Skip to content

build(deps): bump rustls-platform-verifier from 0.6.2 to 0.7.0 - #13

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/rustls-platform-verifier-0.7.0
Closed

build(deps): bump rustls-platform-verifier from 0.6.2 to 0.7.0#13
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/rustls-platform-verifier-0.7.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 12, 2026

Copy link
Copy Markdown

Bumps rustls-platform-verifier from 0.6.2 to 0.7.0.

Release notes

Sourced from rustls-platform-verifier's releases.

0.7.0

The reason this release is semver-incompatible is the upgrade from jni 0.21 to 0.22, which should only affect Android targets (and substantially reuse dependency duplication). Additionally there are several fixes for behavior on Windows.

What's Changed

Commits
  • 996b1c9 Bump version to 0.7.0
  • 89a83ff Upgrade jni to 0.22
  • ffe03d3 Bump MSRV to 1.85.0 (for jni)
  • 64b561e tests: update real-world test certificates
  • f609519 Take semver-compatible dependency updates
  • dafabbe Update Android setup instructions to include library usecase examples
  • 554923d remove nix flake, CI testing
  • bbc27c7 try with extra roots when root is untrusted
  • e50903a Update real world test certificates
  • 31bf3fa Take semver-compatible dependency updates
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [rustls-platform-verifier](https://github.com/rustls/rustls-platform-verifier) from 0.6.2 to 0.7.0.
- [Release notes](https://github.com/rustls/rustls-platform-verifier/releases)
- [Changelog](https://github.com/rustls/rustls-platform-verifier/blob/main/CHANGELOG)
- [Commits](rustls/rustls-platform-verifier@v/0.6.2...v/0.7.0)

---
updated-dependencies:
- dependency-name: rustls-platform-verifier
  dependency-version: 0.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Aug 12, 2026
@dependabot
dependabot Bot requested a review from aesslinger as a code owner August 12, 2026 19:54
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Aug 12, 2026
aesslinger added a commit that referenced this pull request Aug 13, 2026
* build(deps): bump actions/github-script from 7 to 9 (#10)

v8's only change was Node.js 24.x runner support. v9's breaking changes
(require('@actions/github') no longer works, getOctokit is now an injected
parameter) don't apply here — ci.yml's version-suggestion script only uses
the injected github.rest.*/github.graphql client, never require() or a
redeclared getOctokit.

* build(deps): bump async-trait from 0.1.91 to 0.1.92 (#12)

Patch release (resolves a clippy double_must_use lint in generated code);
async-trait isn't used directly in this crate's own code, only pulled
transitively via deadpool-postgres/tokio-postgres. Cargo.toml's existing
"0.1" range already covers this — only Cargo.lock needed updating.
Build/test/clippy all pass unchanged.

* build(deps): bump base64 from 0.22.1 to 0.23.1 (#11)

Major bump, but 0.23's changelog only adds new consts/SIMD-accelerated
engines and custom padding support -- Engine::encode/decode with
general_purpose::STANDARD (our only usage, in extract.rs/binding.rs/blob.rs
for BLOB wire format) is untouched. tokio-postgres's own transitive
postgres-protocol dependency stays pinned to 0.22.1 independently -- no
shared types cross that boundary, so both coexist without conflict.

Verified: 85/85 unit tests pass (including BLOB encode/decode coverage in
binding_tests.rs/blob_tests.rs), clippy/fmt clean, and the full live_db.rs
suite against a real PostgreSQL instance (7/7).

* build(deps): bump infer from 0.16.0 to 0.22.0 (#14)

Six minor versions, but our only usage (infer::get(data).map(|k|
k.mime_type()) in handlers/blob.rs's encode_blob_full) is infer's core
stable API -- the version range only adds new format detectors (DWG,
qcow2, par2, improved LZ4/zstd/audio/PDF/mkv detection) and internal
cleanup, no signature changes.

Verified: 85/85 unit tests pass (including blob_tests.rs's direct coverage
of encode_blob_full's mime-sniffing path), clippy/fmt clean.

* build(deps): bump rustls-platform-verifier from 0.6.2 to 0.7.0 (#13)

Explicitly documented upstream as semver-incompatible only due to the
jni 0.21->0.22 bump, which affects Android targets exclusively -- this
plugin only ships linux/darwin/windows binaries (release.yml), no Android.
Remaining changes are Windows-specific certificate-chain fixes. Our only
call site, BuilderVerifierExt::with_platform_verifier() in client.rs, is
unchanged.

Verified: 85/85 unit tests pass, clippy/fmt clean, compiles without any
call-site changes needed. Not verified: a live TLS handshake end-to-end --
the local test Postgres container has ssl=off, and reconfiguring it would
disrupt the shared dev environment. The with_platform_verifier() builder
call itself is exercised by every build; no behavior change is documented
for non-Android platforms.

* build(deps): bump tokio-postgres-rustls from 0.13.0 to 0.14.0 (#15)

Internal fixes only (correct x509 channel-binding parsing, deferred TLS
hostname validation, drops the ring/const-oid deps in favor of sha2). Our
only call site, MakeRustlsConnect::new(tls_config) in client.rs, is
unchanged.

Verified against a disposable, self-signed-cert Postgres container (not
the shared dev container) built specifically for this: verify-ca mode
connects successfully with a proper SAN cert pinned via ssl_ca, and
require mode correctly rejects an untrusted cert -- both behaviors
confirmed identical against a from-scratch build of the pre-dependabot
baseline commit, ruling out any regression from this bump specifically.
Also ran the full live_db.rs suite (7/7) against the primary non-TLS
pooled-connection path. 85/85 unit tests, clippy/fmt clean.
@dependabot @github

dependabot Bot commented on behalf of github Aug 13, 2026

Copy link
Copy Markdown
Author

Looks like rustls-platform-verifier is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Aug 13, 2026
@dependabot
dependabot Bot deleted the dependabot/cargo/rustls-platform-verifier-0.7.0 branch August 13, 2026 13:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants