Skip to content

chore(deps): bump the rust-dependencies group across 1 directory with 2 updates - #6

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/rust-dependencies-df62e02cc3
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/rust-dependencies-df62e02cc3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the rust-dependencies group with 2 updates in the / directory: age and getrandom.

Updates age from 0.11.5 to 0.12.1

Release notes

Sourced from age's releases.

rage v0.12.1

rage

Fixed

  • Armored files that contain an empty final line are now correctly rejected.

age

Fixed

  • age::armor::ArmoredReader:
    • It now correctly implements the intended strict parsing profile (initially implemented in 0.9.0) by rejecting an empty final line.
    • The async API now correctly rejects some classes of truncated files that previously would cause it to hang.

rage v0.12.0

rage

Added

  • Support for the new native age recipient types:
    • age1tag1..
    • age1tagpq1..

Changed

  • MSRV is now 1.74.0.

age

Added

  • Support for new native age recipient types:
    • age::tag::Recipient (encryption-only)
    • age::tagpq::Recipient (encryption-only)
  • age::encrypted::EncryptedIdentity
  • age::plugin::ResolveError

Changed

  • MSRV is now 1.74.0.
  • Migrated to base64 0.22, i18n-embed 0.16.
  • age::IdentityFile::into_identities now returns Result<Vec<Box<dyn crate::Identity + Send + Sync>>, DecryptError> instead of Result<Vec<Box<dyn crate::Identity>>, DecryptError>. This re-enables cross-thread uses of IdentityFile, which were unintentionally disabled in 0.11.0.
  • age::plugin:
    • The following methods now returns Result<Self, ResolveError>:
      • Identity::default_for_plugin
      • RecipientPluginV1::new
      • IdentityPluginV1::new
  • All existing error enums nameable in the public API are now non-exhaustive:
    • age::{EncryptError, DecryptError}
    • age::IdentityFileConvertError
    • age::armor::ArmoredReadError
    • age::cli_common::ReadError
    • age::ssh::ParseRecipientKeyError
  • Removed the following error enum variants:
    • age::DecryptError::MissingPlugin
    • age::EncryptError::MissingPlugin
    • age::cli_common::ReadError::MissingPlugin

age-plugin 0.7.0

... (truncated)

Commits

Updates getrandom from 0.2.17 to 0.3.4

Changelog

Sourced from getrandom's changelog.

0.3.4 - 2025-10-14

Major change to wasm_js backend

Now, when the wasm_js feature is enabled, the wasm_js backend will be used by default. Users of wasm32-unknown-unknown targeting JavaScript environments like the Web and Node.js will no longer need to specify:

--cfg getrandom_backend="wasm_js"

in RUSTFLAGS for the crate to compile. They can now simple enable a feature.

Note: this should not affect non-JS users of the wasm32-unknown-unknown target. Using --cfg getrandom_backend will still override the source of randomness even if the wasm_js feature is enabled. This includes --cfg getrandom_backend=custom and --cfg getrandom_backend=unsupported.

For more information, see the discussions in #671, #675, and #730.

Added

  • unsupported opt-in backend #667
  • windows_legacy opt-in backend #724

Changed

  • Implement Memory Sanitizer unpoisoning more precisely #678
  • Relax MSRV for the linux_raw opt-in backend on ARM targets #688
  • Use getrandom syscall on all RISC-V Linux targets #699
  • Replaced wasi dependency with wasip2 #721
  • Enable wasm_js backend by default if the wasm_js feature is enabled #730

Removed

  • Unstable rustc-dep-of-std crate feature #694

#667: rust-random/getrandom#667 #671: rust-random/getrandom#671 #675: rust-random/getrandom#675 #678: rust-random/getrandom#678 #688: rust-random/getrandom#688 #694: rust-random/getrandom#694 #699: rust-random/getrandom#699 #721: rust-random/getrandom#721 #724: rust-random/getrandom#724 #730: rust-random/getrandom#730

[0.3.3] - 2025-05-09

Changed

  • Doc improvements #632 #634 #635
  • Add crate version to docs.rs links used in compile_error!s #639

... (truncated)

Commits

@dependabot @github

dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, rust. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from Onwcan as a code owner September 29, 2026 12:24
@Onwcan

Onwcan commented Sep 29, 2026

Copy link
Copy Markdown
Owner

@dependabot rebase

@dependabot dependabot Bot changed the title chore(deps): bump the rust-dependencies group with 2 updates chore(deps): bump the rust-dependencies group across 1 directory with 2 updates Sep 29, 2026
@dependabot
dependabot Bot force-pushed the dependabot/cargo/rust-dependencies-df62e02cc3 branch 2 times, most recently from 338c2aa to 1435708 Compare October 2, 2026 21:43
@Onwcan

Onwcan commented Oct 3, 2026

Copy link
Copy Markdown
Owner

@dependabot rebase

… 2 updates

Bumps the rust-dependencies group with 2 updates in the / directory: [age](https://github.com/str4d/rage) and [getrandom](https://github.com/rust-random/getrandom).


Updates `age` from 0.11.5 to 0.12.1
- [Release notes](https://github.com/str4d/rage/releases)
- [Commits](str4d/rage@age-0.11.5...v0.12.1)

Updates `getrandom` from 0.2.17 to 0.3.4
- [Changelog](https://github.com/rust-random/getrandom/blob/master/CHANGELOG.md)
- [Commits](rust-random/getrandom@v0.2.17...v0.3.4)

---
updated-dependencies:
- dependency-name: age
  dependency-version: 0.12.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-dependencies
- dependency-name: getrandom
  dependency-version: 0.3.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rust-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/cargo/rust-dependencies-df62e02cc3 branch from 1435708 to bda37ed Compare October 3, 2026 21:40
@Onwcan

Onwcan commented Oct 3, 2026

Copy link
Copy Markdown
Owner

Closing this PR by design under the current DireWolf dependency and TCB policy.

ADR-0046 explicitly pins age 0.11.5 and already records age 0.12.1 as measured and rejected due to its larger trusted closure and pre-release post-quantum KEM dependencies. Its revisit conditions have not fired: age 0.12.1 still carries the localisation stack and kem 0.3.0-pre.0 remains in the dependency closure.

The accompanying getrandom 0.3.4 update also does not replace 0.2.17 in the authority closure; rand_core 0.6.4 still requires 0.2.17. The PR additionally fails to compile because the authority still uses the 0.2 API (getrandom::getrandom), while 0.3 exposes getrandom::fill.

The rebased PR also fails the reviewed dependency-boundary and cargo-deny gates. Accepting these changes would therefore require a deliberate new TCB review and an ADR amendment rather than a routine Dependabot merge.

Current main remains green, including the hosted M5a sandbox-foundation acceptance gate.

No changes from this PR are being accepted. The age dependency should be reconsidered when one of ADR-0046's recorded revisit conditions is actually met.

@Onwcan Onwcan closed this Oct 3, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/cargo/rust-dependencies-df62e02cc3 branch October 3, 2026 22:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant