Skip to content

build(deps): bump the cargo group across 1 directory with 5 updates - #30

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/cargo/cargo-ad0989619e
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/cargo/cargo-ad0989619e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the cargo group with 5 updates in the / directory:

Package From To
thiserror 2.0.20 2.0.21
trash 5.2.8 5.2.9
tauri 2.11.5 2.12.0
tauri-plugin-global-shortcut 2.3.2 2.4.0
tauri-build 2.6.3 2.7.1

Updates thiserror from 2.0.20 to 2.0.21

Release notes

Sourced from thiserror's releases.

2.0.21

  • Fix parsing of generic unit variants in display expressions (#459)
Commits
  • b1827ee Release 2.0.21
  • 58037b5 Merge pull request #459 from dtolnay/turbofish
  • f82a0cf Keep track of nested turbofish depth
  • 72ea492 Raise required compiler to Rust 1.77
  • 72eea0d Resolve io_other_error clippy lint in tests
  • 07f09a2 Raise required compiler to Rust 1.74
  • 2715388 Update ui test suite to nightly-2026-09-22
  • 5a306c7 Update ui test suite to nightly-2026-09-05
  • ef9383b Update ui test suite to nightly-2026-08-22
  • 8336b84 Update ui tests for version 2.0.20
  • See full diff in compare view

Updates trash from 5.2.8 to 5.2.9

Release notes

Sourced from trash's releases.

v5.2.9

This is a bug-fix release, where unfortunately I forgot to make the needed edits to the commit message for all of them to automatically show up here. Check the "Commit Details" section instead for everything that went into it.

Bug Fixes

  • fall back to the home trash when per-volume trash cannot be created The spec (v1.0, section "Trash directories") says an implementation "MUST either trash the file into the user's home trash or refuse to trash it" when both $topdir/.Trash/$uid and $topdir/.Trash-$uid are unavailable. Until now the crate took the "refuse" branch, returning a PermissionDenied error whenever the mount-point root was not writable by the calling user - the common case on every partition whose root is owned by root.

    Catch PermissionDenied from execute_on_mounted_trash_folders and fall back to move_to_trash with the home trash, which already handles cross-device copies via copy+delete.

Commit Statistics

  • 8 commits contributed to the release.
  • 5 days passed between releases.
  • 1 commit was understood as conventional.
  • 0 issues like '(#ID)' were seen in commit messages

Commit Details

  • Uncategorized
    • Prepare changelog prior to release (deaf4de)
    • Merge pull request #151 from jaroslavpachola/home-trash-fallback (f99e82e)
    • Review (18cbe14)
    • Fall back to the home trash when per-volume trash cannot be created (50ede33)
    • Merge pull request #150 from ggand0/fix-windows-unc-parsing-name (29ad086)
    • Review (e57c153)
    • Keep the root backslash when rebuilding shell parsing names (e99afbd)
    • Rebuild verbatim paths before handing them to the shell on Windows (ba1d72f)
Changelog

Sourced from trash's changelog.

5.2.9 (2026-09-13)

This is a bug-fix release, where unfortunately I forgot to make the needed edits to the commit message for all of them to automatically show up here. Check the "Commit Details" section instead for everything that went into it.

Bug Fixes

  • fall back to the home trash when per-volume trash cannot be created The spec (v1.0, section "Trash directories") says an implementation "MUST either trash the file into the user's home trash or refuse to trash it" when both $topdir/.Trash/$uid and $topdir/.Trash-$uid are unavailable. Until now the crate took the "refuse" branch, returning a PermissionDenied error whenever the mount-point root was not writable by the calling user - the common case on every partition whose root is owned by root.

    Catch PermissionDenied from execute_on_mounted_trash_folders and fall back to move_to_trash with the home trash, which already handles cross-device copies via copy+delete.

Commit Statistics

  • 8 commits contributed to the release.
  • 5 days passed between releases.
  • 1 commit was understood as conventional.
  • 0 issues like '(#ID)' were seen in commit messages

Commit Details

  • Uncategorized
    • Prepare changelog prior to release (deaf4de)
    • Merge pull request #151 from jaroslavpachola/home-trash-fallback (f99e82e)
    • Review (18cbe14)
    • Fall back to the home trash when per-volume trash cannot be created (50ede33)
    • Merge pull request #150 from ggand0/fix-windows-unc-parsing-name (29ad086)
    • Review (e57c153)
    • Keep the root backslash when rebuilding shell parsing names (e99afbd)
    • Rebuild verbatim paths before handing them to the shell on Windows (ba1d72f)
Commits
  • 54e0a2d Release trash v5.2.9
  • deaf4de prepare changelog prior to release
  • f99e82e Merge pull request #151 from jaroslavpachola/home-trash-fallback
  • 18cbe14 review
  • 50ede33 fix: fall back to the home trash when per-volume trash cannot be created
  • 29ad086 Merge pull request #150 from ggand0/fix-windows-unc-parsing-name
  • e57c153 review
  • e99afbd Keep the root backslash when rebuilding shell parsing names
  • ba1d72f Rebuild verbatim paths before handing them to the shell on Windows
  • See full diff in compare view

Updates tauri from 2.11.5 to 2.12.0

Release notes

Sourced from tauri's releases.

tauri-cli v2.12.0

Fetching advisory database from `https://github.com/RustSec/advisory-db.git`
      Loaded 1271 security advisories (from /home/runner/.cargo/advisory-db)
    Updating crates.io index
    Scanning Cargo.lock for vulnerabilities (1091 crate dependencies)
Crate:     fxhash
Version:   0.2.1
Warning:   unmaintained
Title:     fxhash - no longer maintained
Date:      2025-09-05
ID:        RUSTSEC-2025-0057
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0057

Crate: paste
Version: 1.0.15
Warning: unmaintained
Title: paste - no longer maintained
Date: 2024-10-07
ID: RUSTSEC-2024-0436
URL: https://rustsec.org/advisories/RUSTSEC-2024-0436

Crate: rustls-pemfile
Version: 2.2.0
Warning: unmaintained
Title: rustls-pemfile is unmaintained
Date: 2025-11-28
ID: RUSTSEC-2025-0134
URL: https://rustsec.org/advisories/RUSTSEC-2025-0134

Crate: rustybuzz
Version: 0.20.1
Warning: unmaintained
Title: rustybuzz is unmaintained
Date: 2026-07-11
ID: RUSTSEC-2026-0206
URL: https://rustsec.org/advisories/RUSTSEC-2026-0206

Crate: ttf-parser
Version: 0.25.1
Warning: unmaintained
Title: ttf-parser is unmaintained
Date: 2026-06-28
ID: RUSTSEC-2026-0192
URL: https://rustsec.org/advisories/RUSTSEC-2026-0192

warning: 5 allowed warnings found
</tr></table>

... (truncated)

Commits
  • 447fa9f fix(core): tauri-utils publish
  • 4f46cfc fix(ci): pnpm publish should use "debug" loglevel instead of "silly"
  • 726822c apply version updates (#15634)
  • 9f8922a docs(core): extend app_directories_override documentation (#16139)
  • dc894d4 chore: remove change file for unreleased fix (#16140)
  • 152529e Revert "feat(core): add android activityEmbedding config (#15255)" (#16138)
  • 7456ddd Revert "fix(core): proper unique identifier for menu items on channels store"...
  • 15468de fix(bundler): recognize deb and rpm as self-contained updater targets (#16064)
  • 8e70283 fix(bundler): update linuxdeploy and linuxdeploy-plugin-gtk (#16062)
  • 1b91b7b fix(cli): list all locked crate versions in tauri info (#16102)
  • Additional commits viewable in compare view

Updates tauri-plugin-global-shortcut from 2.3.2 to 2.4.0

Release notes

Sourced from tauri-plugin-global-shortcut's releases.

stronghold-js v2.4.0

[2.4.0]

  • ae3c808e (#3602) The plugin's global API script (used with app.withGlobalTauri) now resolves the core API from window.__TAURI__ instead of bundling its own copy of @tauri-apps/api. Values created with the core API are now accepted by plugin APIs in global mode (e.g. an Image from window.__TAURI__.image passed to clipboardManager.writeImage, which previously failed the instanceof check against the plugin's private copy), and the script is considerably smaller.
  • 9b29b601 Update MSRV to 1.90 to match tauri.
  • a87a3c7d Update documentation.
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-stronghold@2.4.0
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 4.7kB README.md
npm notice 19.4kB dist-js/index.cjs
npm notice 21.1kB dist-js/index.d.ts
npm notice 19.2kB dist-js/index.js
npm notice 750B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-stronghold
npm notice version: 2.4.0
npm notice filename: tauri-apps-plugin-stronghold-2.4.0.tgz
npm notice package size: 8.7 kB
npm notice unpacked size: 66.0 kB
npm notice shasum: 47b370840be057acd7d8f76046a9978a622cfcbe
npm notice integrity: sha512-5FIKueS+4xs66[...]j7Mzwt0NX4r1A==
npm notice total files: 6
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=2969525576
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-stronghold@2.4.0

stronghold v2.4.0

[2.4.0]

  • ae3c808e (#3602) The plugin's global API script (used with app.withGlobalTauri) now resolves the core API from window.__TAURI__ instead of bundling its own copy of @tauri-apps/api. Values created with the core API are now accepted by plugin APIs in global mode (e.g. an Image from window.__TAURI__.image passed to clipboardManager.writeImage, which previously failed the instanceof check against the plugin's private copy), and the script is considerably smaller.
  • 9b29b601 Update MSRV to 1.90 to match tauri.
  • a87a3c7d Update documentation.

... (truncated)

Commits

Updates tauri-build from 2.6.3 to 2.7.1

Release notes

Sourced from tauri-build's releases.

tauri-build v2.7.1

Fetching advisory database from `https://github.com/RustSec/advisory-db.git`
      Loaded 1277 security advisories (from /home/runner/.cargo/advisory-db)
    Updating crates.io index
    Scanning Cargo.lock for vulnerabilities (1091 crate dependencies)
Crate:     fxhash
Version:   0.2.1
Warning:   unmaintained
Title:     fxhash - no longer maintained
Date:      2025-09-05
ID:        RUSTSEC-2025-0057
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0057

Crate: paste
Version: 1.0.15
Warning: unmaintained
Title: paste - no longer maintained
Date: 2024-10-07
ID: RUSTSEC-2024-0436
URL: https://rustsec.org/advisories/RUSTSEC-2024-0436

Crate: rustls-pemfile
Version: 2.2.0
Warning: unmaintained
Title: rustls-pemfile is unmaintained
Date: 2025-11-28
ID: RUSTSEC-2025-0134
URL: https://rustsec.org/advisories/RUSTSEC-2025-0134

Crate: rustybuzz
Version: 0.20.1
Warning: unmaintained
Title: rustybuzz is unmaintained
Date: 2026-07-11
ID: RUSTSEC-2026-0206
URL: https://rustsec.org/advisories/RUSTSEC-2026-0206

Crate: ttf-parser
Version: 0.25.1
Warning: unmaintained
Title: ttf-parser is unmaintained
Date: 2026-06-28
ID: RUSTSEC-2026-0192
URL: https://rustsec.org/advisories/RUSTSEC-2026-0192

warning: 5 allowed warnings found
</tr></table>

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the cargo group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [thiserror](https://github.com/dtolnay/thiserror) | `2.0.20` | `2.0.21` |
| [trash](https://github.com/ArturKovacs/trash) | `5.2.8` | `5.2.9` |
| [tauri](https://github.com/tauri-apps/tauri) | `2.11.5` | `2.12.0` |
| [tauri-plugin-global-shortcut](https://github.com/tauri-apps/plugins-workspace) | `2.3.2` | `2.4.0` |
| [tauri-build](https://github.com/tauri-apps/tauri) | `2.6.3` | `2.7.1` |



Updates `thiserror` from 2.0.20 to 2.0.21
- [Release notes](https://github.com/dtolnay/thiserror/releases)
- [Commits](dtolnay/thiserror@2.0.20...2.0.21)

Updates `trash` from 5.2.8 to 5.2.9
- [Release notes](https://github.com/ArturKovacs/trash/releases)
- [Changelog](https://github.com/Byron/trash-rs/blob/master/CHANGELOG.md)
- [Commits](Byron/trash-rs@v5.2.8...v5.2.9)

Updates `tauri` from 2.11.5 to 2.12.0
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](tauri-apps/tauri@tauri-v2.11.5...tauri-v2.12.0)

Updates `tauri-plugin-global-shortcut` from 2.3.2 to 2.4.0
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@os-v2.3.2...os-v2.4.0)

Updates `tauri-build` from 2.6.3 to 2.7.1
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](tauri-apps/tauri@tauri-build-v2.6.3...tauri-build-v2.7.1)

---
updated-dependencies:
- dependency-name: thiserror
  dependency-version: 2.0.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: trash
  dependency-version: 5.2.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: tauri
  dependency-version: 2.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo
- dependency-name: tauri-plugin-global-shortcut
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo
- dependency-name: tauri-build
  dependency-version: 2.7.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants