Repository navigation
Bump base64 from 0.22.1 to 0.23.1 in /rust - #1449
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [base64](https://github.com/marshallpierce/rust-base64) from 0.22.1 to 0.23.1. - [Changelog](https://github.com/marshallpierce/rust-base64/blob/master/RELEASE-NOTES.md) - [Commits](marshallpierce/rust-base64@v0.22.1...v0.23.1) --- updated-dependencies: - dependency-name: base64 dependency-version: 0.23.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
@bgentry I'm going to start ignoring these Dependabot PRs — there are just too many. We got 6 just in the last half hour. Feel free to keep merging them, but I kinda wonder if we should maybe start experimenting with a different tool instead. e.g. Imagine like an agent-based workflow that goes through a maximum of once a week and just upgrades everything across all subdirectories and includes it all together. I've long ago stopped reading the Dependabot changelog / commit summary so it really wouldn't matter if everything was just wrapped up in a single PR with less information. |
bgentry
left a comment
There was a problem hiding this comment.
🤖 Codex review: Security review is clear; this PR is superseded and should remain unmerged.
Upgrade
base64:0.22.1→0.23.1- Reviewed head:
97d2ba378b02d9830cca87a779e932a72abb61a1
Security review
- Independently hashed both published crates and matched crates.io index and Cargo.lock SHA256 values. Published source files match canonical upstream release commits/tags byte-for-byte; registry source, license, and upstream identity remain consistent. Release tags are unsigned; the owners API was unavailable (403).
- The graph only adds
base64 0.23.1; sqlx retains0.22.1. No new transitive dependencies or build hooks. Reviewed padding, scalar/streaming changes and the new default-on AVX2/NEON unsafe implementation. River's cursor code still explicitly uses scalarGeneralPurposeengines. - No applicable RustSec advisory found; the historical base64 advisory is fixed since
0.5.2. This is not classified as a security update.
Compatibility verification
- Master
81c96bfe8167ab90a5009dad6098195b9857cb62already includes this exact manifest version, checksums, and dependency edges through #1459. There is no remaining dependency upgrade to validate or merge from this PR. - No executable validation of this stale PR was performed. Its older failing PostgreSQL check is not treated as a passing gate.
Residual risk
- Static review does not prove the new optional SIMD implementation memory-safe. Its unsafe kernels are not selected by River's current cursor calls. Unsigned tags, the unavailable owners endpoint, and ordinary unknown-vulnerability risk remain disclosed limits.
|
@dependabot rebase |
|
Looks like base64 is up-to-date now, so this is no longer needed. |
Bumps base64 from 0.22.1 to 0.23.1.
Changelog
Sourced from base64's changelog.
Commits
069bf70v0.23.16ab1fb0Merge pull request #310 from musicinmybrain/test-on-non-simd-arches7cffce6Fix testing on architectures without unsafe SIMD supporte34f9a0Merge pull request #308 from atouchet/come9240c9Remove outdated comment9e9220av0.23.0870326eMerge pull request #306 from marshallpierce/mp/trailing-bits-docsfbec5f1Document no trailing trailing bits0a23549Merge pull request #305 from marshallpierce/mp/edition-2021f10b7e2Update deps & editionDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)