-
Notifications
You must be signed in to change notification settings - Fork 755
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore: bump thiserror to v2 #3172
base: master
Are you sure you want to change the base?
chore: bump thiserror to v2 #3172
Conversation
Bumps all locked dependencies, fixing the following issues: * Building for s390x musl * Building for loongarch64 gnu/musl * [RUSTSEC-2021-0139](https://rustsec.org/advisories/RUSTSEC-2021-0139) on ansi_term (unmaintained) * [RUSTSEC-2024-0320](https://rustsec.org/advisories/RUSTSEC-2024-0320) on yaml-rust (unmaintained) * [RUSTSEC-2024-0404](https://rustsec.org/advisories/RUSTSEC-2024-0404) on anstream (unsound) * Removes some duplicate dependency versions and some unused dependencies - on this I've also opened tokio-rs/tracing#3172 but it'll probably take a long time to get released Remains: * [RUSTSEC-2024-0375](https://rustsec.org/advisories/RUSTSEC-2024-0375) on atty (unmaintained)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks!
Not sure if we also need to bump the examples
thiserror dependency.
I guess it is OK to bump it too in this PR.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Please also update it in the examples crate: examples/Cargo.toml
. Quick build works fine but none of the breaking changes (https://github.com/dtolnay/thiserror/releases/tag/2.0.0) should concern us anyways.
74c6558
to
aab7370
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Motivation
The ecosystem has upgraded to thiserror v2, so this crate was causing duplicate dependency versions.
Solution
Bump thiserror to v2 - https://github.com/dtolnay/thiserror/releases/tag/2.0.0