Skip to content

chore(deps): bump quinn-proto from 0.11.14 to 0.11.16 - #280

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/quinn-proto-0.11.16
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/quinn-proto-0.11.16

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 27, 2026 •

Copy link
Copy Markdown
Contributor

Bumps quinn-proto from 0.11.14 to 0.11.16.

Release notes

Sourced from quinn-proto's releases.

quinn-proto-0.11.16

What's Changed

Commits
  • a96949f Take semver-compatible update for anyhow
  • 5429f60 udp: bump version to 0.5.15
  • 262a493 proto: bump version to 0.11.16
  • c19b63a Upgrade rustls-platform-verifier to 0.7
  • aff3652 Disable default features for fastbloom
  • 01b2eee Upgrade fastbloom to 0.17
  • 2c82013 Switch BBR RNG to PCG
  • 544dd9e Upgrade to rand 0.10.1
  • a7499b8 Bump versions for release
  • 7c1970f proto: yield error on too many gaps in assembler
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [quinn-proto](https://github.com/quinn-rs/quinn) from 0.11.14 to 0.11.16.
- [Release notes](https://github.com/quinn-rs/quinn/releases)
- [Commits](quinn-rs/quinn@quinn-proto-0.11.14...quinn-proto-0.11.16)

---
updated-dependencies:
- dependency-name: quinn-proto
  dependency-version: 0.11.16
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Jul 27, 2026
eraflo added a commit that referenced this pull request Jul 31, 2026
Applies five of the six open Dependabot PRs:

  #280 quinn-proto  0.11.14 -> 0.11.16  (transitive)
  #278 open         5.3.4   -> 5.3.5
  #275 tokio        1.52.2  -> 1.52.3
  #277 sysinfo      0.38.4  -> 0.39.6   (declared in infra + telemetry)
  #274 zip          2.4.2   -> 8.6.0    (hub)

sysinfo crosses a 0.x minor, which is semver-breaking by convention, but the
only API this workspace touches is `{Components, System}` in
`platform/sysinfo_impl.rs` and that is unchanged. It resolves to 0.39.6
rather than the 0.39.1 the PR asked for, since `^0.39.1` admits it.

zip jumps six majors, and compiling proved nothing on its own: the risk in
that upgrade is the default feature set, and an extractor that lost deflate
would still build while failing on every real archive. `cargo tree` confirms
deflate, bzip2, zstd, lzma and deflate64 are all present, and `extract_zip`
— previously untested — now has coverage that round-trips a deflated entry
and asserts the zip-slip guard still refuses to write outside the
destination.

Not applied: #276 egui-winit 0.34. The title undersells it. egui-winit 0.34
requires egui 0.34, and measuring the bump gives one hard error plus 41
deprecations: `eframe::App` now hands the app a `Ui` instead of a `Context`
(`update` -> `ui`), and `SidePanel`/`TopBottomPanel` are superseded by
`Panel::{left,right,top,bottom}`. That is a UI framework migration touching
the custom wgpu renderer and every panel, and it would need the same
surface-by-surface visual re-check the editor just went through. It wants its
own branch, not a slot in a patch batch on the eve of v0.7.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@dependabot @github

dependabot Bot commented on behalf of github Jul 31, 2026

Copy link
Copy Markdown
Contributor Author

Looks like quinn-proto is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Jul 31, 2026
@dependabot
dependabot Bot deleted the dependabot/cargo/quinn-proto-0.11.16 branch July 31, 2026 22:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants