servo / rust-url

URL parser for Rust
https://docs.rs/url/
Apache License 2.0
1.31k stars 325 forks source link

Update unicode-width requirement from =0.1.12 to =0.1.13 #948

Closed dependabot[bot] closed 1 week ago

dependabot[bot] commented 3 months ago

Updates the requirements on unicode-width to permit the latest version.

Commits
  • 612877a Bump to 0.1.13
  • e370cb8 Merge pull request #54 from krasimirgg/rustc
  • 3b82122 adapt for rustc-dep-of-std build
  • d00d357 Merge pull request #52 from Jules-Bertholet/canonically-equivalent-eaw
  • dc86c74 Assign the same CJK width to canonically equivalent strings
  • a2db56b Refactor unicode.py
  • da626ef Merge pull request #49 from Jules-Bertholet/syriac-abbreviation-mark
  • 47bac32 Merge pull request #50 from Jules-Bertholet/remove-old-ci
  • 3742586 Mark more Prepended_Concatenation_Marks as non-advancing
  • 3b56f6d Mark U+A8FA DEVANAGARI CARET as zero-width
  • Additional commits viewable in compare view


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
joshka commented 1 week ago

Heads up unicode-width 0.1.13 changed how certain character widths are calculated to be more inline with the unicode spec. E.g. control characters like newline that were previously 0 width are now width 1.

It doesn't appear that unicode-width is called directly by any code in this repo, but perhaps it's called by something downstream where this causes a meaningful change.

@Manishearth I don't intend this to re-litigate the issue raised in https://github.com/unicode-rs/unicode-width/issues/55 or https://github.com/unicode-rs/unicode-width/issues/66. I'm merely raising a concern that this update may require additional testing beyond the usual amount that would seem obvious from a patch release. I am unaware of any particular problems this causes, and suspect there's a high chance that it would be none.

Manishearth commented 1 week ago

No, the version is just pinned here because unicode-width (depended upon transitively by tests) has an MSRV greater than the MSRV tested in this CI (as we can see with the failing CI task).

This is a dev dependency. The worst that can happen is tests will break, and we would notice that in CI. So no, this update would not require additional testing, @joshka even if you don't intend to relitigate the issue it sure feels like you're doing so by bringing it up on a place where it's very clearly not needed to be mentioned.

dependabot[bot] commented 1 week ago

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.