Skip to content

deps(backend)(deps): bump async_zip from 0.0.17 to 0.0.18 in /backend#13

Merged
pacphi merged 1 commit into
mainfrom
dependabot/cargo/backend/async_zip-0.0.18
Mar 27, 2026
Merged

deps(backend)(deps): bump async_zip from 0.0.17 to 0.0.18 in /backend#13
pacphi merged 1 commit into
mainfrom
dependabot/cargo/backend/async_zip-0.0.18

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Mar 27, 2026

Bumps async_zip from 0.0.17 to 0.0.18.

Release notes

Sourced from async_zip's releases.

v0.0.18

Release notes:

  • Start consuming a data descriptor for read::stream, removing a previous hard-error. Note that this data descriptor currently gets voided, meaning CRC/length checks do not get performed.
  • Removes ZipEntryBuilder::sizes(), replacing with separate compressed and uncompressed setters.
  • Deletes the ZIP APPNOTE which was previously included in the repository as it's disallowed from redistribution.
  • Fixes the EOCDR locator potentially skipping bytes if read() calls didn't fully fill the internal buffer.
  • Introduces ZipFileWriter's write_entry_whole_precompressed() and write_entry_stream_precompressed(), allowing for pre-compressed data to be provided.
  • Added compress() and crc32() helpers in base::write to help with pre-compression. The specifics of these are likely to change in future versions. Added a CRC32 setter for ZipEntryBuilder also.
Commits
  • 95545ed Bump version
  • 81086e8 Introduce pre-compressed stream writing
  • 7b4735a Introduce write_entry_whole_precompressed()
  • 96b2952 Refactor EntryWholeWriter
  • df5fdd8 fix: avoid skipping bytes in the EOCDR search
  • 5a06499 Fix tests
  • 3c17882 Update thiserror requirement from 1 to 2
  • 351afcb Update sanitize-filename requirement from 0.5 to 0.6
  • 527bda9 Revert "Introduce tracing, add util functions, add core raw macro, add core l...
  • f60a9d5 Introduce tracing, add util functions, add core raw macro, add core lfh logic
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [async_zip](https://github.com/Majored/rs-async-zip) from 0.0.17 to 0.0.18.
- [Release notes](https://github.com/Majored/rs-async-zip/releases)
- [Commits](Majored/rs-async-zip@v0.0.17...v0.0.18)

---
updated-dependencies:
- dependency-name: async_zip
  dependency-version: 0.0.18
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Mar 27, 2026
@pacphi pacphi merged commit 6d46e5c into main Mar 27, 2026
10 of 11 checks passed
@dependabot dependabot Bot deleted the dependabot/cargo/backend/async_zip-0.0.18 branch March 27, 2026 17:44
pacphi added a commit that referenced this pull request May 18, 2026
…ty alerts

Markdown (CHANGELOG.md):
- Remove duplicate v0.2.0 section appended by broken release workflow
- Fix MD022 (blanks around headings), MD024 (duplicate heading), MD007
  (list indent 4→2), MD012 (multiple blank lines)

Release process (root cause fix):
- cliff.toml: clear header to stop RELEASE_NOTES from containing '# Changelog'
- release.yml: replace append-to-end logic with Python prepend after heading
  so future releases never duplicate the version section again

Link check CI:
- check-links.yml: exclude ruvector submodule (pre-existing broken links
  in its docs would fail CI on every CHANGELOG push)

Frontend security (PRs #110 + #111, Dependabot #15 + #16):
- Bump brace-expansion override 5.0.5 → 5.0.6 (DoS protection bypass)
- Add ws override 8.20.1 (uninitialized memory disclosure)
- Regenerate frontend/pnpm-lock.yaml

Rust security (Dependabot #11 + #12 + #13 — rustls-webpki CVEs):
- Update ruvector submodule 4307ae45 → 53f04197 (upstream already bumped
  reqwest 0.11 → 0.12 which drops rustls 0.21 / rustls-webpki 0.101.7)
- Regenerate backend/Cargo.lock — only rustls-webpki 0.103.13 remains

Co-Authored-By: claude-flow <ruv@ruv.net>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant