Skip to content

chore(deps): bump zstd-safe from 7.2.4 to 8.0.0 - #14

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/zstd-safe-8.0.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/zstd-safe-8.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 11, 2026 •

Copy link
Copy Markdown

Bumps zstd-safe from 7.2.4 to 8.0.0.

Release notes

Sourced from zstd-safe's releases.

zstd-safe v8.0.0

Breaking

  • CCtx::ref_cdict() and DCtx::ref_ddict() now borrow the dictionary for as long as the context. zstd stores the dictionary in the context by pointer and dereferences it on every later operation, so safe code could previously drop the dictionary and cause a use-after-free.
  • AdvancedSeekable no longer implements DerefMut (gyscos/zstd-rs#366). Handing out a &mut Seekable let safe code mem::swap() the context out and leave the swapped-out one holding a pointer to a reader this type frees on drop. decompress() and decompress_frame() are available directly on AdvancedSeekable instead, and Deref still covers the read-only queries.

Fixed

  • A context is no longer reused after an error left it in a state zstd considers undefined (gyscos/zstd-rs#315). zstd documents calling the streaming functions again on such a context as undefined behaviour; they now return the original error until something resets the context.
  • Cursor positions are no longer truncated when converted to usize, which on a 32-bit target could turn an out-of-range position into a small in-range one and read or write the wrong part of the buffer.
  • Seekable::init_advanced() no longer leaks the boxed reader when initialization fails.

Other

  • New cmake and vendored features, forwarded to zstd-sys.
  • ResetDirective derives Copy, Clone, Debug, PartialEq and Eq, like the crate's other parameter enums.
  • The Send and Sync impls carry safety comments explaining why they hold.
Commits
  • 648acb4 Avoid let...else in the seekable callbacks
  • e1152c1 Bump versions for the next release
  • 7caed6e Derive the usual traits on ResetDirective
  • bf7b1f7 Refuse to reuse a context an error may have left undefined
  • 1565618 Check the target, not the host, for MSVC
  • 8315a62 Return Ok(0) from Read::read for an empty buffer
  • a7cfa93 Keep the std gate on the Cursor WriteBuf impl
  • 9bf1692 Say why the Send and Sync impls hold
  • 681bcc3 Don't truncate Cursor positions on 32-bit targets
  • d5a1fdd Don't hand out a &mut Seekable from AdvancedSeekable
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 11, 2026
@dependabot
dependabot Bot deployed to public-ci September 11, 2026 14:38 Active
@dependabot dependabot Bot changed the title build(deps): bump zstd-safe from 7.2.4 to 8.0.0 chore(deps): bump zstd-safe from 7.2.4 to 8.0.0 Sep 12, 2026
@dependabot
dependabot Bot force-pushed the dependabot/cargo/zstd-safe-8.0.0 branch from 92114d1 to 728280e Compare September 12, 2026 04:07
@dependabot
dependabot Bot deployed to public-ci September 12, 2026 04:07 Active
Bumps [zstd-safe](https://github.com/gyscos/zstd-rs) from 7.2.4 to 8.0.0.
- [Release notes](https://github.com/gyscos/zstd-rs/releases)
- [Commits](gyscos/zstd-rs@zstd-safe-7.2.4...zstd-safe-8.0.0)

---
updated-dependencies:
- dependency-name: zstd-safe
  dependency-version: 8.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

This branch had an error being deployed

1 failed deployment
public-ci — 30f0255a Deployed Sep 12, 2026 by dependabot[bot] via Build and test #19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants