Skip to content

Conversation

@cr-tk
Copy link
Collaborator

@cr-tk cr-tk commented Oct 10, 2025

Summary & Motivation (Problem vs. Solution)

Update some of our Rust dependencies to versions used upstream.
The target versions are determined based on versions that a stable Rust release has picked in one of their Cargo.lock, as a proxy for reasonably stable and trusted versions. As such, this PR is designed to require only minimal efforts to review the dependencies.

Specifically, most of the new crate version picks are based on the Cargo.lock of cargo 0.92.0.

Extra-notable changes:

  • tokio 1.47.1 - the new long term support branch
  • libc = "=0.2.174"
  • socket 0.6.0

How I Tested These Changes

Local tests.

Pre merge check list

There is some general risk of regressions. This PR bumps multiple important crates past SemVer boundaries, such as tokio.

@cr-tk cr-tk added the enhancement New feature or request label Oct 10, 2025
@socket-security
Copy link

socket-security bot commented Oct 10, 2025

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedlibc@​0.2.1747910093100100
Addedrustls@​0.23.318210093100100
Addedserde_json@​1.0.1438210093100100
Addedsha2@​0.10.910010093100100
Updatedder@​0.7.9 ⏵ 0.7.1010010093100100

View full report

@cr-tk cr-tk force-pushed the christian/dep-bump branch from 4e3c743 to 8897350 Compare October 10, 2025 16:01
@cr-tk cr-tk force-pushed the christian/dep-bump branch from 8897350 to ad94a5d Compare November 27, 2025 19:37
@cr-tk cr-tk force-pushed the christian/dep-bump branch from ad94a5d to 48b0e86 Compare November 27, 2025 21:44
@cr-tk cr-tk marked this pull request as ready for review November 27, 2025 21:45
@cr-tk cr-tk requested a review from a team as a code owner November 27, 2025 21:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants