Skip to content

chore(deps): bump the fuzz-minor-patch group across 1 directory with 7 updates - #87

Open
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/cargo/fuzz/dev/fuzz-minor-patch-63ac42d0ff
Open

dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/cargo/fuzz/dev/fuzz-minor-patch-63ac42d0ff

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the fuzz-minor-patch group with 7 updates in the /fuzz directory:

Package From To
aws-lc-rs 1.18.0 1.18.1
encoding_rs 0.8.35 0.8.42
indexmap 2.14.0 2.14.2
libc 0.2.189 0.2.190
rand 0.10.2 0.10.3
thiserror 2.0.20 2.0.21
tokio 1.53.1 1.53.2

Updates aws-lc-rs from 1.18.0 to 1.18.1

Release notes

Sourced from aws-lc-rs's releases.

aws-lc-rs v1.18.1

What's Changed

  • Add ECDSA P-256 SHA-1 ASN.1 signature verification by @​assafvayner in aws/aws-lc-rs#1214
    • Adds ECDSA_P256_SHA1_ASN1 for verifying ASN.1 DER-encoded ECDSA P-256 signatures over SHA-1, so applications can verify legacy signatures such as CloudFront signed URLs using ECDSA P-256 with the default SHA-1 hash.
    • SHA-1 remains available for legacy verification only. This release does not add a corresponding signing algorithm.
  • Tighten AEAD, cipher IV, HKDF, ECDH, and RSA API contracts by @​justsmth in aws/aws-lc-rs#1215
    • In-place AEAD sealing now verifies that Extend produced exactly enough space for the plaintext and authentication tag before passing the buffer to AWS-LC. Non-conforming custom buffers now return Err(Unspecified).
    • Streaming cipher constructors now reject missing or mismatched IV contexts, matching the validation already performed by the one-shot APIs.
    • Salt::from(Okm) now uses the output algorithm selected by the Okm, rather than the algorithm from the source PRK.
    • ECDH shared-secret storage is now zeroized on fallible derive paths.
    • RSA verify_digest_sig now requires the supplied digest to match the digest configured by RsaParameters, for both parsed and unparsed public keys.
    • Valid inputs are unaffected. Calls using inconsistent algorithms, IV contexts, or custom AEAD buffers now fail closed with Err(Unspecified).

Upstream AWS-LC

  • aws-lc-sys v0.45.0 aligns with AWS-LC v5.7.0 (previously v5.5.0). See also the release notes for v5.6.0.
    • v5.7.0 corrects EVP_DecryptUpdate for padded block ciphers so it modifies only the output range reported through out_len. aws-lc-rs now includes canary-based regression coverage around the documented minimum output-buffer sizes.
  • aws-lc-fips-sys v0.14.2 moves to AWS-LC FIPS v4.2.0.
    • Includes the equivalent EVP_DecryptUpdate correction for FIPS builds.
    • Restores FIPS builds with Clang 20 and newer.
    • Removes the FIPS compiler wrapper's dependency on /usr/bin/env, fixing builds in Nix and similar sandboxed environments.

Build Improvements

  • Export cargo:root metadata when linking against a system-installed AWS-LC by @​weihanglo in aws/aws-lc-rs#1208
    • The system-library path now exposes the installation prefix through DEP_AWS_LC_*_ROOT, consistently with the CC and CMake builders, so downstream build scripts can rely on the metadata regardless of how AWS-LC was built.
  • Fix -Wa,--debug-prefix-map handling with Clang and LTO by @​justsmth in aws/aws-lc-rs#1212
    • Fixes Clang builds when CFLAGS contains -flto or -flto=thin. The assembler-specific flag is now used only with GCC; Clang's integrated assembler uses -ffile-prefix-map directly.
  • Filter raw target-triple CFLAGS spellings when compiling jitterentropy by @​justsmth in aws/aws-lc-rs#1207
    • Prevents inherited optimization flags from overriding jitterentropy's required -O0, including when environment variables are set by a parent process using raw or legacy-normalized target triples.

Issues Being Closed

Other Merged PRs

... (truncated)

Commits
  • 22e629d Prepare v1.18.1 (#1224)
  • c4fde5c Prepare aws-lc-fips-sys v0.14.2 (#1221)
  • 7943223 Prepare aws-lc-sys v0.45.0 (#1220)
  • 8ea2229 fix: tighten AEAD, cipher IV, and digest API contracts (#1215)
  • bcca4d1 Add ECDSA P-256 SHA-1 ASN.1 verification algorithm (#1214)
  • 32338a5 fix(builder): filter the raw-triple CFLAGS spelling for jitterentropy (#1207)
  • af422bd Fix -Wa,--debug-prefix-map probe (#1212)
  • 749b26f ci: replace removed llvm-devel-lite package in FreeBSD jobs (#1213)
  • 36c7a68 fix(publish): verify packaged crate with cargo build, not cargo test (#1201)
  • c71ab00 fix: address clippy::assert_is_empty lints in ECB cipher modes (#1210)
  • Additional commits viewable in compare view

Updates encoding_rs from 0.8.35 to 0.8.42

Commits
  • a155adc Increment version number to 0.8.42
  • 6603aed Attach the multiversion crate to the std feature instead
  • f718b07 docs: multiversion is compiled only with simd-accel
  • 4434afa chore: pull in multiversion only when it is actually used
  • 96138f6 Update main branch in URLs
  • 0860491 Increment version number to 0.8.41
  • 2e9ea61 Document multiversion 0.9.0 and syn version
  • 6667988 build(deps): accept multiversion 0.9.0
  • 662cb42 Allow split_u16_stride_mut as dead code
  • 55f2530 Increment version number to 0.8.40
  • Additional commits viewable in compare view

Updates indexmap from 2.14.0 to 2.14.2

Changelog

Sourced from indexmap's changelog.

2.14.2 (2026-09-04)

  • Fix item hygiene in map and set macros. Previously, an internal const CAP could shadow the same name in the caller's namespace.
  • Allow const initialization of empty indexmap_with_default! and indexset_with_default!. The hasher may also be omitted if it's inferrable.

2.14.1 (2026-08-28)

  • Simplify comparisons where Equivalent isn't needed (Q = K).
  • Unify index assertions for bounds checks.
  • Fix (or expect) clippy lints.
Commits
  • 41a8708 Merge pull request #450 from cuviper/macros
  • 0fb7b5c Release 2.14.2
  • 55e6b28 Improve the empty macro cases
  • c067355 Fix item hygiene in user macros
  • fdf7e17 Merge pull request #449 from cuviper/release-2.14.1
  • ada540e Release 2.14.1
  • af93b43 expect clippy::redundant_slicing in tests
  • c95da18 fix clippy::derivable_impls
  • 2196365 fix clippy::useless_vec (and more) in tests
  • 1c2be7b use inherent usize::MAX
  • Additional commits viewable in compare view

Updates libc from 0.2.189 to 0.2.190

Release notes

Sourced from libc's releases.

0.2.190

There is now a single config for enabling 64-bit time_t: libc_unstable_time64. This can be set unconditionally; it opts in to 64-bit time_t on the following platforms that use 32-bit by default:

  • 32-bit Linux-GNU
  • 32-bit Linux-uClibc
  • 32-bit Linux-musl. Note that setting this flag also enables some other changes that happend in musl v1.2.
  • 32-bit Windows-GNU
  • ESP-IDF (all targets with this environment are 32-bit)

Most other 32-bit platforms are either already using 64-bit time_t, or are considered legacy and will not be gaining support from their upstream maintainers.

You can enable this using RUSTFLAGS:

RUSTFLAGS='--cfg=libc_unstable_time64' cargo ...

Note that there may still be some changes to features gated by this config option, hence "unstable" in its name. In the near future we will rename it to just libc_time64. Until then, please test it out and report any bugs you find!

Support

  • Add initial support for HelenOS (#4355)

Added

We are slowly filling out the Default implementations, to reduce the need for mem::zeroed() in user code:

  • Unix: Implement Default for a number of structs, especially on Apple platforms (#5576)
  • Linux, NetBSD: Give statvfs a Default impl (#5583)
  • Linux: Add Default to a linux/can.rs structs (#5257)

Other additions:

  • Expose the libc_unstable_time64 cfg (#5411)
  • Android, Glibc: Add pthread_gettid_np (#5359)
  • Android: Add RTLD_NEXT (#5323)
  • Android: Add reuseport BPF socket options (#5366)
  • Apple: Add TCP header flags, options and SACK limits (#5358)
  • Apple: Add NET_RT_DUMP2 (#5442)
  • Apple: Add posix_spawn_file_actions_add(f)chdir(_np) (#5558)
  • BSD: Add BPF_WORDALIGN (#5320)
  • BSD: Add lchmod and lchflags where supported (#5400)
  • BSD: Add minherit and related constants (#4849)
  • Docs: Add more links to public headers and manual pages (#5407), (#5485)

... (truncated)

Changelog

Sourced from libc's changelog.

0.2.190 - 2026-10-02

There is now a single config for enabling 64-bit time_t: libc_unstable_time64. This can be set unconditionally; it opts in to 64-bit time_t on the following platforms that use 32-bit by default:

  • 32-bit Linux-GNU
  • 32-bit Linux-uClibc
  • 32-bit Linux-musl. Note that setting this flag also enables some other changes that happend in musl v1.2.
  • 32-bit Windows-GNU
  • ESP-IDF (all targets with this environment are 32-bit)

Most other 32-bit platforms are either already using 64-bit time_t, or are considered legacy and will not be gaining support from their upstream maintainers.

You can enable this using RUSTFLAGS:

RUSTFLAGS='--cfg=libc_unstable_time64' cargo ...

Note that there may still be some changes to features gated by this config option, hence "unstable" in its name. In the near future we will rename it to just libc_time64. Until then, please test it out and report any bugs you find!

Support

  • Add initial support for HelenOS (#4355)

Added

We are slowly filling out the Default implementations, to reduce the need for mem::zeroed() in user code:

  • Unix: Implement Default for a number of structs, especially on Apple platforms (#5576)
  • Linux, NetBSD: Give statvfs a Default impl (#5583)
  • Linux: Add Default to a linux/can.rs structs (#5257)

Other additions:

  • Expose the libc_unstable_time64 cfg (#5411)
  • Android, Glibc: Add pthread_gettid_np (#5359)
  • Android: Add RTLD_NEXT (#5323)
  • Android: Add reuseport BPF socket options (#5366)
  • Apple: Add TCP header flags, options and SACK limits (#5358)
  • Apple: Add NET_RT_DUMP2 (#5442)
  • Apple: Add posix_spawn_file_actions_add(f)chdir(_np) (#5558)
  • BSD: Add BPF_WORDALIGN (#5320)
  • BSD: Add lchmod and lchflags where supported (#5400)
  • BSD: Add minherit and related constants (#4849)

... (truncated)

Commits
  • 7b0ab55 ci: Rename publish_0.2.yml to release.yaml
  • ac85dde ci: Sync release permissions with main
  • 8f8cd20 libc: Release 0.2.190
  • 052c6e6 changelog: Fix an incorrect commit link
  • ea19fd7 test: Remove explicit libc version
  • 6dbf3a2 dragonfly: Move INHERIT_ZERO to the freebsd module
  • 8a64766 apple: add posix_spawn_file_actions_add(f)chdir(_np)
  • 28de514 linux, netbsd: Give statvfs a Default impl
  • a58a95f cygwin: Change POSIX_SPAWN_* flags to c_short
  • d175264 apple: timeval32 is exhaustive
  • Additional commits viewable in compare view

Updates rand from 0.10.2 to 0.10.3

Changelog

Sourced from rand's changelog.

[0.10.3] — 2026-09-20

Fixes

  • Fix WeightedIndex panic when the sum of float weights is infinite; return Error::Overflow instead (#1808)
  • Fix spurious Error::NonFinite from Uniform::new_inclusive on large finite float ranges such as 0.0..=f64::MAX (#1821)
  • Fix possible panic due to sampling a deserialized Uniform<char> (#1831)

Changes

  • Report exact remaining lengths from WeightedIndex::weights() and reduce overhead when reading weights (#1838)

#1808: rust-random/rand#1808 #1821: rust-random/rand#1821 #1831: rust-random/rand#1831 #1838: rust-random/rand#1838

Commits
  • 9e7d328 Prepare rand 0.10.3 (#1840)
  • f73ce74 Optimize WeightedIndex weight lookup and iteration (#1838)
  • ef9e044 Avoid panic from deserialized Uniform\<char> where range == 0 (#1831)
  • c994eb1 docs: fix angle unit in quick start example (#1839)
  • 33dea4f Test that WeightedIndex rejects INFINITY with Error::Overflow (#1822)
  • 94c9078 Fix Uniform::new_inclusive overflow on large finite float ranges (#1821)
  • bb1262f Use Xoshiro256PlusPlus in examples/rayon-monte-carlo.rs (#1805)
  • 521fab6 Stop pinning dependencies (#1820)
  • 3f7c433 Stop pinning dependencies
  • cf4f73e sample_efraimidis_spirakis: error on more than amount non-finite weights (#1814)
  • Additional commits viewable in compare view

Updates thiserror from 2.0.20 to 2.0.21

Release notes

Sourced from thiserror's releases.

2.0.21

  • Fix parsing of generic unit variants in display expressions (#459)
Commits
  • b1827ee Release 2.0.21
  • 58037b5 Merge pull request #459 from dtolnay/turbofish
  • f82a0cf Keep track of nested turbofish depth
  • 72ea492 Raise required compiler to Rust 1.77
  • 72eea0d Resolve io_other_error clippy lint in tests
  • 07f09a2 Raise required compiler to Rust 1.74
  • 2715388 Update ui test suite to nightly-2026-09-22
  • 5a306c7 Update ui test suite to nightly-2026-09-05
  • ef9383b Update ui test suite to nightly-2026-08-22
  • 8336b84 Update ui tests for version 2.0.20
  • See full diff in compare view

Updates tokio from 1.53.1 to 1.53.2

Release notes

Sourced from tokio's releases.

Tokio v1.53.2

1.53.2 (October 3rd, 2026)

Fixed

  • fs: handle integer overflow in buffered relative seek (#8574)
  • io: revert "always cleanup AsyncFd registration list on deregister" (#8540)
  • process: unregister Windows wait before closing child handle (#8564)
  • rt: drop blocking pool mutex before shutting down rejected task (#8562)
  • sync: fix mpsc index wraparound in block reclamation (#8546)
  • sync: forget mpsc Permit before sending value (#8560)
  • sync: validate MAX_PERMITS in Semaphore::acquire (#8548)
  • sync: wake broadcast Sender::closed outside mutex (#8558)
  • task: drop replaced waker outside lock in JoinSet (#8554)
  • time: drop timer lock before dropping waker in clear_entry (#8552)
  • time: expire timers directly on shutdown without rotating wheel (#8570)

Fixed (unstable)

  • fs: clamp io_uring read length to u32::MAX (#8572)
  • rt: ignore current_thread task dumps from other runtimes (#8544)
  • rt: preserve io_uring context if a completion waker panics (#8566)
  • sync: fix semaphore use-after-free and permit leak on tracing panic (#8542)
  • taskdump: restore deferred leaf wakes during capture (#8445)
  • time: drop stored waker when cancelling alt timer entry (#8550)

#8445: tokio-rs/tokio#8445 #8572: tokio-rs/tokio#8572 #8540: tokio-rs/tokio#8540 #8542: tokio-rs/tokio#8542 #8544: tokio-rs/tokio#8544 #8546: tokio-rs/tokio#8546 #8548: tokio-rs/tokio#8548 #8550: tokio-rs/tokio#8550 #8552: tokio-rs/tokio#8552 #8554: tokio-rs/tokio#8554 #8558: tokio-rs/tokio#8558 #8560: tokio-rs/tokio#8560 #8562: tokio-rs/tokio#8562 #8564: tokio-rs/tokio#8564 #8566: tokio-rs/tokio#8566 #8570: tokio-rs/tokio#8570 #8574: tokio-rs/tokio#8574

Commits
  • ff0c406 chore: prepare Tokio v1.53.2 (#8580)
  • a762700 Merge 'tokio-1.51.5' into 'tokio-1.53.x' (#8577)
  • ec31a9f chore: prepare Tokio v1.51.5 (#8579)
  • 625c851 sync: assign semaphore permits before emitting tracing event (#8542)
  • 832dd23 sync: avoid leaking semaphore permits on tracing panic (#8542)
  • 826954a sync: unlink semaphore waiter before emitting tracing event (#8542)
  • 9a47992 process: unregister Windows wait before closing child handle (#8564)
  • 2fc5972 fs: handle integer overflow in buffered relative seek (#8574)
  • 85a6d13 io: revert "always cleanup AsyncFd registration list on deregister" (#8540)
  • 436faa2 rt: drop blocking pool mutex before shutting down rejected task (#8562)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…7 updates

Bumps the fuzz-minor-patch group with 7 updates in the /fuzz directory:

| Package | From | To |
| --- | --- | --- |
| [aws-lc-rs](https://github.com/aws/aws-lc-rs) | `1.18.0` | `1.18.1` |
| [encoding_rs](https://github.com/hsivonen/encoding_rs) | `0.8.35` | `0.8.42` |
| [indexmap](https://github.com/indexmap-rs/indexmap) | `2.14.0` | `2.14.2` |
| [libc](https://github.com/rust-lang/libc) | `0.2.189` | `0.2.190` |
| [rand](https://github.com/rust-random/rand) | `0.10.2` | `0.10.3` |
| [thiserror](https://github.com/dtolnay/thiserror) | `2.0.20` | `2.0.21` |
| [tokio](https://github.com/tokio-rs/tokio) | `1.53.1` | `1.53.2` |



Updates `aws-lc-rs` from 1.18.0 to 1.18.1
- [Release notes](https://github.com/aws/aws-lc-rs/releases)
- [Commits](aws/aws-lc-rs@v1.18.0...v1.18.1)

Updates `encoding_rs` from 0.8.35 to 0.8.42
- [Commits](hsivonen/encoding_rs@v0.8.35...v0.8.42)

Updates `indexmap` from 2.14.0 to 2.14.2
- [Changelog](https://github.com/indexmap-rs/indexmap/blob/main/RELEASES.md)
- [Commits](indexmap-rs/indexmap@2.14.0...2.14.2)

Updates `libc` from 0.2.189 to 0.2.190
- [Release notes](https://github.com/rust-lang/libc/releases)
- [Changelog](https://github.com/rust-lang/libc/blob/0.2.190/CHANGELOG.md)
- [Commits](rust-lang/libc@0.2.189...0.2.190)

Updates `rand` from 0.10.2 to 0.10.3
- [Release notes](https://github.com/rust-random/rand/releases)
- [Changelog](https://github.com/rust-random/rand/blob/master/CHANGELOG.md)
- [Commits](rust-random/rand@0.10.2...0.10.3)

Updates `thiserror` from 2.0.20 to 2.0.21
- [Release notes](https://github.com/dtolnay/thiserror/releases)
- [Commits](dtolnay/thiserror@2.0.20...2.0.21)

Updates `tokio` from 1.53.1 to 1.53.2
- [Release notes](https://github.com/tokio-rs/tokio/releases)
- [Commits](tokio-rs/tokio@tokio-1.53.1...tokio-1.53.2)

---
updated-dependencies:
- dependency-name: aws-lc-rs
  dependency-version: 1.18.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: fuzz-minor-patch
- dependency-name: encoding_rs
  dependency-version: 0.8.42
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: fuzz-minor-patch
- dependency-name: indexmap
  dependency-version: 2.14.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: fuzz-minor-patch
- dependency-name: libc
  dependency-version: 0.2.190
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: fuzz-minor-patch
- dependency-name: rand
  dependency-version: 0.10.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: fuzz-minor-patch
- dependency-name: thiserror
  dependency-version: 2.0.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: fuzz-minor-patch
- dependency-name: tokio
  dependency-version: 1.53.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: fuzz-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants