orhun / rustypaste

A minimal file upload/pastebin service.
https://blog.orhun.dev/blazingly-fast-file-sharing
MIT License
771 stars 48 forks source link

chore(deps): bump actix-web from 4.5.1 to 4.6.0 #289

Closed dependabot[bot] closed 3 months ago

dependabot[bot] commented 4 months ago

Bumps actix-web from 4.5.1 to 4.6.0.

Release notes

Sourced from actix-web's releases.

actix-web: v4.6.0

Added

  • Add unicode crate feature (on-by-default) to switch between regex and regex-lite as a trade-off between full unicode support and binary size.
  • Add rustls-0_23 crate feature.
  • Add HttpServer::{bind_rustls_0_23, listen_rustls_0_23}() builder methods.
  • Add HttpServer::tls_handshake_timeout() builder method for rustls-0_22 and rustls-0_23.

Changed

  • Update brotli dependency to 6.
  • Minimum supported Rust version (MSRV) is now 1.72.

Fixed

  • Avoid type confusion with rustls in some circumstances.
Commits


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
codecov-commenter commented 3 months ago

Codecov Report

All modified and coverable lines are covered by tests :white_check_mark:

Project coverage is 83.20%. Comparing base (5b363a1) to head (9b68780).

:exclamation: Your organization needs to install the Codecov GitHub app to enable full functionality.

Additional details and impacted files ```diff @@ Coverage Diff @@ ## master #289 +/- ## ======================================= Coverage 83.20% 83.20% ======================================= Files 11 11 Lines 1209 1209 ======================================= Hits 1006 1006 Misses 203 203 ```

:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Have feedback on the report? Share it here.

dependabot[bot] commented 3 months ago

A newer version of actix-web exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged.

tessus commented 3 months ago

@orhun instead of merging master you should use @dependabot rebase because apparently merging rsults in not updating to the latest version. Btw, there are a bunch or dependency PRs to merge in this repo and the cli repo....

tessus commented 3 months ago

or maybe @dependabot recreate has to be used. I'm not so sure about these dependabot commands. Maybe the only way that a newer version is picked up is to close it.

tessus commented 3 months ago

Additionally it seems that the automarge still doesn't work. It says Review required

tessus commented 3 months ago

@orhun ^^^

Too bad that gh's access is not granular enough to allow people to merge only specific PRs (e.g. dependabot).

orhun commented 3 months ago

@tessus do you want to be a collaborator on this repo for handling stuff like this and overall maintenance? I'd appreciate some help and you've been contributing nice stuff for some time now.

tessus commented 3 months ago

@orhun Yes, I'd like that. If possible also for the cli repo. I promise I won't merge anything but dependabot PRs.

orhun commented 3 months ago

you got it!

tessus commented 3 months ago

thanks.

tessus commented 3 months ago

@dependabot recreate

dependabot[bot] commented 3 months ago

Superseded by #305.