wbbaddons / Tims-PackageServer

Lightweight Package Server for WoltLab Community Framework
https://tims.bastelstu.be
GNU Affero General Public License v3.0
9 stars 3 forks source link

Bump roxmltree from 0.18.1 to 0.19.0 #264

Closed dependabot[bot] closed 9 months ago

dependabot[bot] commented 9 months ago

Bumps roxmltree from 0.18.1 to 0.19.0.

Changelog

Sourced from roxmltree's changelog.

[0.19.0] - 2023-11-18

Changed

  • xmlparser is no longer a dependency and its fork is used internally.
  • ~5% faster parsing.
  • Fallback to Rc when Arc isn't available.
  • Bump MSRV to 1.60
  • Bump edition to 2021
  • Error variants have changed quite a lot.
  • XML declaration validation was simplified. We no longer check for attributes content. Meaning that version, encoding and standalone can contain any value now. But we still do check attribute names and order. And while we did validated those attributes before, they weren't really affecting the parser in any way. Therefore the parsing behavior is mostly unchanged.

Fixed

  • ParsingOptions::allow_dtd = false would not trigger an error when an empty DTD was present.

Removed

  • The xmlparser dependency.
Commits
  • 9f9df0a Version bump.
  • f37f358 Bump edition to 2021.
  • 28ad9e5 Simplify XML declaration validation.
  • 7e739cb A nicer unexpected XML declaration error.
  • 35016da Fix text parsing with a non-ASCII encoding.
  • 8d7c362 Rename lifetimes.
  • ce1d004 Fix build without default features.
  • 97737a1 Merge xmlparser into this crate.
  • 30b8c81 Simplify parser a bit.
  • 160e514 Bump MSRV to 1.60
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)