mozilla / cargo-vet

supply-chain security for Rust
Apache License 2.0
667 stars 46 forks source link

Bump tracing-subscriber from 0.3.11 to 0.3.17 #471

Open dependabot[bot] opened 1 year ago

dependabot[bot] commented 1 year ago

Bumps tracing-subscriber from 0.3.11 to 0.3.17.

Release notes

Sourced from tracing-subscriber's releases.

tracing-subscriber 0.3.17

This release of tracing-subscriber fixes a build error when using env-filter with recent versions of the regex crate. It also introduces several minor API improvements.

Fixed

  • env-filter: Add "unicode-case" and "unicode-perl" to the regex dependency, fixing a build error with recent versions of regex (#2566)
  • A number of minor documentation typos and other fixes (#2384, #2378, #2368, #2548)

Added

  • filter: Add fmt::Display impl for filter::Targets (#2343)
  • fmt: Made with_ansi(false) no longer require the "ansi" feature, so that ANSI formatting escapes can be disabled without requiring ANSI-specific dependencies (#2532)

Changed

  • fmt: Dim targets in the Compact formatter, matching the default formatter (#2409)

Thanks to @​keepsimple1, @​andrewhalle, @​LeoniePhiline, @​LukeMathWalker, @​howardjohn, @​daxpedda, and @​dbidwell94 for contributing to this release!

#2566: tokio-rs/tracing#2566 #2384: tokio-rs/tracing#2384 #2378: tokio-rs/tracing#2378 #2368: tokio-rs/tracing#2368 #2548: tokio-rs/tracing#2548 #2343: tokio-rs/tracing#2343 #2532: tokio-rs/tracing#2532 #2409: tokio-rs/tracing#2409

tracing-subscriber 0.3.16

This release of tracing-subscriber fixes a regression introduced in [v0.3.15][subscriber-0.3.15] where Option::None's Layer implementation would set the max level hint to OFF. In addition, it adds several new APIs, including the Filter::event_enabled method for filtering events based on fields values, and the ability to log internal errors that occur when writing a log line.

This release also replaces the dependency on the unmaintained [ansi-term] crate with the [nu-ansi-term] crate, resolving an informational security advisory ([RUSTSEC-2021-0139]) for [ansi-term]'s maintainance status. This increases the minimum supported Rust version (MSRV) to Rust 1.50+, although the crate should still compile for the previous MSRV of Rust 1.49+ when the ansi feature is not enabled.

... (truncated)

Commits
  • 0114ec1 subscriber: prepare to release v0.3.17 (#2571)
  • 53989b4 chore: fix rustfmt
  • 2235570 subscriber: add "unicode-case" and "unicode-perl" features to regex depende...
  • b9becf9 attributes: update UI tests with the latest stable version of Rust (#2568)
  • 3a65354 tracing, tracing-futures: instrument Future inside Drop (#2562)
  • 29d85b1 mock: move layer mock from tracing-subscriber tests (#2369)
  • 049ad73 subscriber: add ability to disable ANSI without crate feature (#2532)
  • a066c36 attributes: update to syn 2.0 (#2516)
  • 27eecd5 attributes: remove unused syn's feature visit (#2530)
  • cbafd75 Remove dep cfg-if from tracing (#2553)
  • Additional commits viewable in compare view


Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note Automatic rebases have been disabled on this pull request as it has been open for over 30 days.