6

Release notes

Sourced from which's releases.

8.0.6

What's Changed

New Contributors

Full Changelog: harryfei/which-rs@8.0.5...8.0.6

8.0.5

What's Changed

New Contributors

Full Changelog: harryfei/which-rs@8.0.4...8.0.5

Changelog

Sourced from which's changelog.

8.0.6

  • Bug fix: #128 Resolve relative PATH entries against the user provided CWD when available, rather than the process CWD. Thanks @​RSS1102 for your contribution to which!

8.0.5

  • Bug fix: #126 Do not use current directory for search when provided path is absolute. Thanks @​weifanglab for your contribution to which!
Commits

Updates turso from 0.7.2 to 0.8.0

Release notes

Sourced from turso's releases.

0.8.0 -- 2026-09-28

Release Notes

Added

  • Add rule on helper functions (Mikaël Francoeur)
  • core/schema: Fix ALTER TABLE ADD/DROP COLUMN dropping column type size parameters (Sergei Iarymov)
  • testing: add an FTS stress workload and Antithesis singleton (Pedro Muniz)
  • core/translate: run ADD COLUMN DEFAULT type check only on STRICT tables (Ryan Lin)
  • perf/fts: add search benchmarks, CPU profiles, and peak heap measurements (Pedro Muniz)
  • core/vdbe: add AggStep fast paths for float sum, avg and count (Pekka Enberg)
  • sqlite/conformance: add generated-column coverage from the issue backlog (Glauber Costa)
  • simulator: add power loss (Pavan Nambi)
  • add valgrind to the devcontainer (Mikaël Francoeur)
  • Add aristo intent on partial writes (Mikaël Francoeur)
  • perf: add join optimizer benchmarks and metrics (Jussi Saurio)
  • postgres: support WITHIN GROUP aggregates (Joe Sluis)
  • Add per-seed timeouts to differential_fuzzer CI runs so pathological queries fail faster (Jussi Saurio)
  • bindings/c: implement sqlite3_strnicmp (Ishwar)
  • bindings/dotnet: support batches on embedded replicas (Marc-André Moreau)
  • fts/testing: add FTS workload to concurrent simulator (Preston Thorpe)
  • serverless/compat: add reconnect support (Ishwar)
  • serverless/js: fix broken README links and add repository field (Pure Tech)
  • bindings/c: implement sqlite3_total_changes64 (Ishwar)
  • bindings/dotnet: add connection-string embedded replicas (Marc-André Moreau)
  • postgres: support quit and exit commands in tursopg cli (Joe Sluis)
  • bindings/dotnet: add advanced sync database options (Marc-André Moreau)
  • core/schema: add collation property in to_sql output for btree table (thomas kim)
  • bindings/dotnet: add managed pull replica API (Marc-André Moreau)
  • postgres: implement pg_get_expr function (Joe Sluis)
  • core: make autovacuum an additive cargo feature (Pekka Enberg)
  • Add snapshot tests for multi-index with intersection (Mikaël Francoeur)
  • serverless/rust: add Builder::with_auth_token_fn for rotating tokens (Glauber Costa)
  • Add ARGS variable to run-cli Makefile target (Mikaël Francoeur)
  • Introduce Affinity::None (Mikaël Francoeur)
  • add sqltest instructions (Mikaël Francoeur)
  • Add EXPLAIN QUERY PLAN format=json (Mikaël Francoeur)
  • bindings/tcl: implement [db status] statement counters (Pekka Enberg)
  • core/storage: add more tests for codec interface (Avinash Sajjanshetty)
  • Support virtual columns in covering indexes (Mikaël Francoeur")
  • Support virtual columns in covering indexes (Mikaël Francoeur)
  • bindings/c: implement sqlite3_set_authorizer, sqlite3_db_config, sqlite3_extended_result_codes (Glauber Costa)
  • add select star benchmark (Mikaël Francoeur)
  • core: implement PRAGMA count_changes (roboturso)
  • add missing field to fix build (Mikaël Francoeur)
  • core: support NULLS FIRST/LAST in indexes (Mikaël Francoeur)
  • core/translate: add full window frame support (Jussi Saurio)
  • core/storage: add page codec interface (Avinash Sajjanshetty)
  • add missing argument to fix build (Mikaël Francoeur)
  • postgres: implement session information functions (Michael)
  • testing/antithesis: add VACUUM driver to stress-composer (Pekka Enberg)

... (truncated)

Changelog

Sourced from turso's changelog.

0.8.0 -- 2026-09-28

Added

  • Add rule on helper functions (Mikaël Francoeur)
  • core/schema: Fix ALTER TABLE ADD/DROP COLUMN dropping column type size parameters (Sergei Iarymov)
  • testing: add an FTS stress workload and Antithesis singleton (Pedro Muniz)
  • core/translate: run ADD COLUMN DEFAULT type check only on STRICT tables (Ryan Lin)
  • perf/fts: add search benchmarks, CPU profiles, and peak heap measurements (Pedro Muniz)
  • core/vdbe: add AggStep fast paths for float sum, avg and count (Pekka Enberg)
  • sqlite/conformance: add generated-column coverage from the issue backlog (Glauber Costa)
  • simulator: add power loss (Pavan Nambi)
  • add valgrind to the devcontainer (Mikaël Francoeur)
  • Add aristo intent on partial writes (Mikaël Francoeur)
  • perf: add join optimizer benchmarks and metrics (Jussi Saurio)
  • postgres: support WITHIN GROUP aggregates (Joe Sluis)
  • Add per-seed timeouts to differential_fuzzer CI runs so pathological queries fail faster (Jussi Saurio)
  • bindings/c: implement sqlite3_strnicmp (Ishwar)
  • bindings/dotnet: support batches on embedded replicas (Marc-André Moreau)
  • fts/testing: add FTS workload to concurrent simulator (Preston Thorpe)
  • serverless/compat: add reconnect support (Ishwar)
  • serverless/js: fix broken README links and add repository field (Pure Tech)
  • bindings/c: implement sqlite3_total_changes64 (Ishwar)
  • bindings/dotnet: add connection-string embedded replicas (Marc-André Moreau)
  • postgres: support quit and exit commands in tursopg cli (Joe Sluis)
  • bindings/dotnet: add advanced sync database options (Marc-André Moreau)
  • core/schema: add collation property in to_sql output for btree table (thomas kim)
  • bindings/dotnet: add managed pull replica API (Marc-André Moreau)
  • postgres: implement pg_get_expr function (Joe Sluis)
  • core: make autovacuum an additive cargo feature (Pekka Enberg)
  • Add snapshot tests for multi-index with intersection (Mikaël Francoeur)
  • serverless/rust: add Builder::with_auth_token_fn for rotating tokens (Glauber Costa)
  • Add ARGS variable to run-cli Makefile target (Mikaël Francoeur)
  • Introduce Affinity::None (Mikaël Francoeur)
  • add sqltest instructions (Mikaël Francoeur)
  • Add EXPLAIN QUERY PLAN format=json (Mikaël Francoeur)
  • bindings/tcl: implement [db status] statement counters (Pekka Enberg)
  • core/storage: add more tests for codec interface (Avinash Sajjanshetty)
  • Support virtual columns in covering indexes (Mikaël Francoeur")
  • Support virtual columns in covering indexes (Mikaël Francoeur)
  • bindings/c: implement sqlite3_set_authorizer, sqlite3_db_config, sqlite3_extended_result_codes (Glauber Costa)
  • add select star benchmark (Mikaël Francoeur)
  • core: implement PRAGMA count_changes (roboturso)
  • add missing field to fix build (Mikaël Francoeur)
  • core: support NULLS FIRST/LAST in indexes (Mikaël Francoeur)
  • core/translate: add full window frame support (Jussi Saurio)
  • core/storage: add page codec interface (Avinash Sajjanshetty)
  • add missing argument to fix build (Mikaël Francoeur)
  • postgres: implement session information functions (Michael)
  • testing/antithesis: add VACUUM driver to stress-composer (Pekka Enberg)
  • add comprehensive prepare-time benchmarks across SQL statement shapes (Pedro Muniz)

... (truncated)

Commits
  • 2829ee1 Turs...

    Description has been truncated

Bumps the prod-deps group with 35 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [clap](https://github.com/clap-rs/clap) | `4.6.1` | `4.6.7` |
| [serde](https://github.com/serde-rs/serde) | `1.0.228` | `1.0.229` |
| [serde-saphyr](https://github.com/bourumir-wyngs/serde-saphyr) | `0.0.27` | `1.3.0` |
| [serde_json](https://github.com/serde-rs/json) | `1.0.150` | `1.0.151` |
| [thiserror](https://github.com/dtolnay/thiserror) | `2.0.18` | `2.0.21` |
| [minijinja](https://github.com/mitsuhiko/minijinja) | `2.21.0` | `2.24.0` |
| dirs | `6.0.0` | `7.0.0` |
| [reqwest](https://github.com/seanmonstar/reqwest) | `0.13.4` | `0.13.5` |
| [rustls](https://github.com/rustls/rustls) | `0.23.40` | `0.23.45` |
| [tokio-rustls](https://github.com/rustls/tokio-rustls) | `0.26.4` | `0.26.6` |
| [rcgen](https://github.com/rustls/rcgen) | `0.14.9` | `0.14.10` |
| [tokio](https://github.com/tokio-rs/tokio) | `1.52.3` | `1.53.1` |
| [which](https://github.com/harryfei/which-rs) | `8.0.4` | `8.0.6` |
| [turso](https://github.com/tursodatabase/turso) | `0.7.2` | `0.8.0` |
| [rmcp](https://github.com/modelcontextprotocol/rust-sdk) | `1.7.0` | `2.2.0` |
| [futures](https://github.com/rust-lang/futures-rs) | `0.3.32` | `0.3.34` |
| [http](https://github.com/hyperium/http) | `1.4.2` | `1.5.0` |
| [http-body-util](https://github.com/hyperium/http-body) | `0.1.3` | `0.1.5` |
| [hyper](https://github.com/hyperium/hyper) | `1.10.1` | `1.11.1` |
| [hyper-util](https://github.com/hyperium/hyper-util) | `0.1.20` | `0.1.21` |
| [sse-stream](https://github.com/4t145/sse-stream) | `0.2.3` | `0.3.0` |
| [schemars](https://github.com/GREsau/schemars) | `1.2.1` | `1.2.2` |
| [uuid](https://github.com/uuid-rs/uuid) | `1.23.3` | `1.26.1` |
| [tokio-util](https://github.com/tokio-rs/tokio) | `0.7.18` | `0.7.19` |
| [flate2](https://github.com/rust-lang/flate2-rs) | `1.1.9` | `1.1.10` |
| [cron](https://github.com/zslayton/cron) | `0.16.0` | `0.17.0` |
| [cron-descriptor](https://github.com/cflockhart/cron-descriptor-rust) | `0.1.1` | `0.1.2` |
| [rand](https://github.com/rust-random/rand) | `0.10.2` | `0.10.3` |
| [base64](https://github.com/marshallpierce/rust-base64) | `0.22.1` | `0.23.1` |
| [owo-colors](https://github.com/owo-colors/owo-colors) | `4.3.0` | `4.4.0` |
| [anyhow](https://github.com/dtolnay/anyhow) | `1.0.102` | `1.0.104` |
| [arc-swap](https://github.com/vorner/arc-swap) | `1.9.1` | `1.9.2` |
| [zeroize](https://github.com/RustCrypto/utils) | `1.8.2` | `1.9.0` |
| [fastrand](https://github.com/smol-rs/fastrand) | `2.4.1` | `2.5.0` |
| [syn](https://github.com/dtolnay/syn) | `3.0.3` | `3.0.6` |



Updates `clap` from 4.6.1 to 4.6.7
- [Release notes](https://github.com/clap-rs/clap/releases)
- [Changelog](https://github.com/clap-rs/clap/blob/main/CHANGELOG.md)
- [Commits](clap-rs/clap@clap_complete-v4.6.1...clap_complete-v4.6.7)

Updates `serde` from 1.0.228 to 1.0.229
- [Release notes](https://github.com/serde-rs/serde/releases)
- [Commits](serde-rs/serde@v1.0.228...v1.0.229)

Updates `serde-saphyr` from 0.0.27 to 1.3.0
- [Release notes](https://github.com/bourumir-wyngs/serde-saphyr/releases)
- [Changelog](https://github.com/bourumir-wyngs/serde-saphyr/blob/master/CHANGELOG.md)
- [Commits](bourumir-wyngs/serde-saphyr@0.0.27...1.3.0)

Updates `serde_json` from 1.0.150 to 1.0.151
- [Release notes](https://github.com/serde-rs/json/releases)
- [Commits](serde-rs/json@v1.0.150...v1.0.151)

Updates `thiserror` from 2.0.18 to 2.0.21
- [Release notes](https://github.com/dtolnay/thiserror/releases)
- [Commits](dtolnay/thiserror@2.0.18...2.0.21)

Updates `minijinja` from 2.21.0 to 2.24.0
- [Release notes](https://github.com/mitsuhiko/minijinja/releases)
- [Changelog](https://github.com/mitsuhiko/minijinja/blob/main/CHANGELOG.md)
- [Commits](mitsuhiko/minijinja@minijinja-go/v2.21.0...minijinja-go/v2.24.0)

Updates `dirs` from 6.0.0 to 7.0.0

Updates `reqwest` from 0.13.4 to 0.13.5
- [Release notes](https://github.com/seanmonstar/reqwest/releases)
- [Changelog](https://github.com/seanmonstar/reqwest/blob/master/CHANGELOG.md)
- [Commits](seanmonstar/reqwest@v0.13.4...v0.13.5)

Updates `rustls` from 0.23.40 to 0.23.45
- [Release notes](https://github.com/rustls/rustls/releases)
- [Changelog](https://github.com/rustls/rustls/blob/main/CHANGELOG.md)
- [Commits](rustls/rustls@v/0.23.40...v/0.23.45)

Updates `tokio-rustls` from 0.26.4 to 0.26.6
- [Release notes](https://github.com/rustls/tokio-rustls/releases)
- [Commits](rustls/tokio-rustls@v/0.26.4...v/0.26.6)

Updates `rcgen` from 0.14.9 to 0.14.10
- [Release notes](https://github.com/rustls/rcgen/releases)
- [Commits](rustls/rcgen@v/0.14.9...v0.14.10)

Updates `tokio` from 1.52.3 to 1.53.1
- [Release notes](https://github.com/tokio-rs/tokio/releases)
- [Commits](tokio-rs/tokio@tokio-1.52.3...tokio-1.53.1)

Updates `which` from 8.0.4 to 8.0.6
- [Release notes](https://github.com/harryfei/which-rs/releases)
- [Changelog](https://github.com/harryfei/which-rs/blob/master/CHANGELOG.md)
- [Commits](harryfei/which-rs@8.0.4...8.0.6)

Updates `turso` from 0.7.2 to 0.8.0
- [Release notes](https://github.com/tursodatabase/turso/releases)
- [Changelog](https://github.com/tursodatabase/turso/blob/main/CHANGELOG.md)
- [Commits](tursodatabase/turso@v0.7.2...v0.8.0)

Updates `rmcp` from 1.7.0 to 2.2.0
- [Release notes](https://github.com/modelcontextprotocol/rust-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/rust-sdk/blob/main/release-plz.toml)
- [Commits](modelcontextprotocol/rust-sdk@rmcp-v1.7.0...rmcp-v2.2.0)

Updates `futures` from 0.3.32 to 0.3.34
- [Release notes](https://github.com/rust-lang/futures-rs/releases)
- [Changelog](https://github.com/rust-lang/futures-rs/blob/main/CHANGELOG.md)
- [Commits](rust-lang/futures-rs@0.3.32...0.3.34)

Updates `http` from 1.4.2 to 1.5.0
- [Release notes](https://github.com/hyperium/http/releases)
- [Changelog](https://github.com/hyperium/http/blob/master/CHANGELOG.md)
- [Commits](hyperium/http@v1.4.2...v1.5.0)

Updates `http-body-util` from 0.1.3 to 0.1.5
- [Release notes](https://github.com/hyperium/http-body/releases)
- [Commits](hyperium/http-body@http-body-util-v0.1.3...http-body-util-v0.1.5)

Updates `hyper` from 1.10.1 to 1.11.1
- [Release notes](https://github.com/hyperium/hyper/releases)
- [Changelog](https://github.com/hyperium/hyper/blob/master/CHANGELOG.md)
- [Commits](hyperium/hyper@v1.10.1...v1.11.1)

Updates `hyper-util` from 0.1.20 to 0.1.21
- [Release notes](https://github.com/hyperium/hyper-util/releases)
- [Changelog](https://github.com/hyperium/hyper-util/blob/master/CHANGELOG.md)
- [Commits](hyperium/hyper-util@v0.1.20...v0.1.21)

Updates `sse-stream` from 0.2.3 to 0.3.0
- [Release notes](https://github.com/4t145/sse-stream/releases)
- [Changelog](https://github.com/4t145/sse-stream/blob/master/CHANGELOG.md)
- [Commits](4t145/sse-stream@release-0.2.3...release-0.3.0)

Updates `schemars` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/GREsau/schemars/releases)
- [Changelog](https://github.com/GREsau/schemars/blob/master/CHANGELOG.md)
- [Commits](GREsau/schemars@v1.2.1...v1.2.2)

Updates `uuid` from 1.23.3 to 1.26.1
- [Release notes](https://github.com/uuid-rs/uuid/releases)
- [Commits](uuid-rs/uuid@v1.23.3...v1.26.1)

Updates `tokio-util` from 0.7.18 to 0.7.19
- [Release notes](https://github.com/tokio-rs/tokio/releases)
- [Commits](tokio-rs/tokio@tokio-util-0.7.18...tokio-util-0.7.19)

Updates `flate2` from 1.1.9 to 1.1.10
- [Release notes](https://github.com/rust-lang/flate2-rs/releases)
- [Commits](rust-lang/flate2-rs@1.1.9...1.1.10)

Updates `cron` from 0.16.0 to 0.17.0
- [Release notes](https://github.com/zslayton/cron/releases)
- [Commits](https://github.com/zslayton/cron/commits)

Updates `cron-descriptor` from 0.1.1 to 0.1.2
- [Commits](https://github.com/cflockhart/cron-descriptor-rust/commits/v0.1.2)

Updates `rand` from 0.10.2 to 0.10.3
- [Release notes](https://github.com/rust-random/rand/releases)
- [Changelog](https://github.com/rust-random/rand/blob/master/CHANGELOG.md)
- [Commits](rust-random/rand@0.10.2...0.10.3)

Updates `base64` from 0.22.1 to 0.23.1
- [Changelog](https://github.com/marshallpierce/rust-base64/blob/master/RELEASE-NOTES.md)
- [Commits](marshallpierce/rust-base64@v0.22.1...v0.23.1)

Updates `owo-colors` from 4.3.0 to 4.4.0
- [Release notes](https://github.com/owo-colors/owo-colors/releases)
- [Changelog](https://github.com/owo-colors/owo-colors/blob/main/CHANGELOG.md)
- [Commits](owo-colors/owo-colors@v4.3.0...v4.4.0)

Updates `anyhow` from 1.0.102 to 1.0.104
- [Release notes](https://github.com/dtolnay/anyhow/releases)
- [Commits](dtolnay/anyhow@1.0.102...1.0.104)

Updates `arc-swap` from 1.9.1 to 1.9.2
- [Changelog](https://github.com/vorner/arc-swap/blob/master/CHANGELOG.md)
- [Commits](https://github.com/vorner/arc-swap/commits)

Updates `zeroize` from 1.8.2 to 1.9.0
- [Commits](RustCrypto/utils@zeroize-v1.8.2...zeroize-v1.9.0)

Updates `fastrand` from 2.4.1 to 2.5.0
- [Release notes](https://github.com/smol-rs/fastrand/releases)
- [Changelog](https://github.com/smol-rs/fastrand/blob/master/CHANGELOG.md)
- [Commits](smol-rs/fastrand@v2.4.1...v2.5.0)

Updates `syn` from 3.0.3 to 3.0.6
- [Release notes](https://github.com/dtolnay/syn/releases)
- [Commits](dtolnay/syn@3.0.3...3.0.6)

---
updated-dependencies:
- dependency-name: clap
  dependency-version: 4.6.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: serde
  dependency-version: 1.0.229
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: serde-saphyr
  dependency-version: 1.3.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: prod-deps
- dependency-name: serde_json
  dependency-version: 1.0.151
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: thiserror
  dependency-version: 2.0.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: minijinja
  dependency-version: 2.24.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-deps
- dependency-name: dirs
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: prod-deps
- dependency-name: reqwest
  dependency-version: 0.13.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: rustls
  dependency-version: 0.23.45
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: tokio-rustls
  dependency-version: 0.26.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: rcgen
  dependency-version: 0.14.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: tokio
  dependency-version: 1.53.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-deps
- dependency-name: which
  dependency-version: 8.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: turso
  dependency-version: 0.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-deps
- dependency-name: rmcp
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: prod-deps
- dependency-name: futures
  dependency-version: 0.3.34
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: http
  dependency-version: 1.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-deps
- dependency-name: http-body-util
  dependency-version: 0.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: hyper
  dependency-version: 1.11.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-deps
- dependency-name: hyper-util
  dependency-version: 0.1.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: sse-stream
  dependency-version: 0.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-deps
- dependency-name: schemars
  dependency-version: 1.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: uuid
  dependency-version: 1.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-deps
- dependency-name: tokio-util
  dependency-version: 0.7.19
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: flate2
  dependency-version: 1.1.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: cron
  dependency-version: 0.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-deps
- dependency-name: cron-descriptor
  dependency-version: 0.1.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: rand
  dependency-version: 0.10.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: base64
  dependency-version: 0.23.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-deps
- dependency-name: owo-colors
  dependency-version: 4.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-deps
- dependency-name: anyhow
  dependency-version: 1.0.104
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: arc-swap
  dependency-version: 1.9.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: zeroize
  dependency-version: 1.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-deps
- dependency-name: fastrand
  dependency-version: 2.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-deps
- dependency-name: syn
  dependency-version: 3.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 2, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 8, 2026
@dependabot
dependabot Bot deleted the dependabot/cargo/prod-deps-c756232eda branch October 8, 2026 07:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants