kpcyrd / sn0int

Semi-automatic OSINT framework and package manager
https://sn0int.readthedocs.io/
GNU General Public License v3.0
1.92k stars 177 forks source link

Bump tungstenite from 0.13.0 to 0.20.1 #254

Open dependabot[bot] opened 7 months ago

dependabot[bot] commented 7 months ago

Bumps tungstenite from 0.13.0 to 0.20.1.

Changelog

Sourced from tungstenite's changelog.

0.20.1

0.20.0

  • Remove many implicit flushing behaviours. In general reading and writing messages will no longer flush until calling flush. An exception is automatic responses (e.g. pongs) which will continue to be written and flushed when reading and writing. This allows writing a batch of messages and flushing once, improving performance.
  • Add WebSocket::read, write, send, flush. Deprecate read_message, write_message, write_pending.
  • Add FrameSocket::read, write, send, flush. Remove read_frame, write_frame, write_pending. Note: Previous use of write_frame may be replaced with send.
  • Add WebSocketContext::read, write, flush. Remove read_message, write_message, write_pending. Note: Previous use of write_message may be replaced with write + flush.
  • Remove send_queue, replaced with using the frame write buffer to achieve similar results.
    • Add WebSocketConfig::max_write_buffer_size. Deprecate max_send_queue.
    • Add Error::WriteBufferFull. Remove Error::SendQueueFull. Note: WriteBufferFull returns the message that could not be written as a Message::Frame.
  • Add ability to buffer multiple writes before writing to the underlying stream, controlled by WebSocketConfig::write_buffer_size (default 128 KiB). Improves batch message write performance.
  • Panic on receiving invalid WebSocketConfig.

0.19.0

  • Update TLS dependencies.
  • Exchanging base64 for data-encoding.

0.18.0

  • Make handshake dependencies optional with a new handshake feature (now a default one!).
  • Return HTTP error responses (their HTTP body) upon non 101 status codes.

0.17.3

  • Respect the case-sentitivity of the "Origin" header to keep compatibility with the older servers that use case-sensitive comparison.

0.17.2

  • Fix panic when invalid manually constructed http::Request is passed to tungstenite.
  • Downgrade the MSRV to 1.56 due to some other crates that rely on us not being quite ready for 1.58.

0.17.1

  • Specify the minimum required Rust version.

0.17.0

  • Update of dependencies (primarily sha1).
  • Add support of the fragmented messages (allow the user to send the frames without composing the full message).
  • Overhaul of the client's request generation process. Now the users are able to pass the constructed http::Request "as is" to tungstenite-rs, letting the library to check the correctness of the request and specifying their own headers (including its own key if necessary). No changes for those ones who used the client in a normal way by connecting using a URL/URI (most common use-case).

... (truncated)

Commits
  • 219075e Merge pull request #379 from snapview/CVE-2023-43669
  • f0f1a06 Bump crate version
  • 2e50292 Add checking for header sanity
  • f916b33 Add AttackAttempt error variant
  • 53914c1 Include examples so that cargo publish works
  • 5323559 Bump version
  • 6e63b17 Update changelog
  • f2ed7aa Merge pull request #365 from snapview/dependabot/cargo/webpki-roots-0.24
  • 8d8f0da Merge pull request #362 from alexheretic/config-asserts
  • dac07ea Merge pull request #361 from alexheretic/docs++
  • Additional commits viewable in compare view


Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/kpcyrd/sn0int/network/alerts).

Note Automatic rebases have been disabled on this pull request as it has been open for over 30 days.