alexcrichton / cargo-vendor

Archived as subcommand is now part of Cargo itself
Apache License 2.0
261 stars 30 forks source link

Bump curl from 0.4.21 to 0.4.22 #318

Closed dependabot-preview[bot] closed 5 years ago

dependabot-preview[bot] commented 5 years ago

Bumps curl from 0.4.21 to 0.4.22.

Commits - [`ed811d6`](https://github.com/alexcrichton/curl-rust/commit/ed811d63d1934d3d167462d8b7e9f46152890928) Bump to 0.4.22 - [`c0ab585`](https://github.com/alexcrichton/curl-rust/commit/c0ab585e17fac48783317301b237e26817822511) Merge pull request [#270](https://github-redirect.dependabot.com/alexcrichton/curl-rust/issues/270) from mitsuhiko/feature/do-not-crash-in-buffer - [`ebb6d8e`](https://github.com/alexcrichton/curl-rust/commit/ebb6d8eeb59c3cfe935e0ef2ff9e409e6adbe689) Do not crash with a segfault if empty buffer is passed - [`8b7db11`](https://github.com/alexcrichton/curl-rust/commit/8b7db11da8ffb3f270cd94e4b8dbee3ea9506fd3) Merge pull request [#268](https://github-redirect.dependabot.com/alexcrichton/curl-rust/issues/268) from gwenn/patch-1 - [`8c7069e`](https://github.com/alexcrichton/curl-rust/commit/8c7069e2746332d328508817d5339cfe1d5caf98) Fix typo - See full diff in [compare view](https://github.com/alexcrichton/curl-rust/compare/0.4.21...0.4.22)


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

If all status checks pass Dependabot will automatically merge this pull request.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot ignore this [patch|minor|major] version` will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language - `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com): - Update frequency (including time of day and day of week) - Automerge options (never/patch/minor, and dev/runtime dependencies) - Pull request limits (per update run and/or open at any time) - Out-of-range updates (receive only lockfile updates, if desired) - Security updates (receive only security updates, if desired) Finally, you can contact us by mentioning @dependabot.

Dependabot has been acquired by GitHub  🎉