Skip to content

chore(deps): update rust-minor-patch#6324

Merged
bug-ops merged 2 commits into
mainfrom
renovate/rust-minor-patch
Jul 16, 2026
Merged

chore(deps): update rust-minor-patch#6324
bug-ops merged 2 commits into
mainfrom
renovate/rust-minor-patch

Conversation

@bug-ops

@bug-ops bug-ops commented Jul 16, 2026

Copy link
Copy Markdown
Owner

This PR contains the following updates:

Package Type Update Change Pending
age workspace.dependencies minor 0.11.30.12.0 0.12.1
agent-client-protocol workspace.dependencies minor 1.0.11.2.0
agent-client-protocol-schema workspace.dependencies minor =1.1.0=1.4.0
arc-swap workspace.dependencies patch 1.9.11.9.2
bytemuck workspace.dependencies patch 1.251.25.1
bytes workspace.dependencies patch 1.12.01.12.1
chacha20poly1305 (source) workspace.dependencies minor 0.10.10.11.0
http-body-util workspace.dependencies patch 0.1.30.1.4
ignore (source) workspace.dependencies patch 0.4.260.4.28 0.4.29
k256 (source) workspace.dependencies minor 0.13.40.14.0
libsqlite3-sys workspace.dependencies minor 0.37.00.38.1
lru workspace.dependencies patch 0.18.00.18.1
open workspace.dependencies minor 5.3.55.4.0
rand (source) workspace.dependencies patch 0.10.10.10.2
regex workspace.dependencies minor 1.12.41.13.0 1.13.1
reqwest012 dependencies minor 0.120.13.4
rmcp workspace.dependencies patch 2.0.02.2.0
scrape-core workspace.dependencies patch 0.2.80.2.9
sysinfo workspace.dependencies patch 0.39.50.39.6
tree-sitter (source) workspace.dependencies patch 0.26.90.26.11
tree-sitter-highlight (source) workspace.dependencies patch 0.26.90.26.11
uuid workspace.dependencies patch 1.23.41.23.5 1.24.0

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

str4d/rage (age)

v0.12.0: rage v0.12.0

Compare Source

rage

Added
  • Support for the new native age recipient types:
    • age1tag1..
    • age1tagpq1..
Changed
  • MSRV is now 1.74.0.

age

Added
  • Support for new native age recipient types:
    • age::tag::Recipient (encryption-only)
    • age::tagpq::Recipient (encryption-only)
  • age::encrypted::EncryptedIdentity
  • age::plugin::ResolveError
Changed
  • MSRV is now 1.74.0.
  • Migrated to base64 0.22, i18n-embed 0.16.
  • age::IdentityFile::into_identities now returns Result<Vec<Box<dyn crate::Identity + Send + Sync>>, DecryptError> instead of Result<Vec<Box<dyn crate::Identity>>, DecryptError>. This re-enables cross-thread uses of IdentityFile, which were unintentionally disabled in 0.11.0.
  • age::plugin:
    • The following methods now returns Result<Self, ResolveError>:
      • Identity::default_for_plugin
      • RecipientPluginV1::new
      • IdentityPluginV1::new
  • All existing error enums nameable in the public API are now non-exhaustive:
    • age::{EncryptError, DecryptError}
    • age::IdentityFileConvertError
    • age::armor::ArmoredReadError
    • age::cli_common::ReadError
    • age::ssh::ParseRecipientKeyError
  • Removed the following error enum variants:
    • age::DecryptError::MissingPlugin
    • age::EncryptError::MissingPlugin
    • age::cli_common::ReadError::MissingPlugin

age-plugin 0.7.0

Changed
  • MSRV is now 1.74.0.
  • Migrated to age-core 0.12.

age-core

Added
  • age_core::primitives:
    • bech32_encode
    • bech32_encode_to_fmt
    • bech32_decode
    • hpke_seal
    • hpke_open
Changed
  • MSRV is now 1.74.0.

New Contributors

Full Changelog: str4d/rage@v0.11.3...v0.12.0

v0.11.5

Compare Source

v0.11.4: rage v0.11.4

Compare Source

rage

Fixed
  • Armored files that contain an empty final line are now correctly rejected.

age 0.11.5

Fixed
  • age::armor::ArmoredReader:
    • It now correctly implements the intended strict parsing profile (initially implemented in 0.9.0) by rejecting an empty final line.
    • The async API now correctly rejects some classes of truncated files that previously would cause it to hang.
agentclientprotocol/rust-sdk (agent-client-protocol)

v1.2.0: agent-client-protocol-v1.2.0

Compare Source

Added
  • (acp) add constructors for renamed adapters (#​247)

v1.1.0: agent-client-protocol-v1.1.0

Compare Source

Added
  • (deps) bump schema to 1.4.0 (#​243)
  • (acp) Make request cancellation stable (#​242)
agentclientprotocol/agent-client-protocol (agent-client-protocol-schema)

v1.4.0

Compare Source

Added
  • (unstable) Add descriptions to elicitation enum options (#​1397)

v1.3.0

Compare Source

Added
  • (schema) Stabilize boolean session config options (#​1604)
  • (unstable-v2) tighten v2 field validation (#​1587)
  • (unstable-v2) New diff format (#​1586)
  • (unstable-v2) Unify session/load and session/resume (#​1584)
  • (unstable-v2) require more session methods by default (#​1578)
  • (unstable-v2) More flexible permission requests (#​1577)
  • (unstable-v2) Align v2 Content types with the latest MCP spec (#​1576)
  • (unstable-v2) Unify the ID naming conventions across the schema (#​1567)
  • (unstable-v2) require typed config values (#​1561)
Fixed
  • (schema) Reject malformed protocol fields (#​1583)
  • (unstable) remove URL elicitation error (#​1574)
  • (unstable-v2) Preserve meta update signals in v2 (#​1573)
  • (unstable-v2) Continue to make more enums future compatible (#​1571)
  • (unstable-v2) Make empty MCP arrays optional (#​1570)
  • (unstable-v2) Make all session lifecycle requests consistent (#​1555)
Other
  • (schema) Clean up generated documentation and make wording more consistent (#​1568)
  • (rust) Box v2 protocol enum variants (#​1562)

v1.2.0

Compare Source

Added
  • (schema) Stabilize request cancellation (#​1549)
  • (unstable-v2) use EnvVariable for terminal auth env (#​1522)
  • (unstable-v2) Require auth logout support (#​1520)
  • (unstable-v2) Group v2 auth methods under auth/* (#​1519)
  • (unstable-v2) require v2 implementation info (#​1517)
Fixed
  • (unstable-v2) allow null auth capabilities (#​1539)
  • Deserialization leniency part 2 (#​1526)
  • (unstable-v2) make mcpServers optional in new sessions (#​1523)
  • (rust) Clean up Protocol version handling (#​1515)
Other
  • (unstable-v2) reorder v2 content fields (#​1541)
  • (unstable-v2) Clean up client schema types (#​1540)
  • (schema) correct Implementation description (#​1518)
Lokathor/bytemuck (bytemuck)

v1.25.1

Compare Source

tokio-rs/bytes (bytes)

v1.12.1

Compare Source

Fixed
  • Properly handle when Box::new panics (#​837)
RustCrypto/AEADs (chacha20poly1305)

v0.11.0

Compare Source

hyperium/http-body (http-body-util)

v0.1.4

Compare Source

What's Changed

  • Add Fused body combinator that always returns None once completed.
  • Add BodyExt::into_stream() to convert a body into a Stream.
  • Add Full::into_inner() to get the full Buf.
  • Add InspectFrame and InspectErr combinators.
BurntSushi/ripgrep (ignore)

v0.4.28

Compare Source

v0.4.27

Compare Source

rusqlite/rusqlite (libsqlite3-sys)

v0.38.0: 0.38.0

Compare Source

What's Changed

  • bump sqlcipher to 4.10.0 (sqlite 3.50.4) #​1725
  • Use CARGO_CFG_TARGET_FEATURE for crt-static check #​1737
  • Disable u64, usize ToSql/FromSql impl by default #​1732, ##​1722 (breaking change)
  • Make statement cache optional #​1682, #​1173 (breaking change)
  • Remove shell scripts from the published package #​1744
  • Use new interfaces with 64-bit length parameters #​1749
  • sqlite3_vtab_rhs_value #​1753
  • Handle VTab IN values #​1754
  • Give access to Connection from VTabCursor::column #​1755
  • Bump minimal SQLite version to 3.34.1 #​1733, #​1731 (breaking change)
  • Bump bundled SQLite version to 3.51.1 #​1758
  • Add support for transaction to the vtab module #​1761
  • Check Connection is owned when registering Closure as hook #​1764 (breaking change)
  • Turn libsqlite3-sys in a !#[no_std] crate #​1767
  • Add wasm32-unknown-unknown support #​1769, #​488, #​827
  • Remove useless Send/Sync on Module #​1774

Full Changelog: rusqlite/rusqlite@v0.37.0...v0.38.0

jeromefroe/lru-rs (lru)

v0.18.1

Compare Source

  • Add find_and_promote method.
Byron/open-rs (open)

v5.4.0

Compare Source

New Features
  • cargo run now shows the exact commands that were tried when opening.
    This is useful for debugging, mainly.
Bug Fixes
  • Align WSL PowerShell invocation with Windows
    Pass the WSL open target to PowerShell through the OPEN_RS_TARGET
    environment variable instead of embedding it in the command string and
    escaping it as a single-quoted PowerShell value.

    This matches the safer invocation already used by the native Windows
    backend. Keeping the PowerShell program fixed ensures that paths and URLs
    are treated purely as data, even when they contain quotes, semicolons, or
    other PowerShell metacharacters. It also removes the need for custom
    PowerShell quoting and avoids converting the target through
    to_string_lossy() during command construction.

    Add -NonInteractive for consistency with the Windows launcher and update
    the WSL tests to verify both the fixed command and the unchanged
    environment-variable value.

  • prevent launcher option and shell injection
    Opening an attacker-controlled dash-leading path could be interpreted as
    launcher options. On Windows, cmd /c start also parsed embedded quotes and
    metacharacters as command language, while the legacy gnome-open fallback
    could load a module even after a double-dash separator.

    Add command-construction regressions for malicious option-shaped paths and
    Windows shell metacharacters. Use supported separators on macOS and KDE, and
    rewrite dash-leading relative paths for launchers without separator support.
    Keep Windows values out of shell syntax by passing the default target through
    the environment and invoking custom applications directly, with explorer.exe
    as a PowerShell-free fallback.

    Exclude cmd-based opening by default, while providing an
    explicit insecure Cargo feature for users who need compatibility it
    and accept their unsafe handling of untrusted input.

    Validated with default and all-feature cargo tests, clippy, and cross-target
    cargo check --tests for aarch64 Linux and Windows.

Commit Statistics
  • 5 commits contributed to the release.
  • 3 commits were understood as conventional.
  • 1 unique issue was worked on: #​124
Commit Details
view details
  • #​124
    • Prevent launcher option and shell injection (fd29861)
  • Uncategorized
    • Merge pull request #​126 from Byron/fix-wsl (bdc3397)
    • Align WSL PowerShell invocation with Windows (7265cae)
    • Merge pull request #​125 from Byron/open-with-dash-dash (407b058)
    • cargo run now shows the exact commands that were tried when opening. (7c19c0a)
rust-random/rand (rand)

v0.10.2

Compare Source

Fixes
  • Fix possible memory safety violation due to deserialization of UniformChar from bad source (#​1790)
Changes
  • Document required output order of fn partial_shuffle and apply #[must_use] (#​1769)
  • Avoid usage of unsafe in contexts where non-local memory corruption could invalidate contract (#​1791)
rust-lang/regex (regex)

v1.13.0

Compare Source

===================
This release includes a new API, a regex! macro, for lazy compilation of
a regex from a string literal. If you use regexes a lot, it's likely you've
already written one exactly like it. The new macro can be used like this:

use regex::regex;

fn is_match(line: &str) -> bool {
    // The regex will be compiled approximately once and reused automatically.
    // This avoids the footgun of using `Regex::new` here, which would
    // guarantee that it would be compiled every time this routine is called.
    // This would likely make this routine much slower than it needs to be.
    regex!(r"bar|baz").is_match(line)
}

let hay = "\
path/to/foo:54:Blue Harvest
path/to/bar:90:Something, Something, Something, Dark Side
path/to/baz:3:It's a Trap!
";

let matches = hay.lines().filter(|line| is_match(line)).count();
assert_eq!(matches, 2);

Improvements:

  • #​709:
    Add a new regex! macro for efficient and automatic reuse of a compiled regex.
seanmonstar/reqwest (reqwest012)

v0.13.4

Compare Source

  • Add ClientBuilder::tls_sslkeylogfile(bool) option to allow using the related environment variable.
  • Add ClientBuilder::http2_keep_alive_* options for the blocking client.
  • Add TLS 1.3 support when using native-tls backend.
  • Fix redirect handling to strip sensitive headers when the scheme changes.
  • Fix HTTP/3 happy-eyeball connection creation.
  • Upgrade hickory-resolver to 0.26.

v0.13.3

Compare Source

  • Fix CertificateRevocationList parsing of PEM values.
  • Fix logging in resolver to only show host, not full URL.
  • Fix hickory-dns to fallback to a default if /etc/resolv.conf fails.
  • Fix HTTP/3 to handle STOP_SENDING as not an error.
  • Fix HTTP/3 pool to remove timed out QUIC connections.
  • Fix HTTP/3 connection establishment picking IPv4 and IPv6.
  • Upgrade rustls-platform-verifier.
  • (wasm) Only use wasm-bindgen on unknown-* targets.

v0.13.2

Compare Source

  • Fix HTTP/2 and native-tls ALPN feature combinations.
  • Fix HTTP/3 to send h3 ALPN.
  • (wasm) fix RequestBuilder::json() from override previously set content-type.

v0.13.1

Compare Source

  • Fixes compiling with rustls on Android targets.

v0.13.0

Compare Source

  • Breaking changes:
    • rustls is now the default TLS backend, instead of native-tls.
    • rustls crypto provider defaults to aws-lc instead of ring. (rustls-no-provider exists if you want a different crypto provider)
    • rustls-tls has been renamed to rustls.
    • rustls roots features removed, rustls-platform-verifier is used by default.
      • To use different roots, call tls_certs_only(your_roots).
    • native-tls now includes ALPN. To disable, use native-tls-no-alpn.
    • query and form are now crate features, disabled by default.
    • Long-deprecated methods and crate features have been removed (such as trust-dns, which was renamed hickory-dns a while ago).
  • Many TLS-related methods renamed to improve autocompletion and discovery, but previous name left in place with a "soft" deprecation. (just documented, no warnings)
    • For example, prefer tls_backend_rustls() over use_rustls_tls().

v0.12.28

  • Fix compiling on Windows if TLS and SOCKS features are not enabled.

v0.12.27

  • Add ClientBuilder::windows_named_pipe(name) option that will force all requests over that Windows Named Piper.

v0.12.26

  • Fix sending Accept-Encoding header only with values configured with reqwest, regardless of underlying tower-http config.

v0.12.25

  • Add Error::is_upgrade() to determine if the error was from an HTTP upgrade.
  • Fix sending Proxy-Authorization if only username is configured.
  • Fix sending Proxy-Authorization to HTTPS proxies when the target is HTTP.
  • Refactor internal decompression handling to use tower-http.

v0.12.24

  • Refactor cookie handling to an internal middleware.
  • Refactor internal random generator.
  • Refactor base64 encoding to reduce a copy.
  • Documentation updates.

v0.12.23

  • Add ClientBuilder::unix_socket(path) option that will force all requests over that Unix Domain Socket.
  • Add ClientBuilder::retry(policy) and reqwest::retry::Builder to configure automatic retries.
  • Add ClientBuilder::dns_resolver2() with more ergonomic argument bounds, allowing more resolver implementations.
  • Add http3_* options to blocking::ClientBuilder.
  • Fix default TCP timeout values to enabled and faster.
  • Fix SOCKS proxies to default to port 1080
  • (wasm) Add cache methods to RequestBuilder.

v0.12.22

  • Fix socks proxies when resolving IPv6 destinations.

v0.12.21

  • Fix socks proxy to use socks4a:// instead of socks4h://.
  • Fix Error::is_timeout() to check for hyper and IO timeouts too.
  • Fix request Error to again include URLs when possible.
  • Fix socks connect error to include more context.
  • (wasm) implement Default for Body.

v0.12.20

  • Add ClientBuilder::tcp_user_timeout(Duration) option to set TCP_USER_TIMEOUT.
  • Fix proxy headers only using the first matched proxy.
  • (wasm) Fix re-adding Error::is_status().

v0.12.19

  • Fix redirect that changes the method to GET should remove payload headers.
  • Fix redirect to only check the next scheme if the policy action is to follow.
  • (wasm) Fix compilation error if cookies feature is enabled (by the way, it's a noop feature in wasm).

v0.12.18

  • Fix compilation when socks enabled without TLS.

v0.12.17

  • Fix compilation on macOS.

v0.12.16

  • Add ClientBuilder::http3_congestion_bbr() to enable BBR congestion control.
  • Add ClientBuilder::http3_send_grease() to configure whether to send use QUIC grease.
  • Add ClientBuilder::http3_max_field_section_size() to configure the maximum response headers.
  • Add ClientBuilder::tcp_keepalive_interval() to configure TCP probe interval.
  • Add ClientBuilder::tcp_keepalive_retries() to configure TCP probe count.
  • Add Proxy::headers() to add extra headers that should be sent to a proxy.
  • Fix redirect::Policy::limit() which had an off-by-1 error, allowing 1 more redirect than specified.
  • Fix HTTP/3 to support streaming request bodies.
  • (wasm) Fix null bodies when calling Response::bytes_stream().

v0.12.15

  • Fix Windows to support both ProxyOverride and NO_PROXY.
  • Fix http3 to support streaming response bodies.
  • Fix http3 dependency from public API misuse.

v0.12.14

  • Fix missing fetch_mode_no_cors(), marking as deprecated when not on WASM.

v0.12.13

  • Add Form::into_reader() for blocking multipart forms.
  • Add Form::into_stream() for async multipart forms.
  • Add support for SOCKS4a proxies.
  • Fix decoding responses with multiple zstd frames.
  • Fix RequestBuilder::form() from overwriting a previously set Content-Type header, like the other builder methods.
  • Fix cloning of request timeout in blocking::Request.
  • Fix http3 synchronization of connection creation, reducing unneccesary extra connections.
  • Fix Windows system proxy to use ProxyOverride as a NO_PROXY value.
  • Fix blocking read to correctly reserve and zero read buffer.
  • (wasm) Add support for request timeouts.
  • (wasm) Fix Error::is_timeout() to return true when from a request timeout.

v0.12.12

  • (wasm) Fix compilation by not compiler tokio/time on WASM.

v0.12.11

  • Fix decompression returning an error when HTTP/2 ends with an empty data frame.

v0.12.10

  • Add ClientBuilder::connector_layer() to allow customizing the connector stack.
  • Add ClientBuilder::http2_max_header_list_size() option.
  • Fix propagating body size hint (content-length) information when wrapping bodies.
  • Fix decompression of chunked bodies so the connections can be reused more often.

v0.12.9

  • Add tls::CertificateRevocationLists support.
  • Add crate features to enable webpki roots without selecting a rustls provider.
  • Fix connection_verbose() to output read logs.
  • Fix multipart::Part::file() to automatically include content-length.
  • Fix proxy to internally no longer cache system proxy settings.

v0.12.8

  • Add support for SOCKS4 proxies.
  • Add multipart::Form::file() method for adding files easily.
  • Add Body::wrap() to wrap any http_body::Body type.
  • Fix the pool configuration to use a timer to remove expired connections.

v0.12.7

  • Revert adding impl Service<http::Request<_>> for Client.

v0.12.6

  • Add support for danger_accept_invalid_hostnames for rustls.
  • Add impl Service<http::Request<Body>> for Client and &'_ Client.
  • Add support for !Sync bodies in Body::wrap_stream().
  • Enable happy eyeballs when hickory-dns is used.
  • Fix Proxy so that HTTP(S)_PROXY values take precedence over ALL_PROXY.
  • Fix blocking::RequestBuilder::header() from unsetting sensitive on passed header values.

v0.12.5

  • Add blocking::ClientBuilder::dns_resolver() method to change DNS resolver in blocking client.
  • Add http3 feature back, still requiring reqwest_unstable.
  • Add rustls-tls-no-provider Cargo feature to use rustls without a crypto provider.
  • Fix Accept-Encoding header combinations.
  • Fix http3 resolving IPv6 addresses.
  • Internal: upgrade to rustls 0.23.

v0.12.4

  • Add zstd support, enabled with zstd Cargo feature.
  • Add ClientBuilder::read_timeout(Duration), which applies the duration for each read operation. The timeout resets after a successful read.

v0.12.3

  • Add FromStr for dns::Name.
  • Add ClientBuilder::built_in_webpki_certs(bool) to enable them separately.
  • Add ClientBuilder::built_in_native_certs(bool) to enable them separately.
  • Fix sending content-length: 0 for GET requests.
  • Fix response body content_length() to return value when timeout is configured.
  • Fix ClientBuilder::resolve() to use lowercase domain names.

v0.12.2

  • Fix missing ALPN when connecting to socks5 proxy with rustls.
  • Fix TLS version limits with rustls.
  • Fix not detected ALPN h2 from server with native-tls.

v0.12.1

  • Fix ClientBuilder::interface() when no TLS is enabled.
  • Fix TlsInfo::peer_certificate() being truncated with rustls.
  • Fix panic if http2 feature disabled but TLS negotiated h2 in ALPN.
  • Fix Display for Error to not include its source error.
bug-ops/scrape-rs (scrape-core)

v0.2.9

Compare Source

Fixed
  • Bump crossbeam-epoch 0.9.18 → 0.9.20 (RUSTSEC-2026-0204: invalid pointer dereference in
    fmt::Pointer impl for Atomic and Shared when the underlying pointer is invalid)
  • Bump anyhow 1.0.102 → 1.0.103 (RUSTSEC: undefined behavior in downcast_mut)
  • Bump memmap2 0.9.10 → 0.9.11 (RUSTSEC-2026-0186)
Dependencies
  • Bump lol_html 2.9.0 → 3.0.0
  • Bump selectors 0.38.0 → 0.39.0
  • Bump napi 3.9.1 → 3.10.3, napi-derive 3.5.6 → 3.5.9 (across several rust-minor group updates)
  • Bump @napi-rs/cli 3.6.2 → 3.7.2
  • Bump @emnapi/core 1.11.0 → 1.11.2, @emnapi/runtime 1.11.0 → 1.11.2 (Node.js package)
  • Bump @biomejs/biome 2.4.16 → 2.5.2 (Node.js and WASM packages)
  • Bump CI actions: actions/checkout 6 → 7, actions/cache 5 → 6,
    lewagon/wait-on-check-action 1.7.0 → 1.8.1
GuillaumeGomez/sysinfo (sysinfo)

v0.39.6

Compare Source

  • NetBSD: Add support for disk I/O usage.
  • NetBSD: Improve retrieval of disk information.
tree-sitter/tree-sitter (tree-sitter)

v0.26.11

Compare Source

What's Changed

Full Changelog: tree-sitter/tree-sitter@v0.26.10...v0.26.11

uuid-rs/uuid (uuid)

v1.23.5

Compare Source

What's Changed

New Contributors

Full Changelog: uuid-rs/uuid@v1.23.4...v1.23.5


Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • "before 6am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@bug-ops bug-ops added the dependencies Dependency updates label Jul 16, 2026
@bug-ops
bug-ops enabled auto-merge (squash) July 16, 2026 18:09
@bug-ops

bug-ops commented Jul 16, 2026

Copy link
Copy Markdown
Owner Author

⚠️ Artifact update problem

Renovate failed to update artifacts related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: Cargo.lock
Command failed: cargo update --config net.git-fetch-with-cli=true --manifest-path Cargo.toml --workspace
    Updating crates.io index
error: failed to select a version for `agent-client-protocol`.
    ... required by package `zeph-acp v0.22.1 (/tmp/renovate/repos/github/bug-ops/zeph/crates/zeph-acp)`
versions that meet the requirements `^1.2.0` are: 1.2.0

package `zeph-acp` depends on `agent-client-protocol` with feature `unstable_boolean_config` but `agent-client-protocol` does not have that feature.
help: available features: default, unstable, unstable_auth_methods, unstable_elicitation, unstable_end_turn_token_usage, unstable_mcp_over_acp, unstable_protocol_v2, unstable_session_fork


failed to select a version for `agent-client-protocol` which could resolve this conflict

File name: Cargo.lock
Command failed: cargo update --config net.git-fetch-with-cli=true --manifest-path crates/zeph-llm/Cargo.toml --workspace
    Updating crates.io index
error: failed to select a version for `agent-client-protocol`.
    ... required by package `zeph-acp v0.22.1 (/tmp/renovate/repos/github/bug-ops/zeph/crates/zeph-acp)`
versions that meet the requirements `^1.2.0` are: 1.2.0

package `zeph-acp` depends on `agent-client-protocol` with feature `unstable_boolean_config` but `agent-client-protocol` does not have that feature.
help: available features: default, unstable, unstable_auth_methods, unstable_elicitation, unstable_end_turn_token_usage, unstable_mcp_over_acp, unstable_protocol_v2, unstable_session_fork


failed to select a version for `agent-client-protocol` which could resolve this conflict

@github-actions github-actions Bot added llm zeph-llm crate (Ollama, Claude) rust Rust code changes chore Maintenance tasks size/S Small PR (11-50 lines) labels Jul 16, 2026
@bug-ops
bug-ops force-pushed the renovate/rust-minor-patch branch from cc21907 to fdc9d4d Compare July 16, 2026 22:30
@github-actions github-actions Bot added size/XL Extra large PR (500+ lines) and removed size/S Small PR (11-50 lines) labels Jul 16, 2026
renovate Bot and others added 2 commits July 17, 2026 00:30
agent-client-protocol 1.1.0 stabilized and removed the
unstable_boolean_config/unstable_cancel_request feature flags that
zeph-acp still forwarded to, breaking cargo metadata resolution;
convert both to local no-op features. Schema 1.4.0 also renamed
SetProviderRequest/DisableProviderRequest/ProviderInfo's id field to
provider_id (a new ProviderId newtype) and made
SessionConfigOptionValue::Boolean unconditional; update zeph-acp
accordingly.

chacha20poly1305 0.11's aead 0.6 bump deprecated Array::from_slice,
KeyInit::generate_key, and AeadCore::generate_nonce in favor of
TryFrom and the new Generate trait; update the durable cipher and its
bench stub.

Revert an incorrect bump of zeph-llm's pinned reqwest012 alias (needed
only for ABI compatibility with ollama-rs's own reqwest ^0.12.28
requirement) from 0.13.4 back to 0.12, restoring the rustls-tls
feature name that only exists on that line.
@bug-ops
bug-ops force-pushed the renovate/rust-minor-patch branch from fdc9d4d to 48f0cc1 Compare July 16, 2026 22:31
@github-actions github-actions Bot added documentation Improvements or additions to documentation core zeph-core crate and removed llm zeph-llm crate (Ollama, Claude) labels Jul 16, 2026
@bug-ops
bug-ops merged commit f06b3b9 into main Jul 16, 2026
42 of 46 checks passed
@bug-ops
bug-ops deleted the renovate/rust-minor-patch branch July 16, 2026 22:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore Maintenance tasks core zeph-core crate dependencies Dependency updates documentation Improvements or additions to documentation rust Rust code changes size/XL Extra large PR (500+ lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant