Conversation
|
(rustbot has picked a reviewer for you, use r? to override) |
|
These commits modify the If this was intentional then you can ignore this comment. |
|
@bors r+ |
|
⌛ Testing commit 40b6095 with merge d56b56d9e14b748d05ab682c8d8d09250964743c... |
|
💔 Test failed - checks-actions |
|
@bors retry crates.io network blip |
|
☀️ Test successful - checks-actions |
|
Finished benchmarking commit (7f7e8fb): comparison URL. Overall result: no relevant changes - no action needed@rustbot label: -perf-regression Instruction countThis benchmark run did not return any relevant results for this metric. Max RSS (memory usage)ResultsThis is a less reliable metric that may be of interest but was not used to determine the overall result at the top of this comment.
CyclesResultsThis is a less reliable metric that may be of interest but was not used to determine the overall result at the top of this comment.
|
Update few deps to fix security vulns, future incompatibilities, duplicates.
jemalloc-sysv0.5.0+5.3.0 -> v0.5.3+5.3.0-patched: fixes future-incompatibilities by dropping fs_extra (https://github.com/rust-lang-ci/rust/actions/runs/4626595610/jobs/8183514150#step:26:19499, https://github.com/tikv/jemallocator/blob/tikv-jemalloc-sys-0.5.3/CHANGELOG.md)openssl-srcv111.22.0+1.1.1q -> v111.25.0+1.1.1t: fixes few vulns:https://www.openssl.org/news/vulnerabilities-1.1.1.html
https://www.cve.org/CVERecord?id=CVE-2022-4304
https://www.cve.org/CVERecord?id=CVE-2022-4450
https://www.cve.org/CVERecord?id=CVE-2023-0215
https://www.cve.org/CVERecord?id=CVE-2023-0286
There exist newer openssl version 1.1.1u with low severity vulns, but no crate update yet
opensslcrate with deps 0.10.38 ->0.10.49 fixes vulns (https://github.com/sfackler/rust-openssl/blob/openssl-v0.10.49/openssl/CHANGELOG.md)https://rustsec.org/advisories/RUSTSEC-2023-0022
https://rustsec.org/advisories/RUSTSEC-2023-0023
https://rustsec.org/advisories/RUSTSEC-2023-0024
update
env_loggerforrustbookandcargo_metadatafortidyto newer versions (still used byrustfmt,miri)