deps(rust): bump http from 1.4.0 to 1.4.1#75
Conversation
Bumps [http](https://github.com/hyperium/http) from 1.4.0 to 1.4.1. - [Release notes](https://github.com/hyperium/http/releases) - [Changelog](https://github.com/hyperium/http/blob/master/CHANGELOG.md) - [Commits](hyperium/http@v1.4.0...v1.4.1) --- updated-dependencies: - dependency-name: http dependency-version: 1.4.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
…ixes (#81) * chore(deps): consolidate Dependabot PRs #70–#80 + frontend security fixes Consolidates 11 open Dependabot PRs into one branch as latest-compatible within each existing major, regenerates both lockfiles once, and patches 5 frontend security advisories surfaced by `pnpm audit`. Rust (cargo): openssl 0.10.79→0.10.80, reqwest 0.13.3→0.13.4, http 1.4.0→1.4.1, uuid 1.23.1→1.23.2, sysinfo 0.39.2→0.39.3 (#70,#72,#75,#77,#79) Docker: rust 1.95→1.96-bookworm (#71) TS (frontend): react-router(-dom) 7.15.1→7.17.0, typescript-eslint 8.59.3→8.61.1, @vitejs/plugin-react 6.0.1→6.0.2, eslint 10.2.1→10.5.0 (#73,#74,#76,#78,#80) Security (pnpm audit): vite→8.0.16 (GHSA-fx2h-pf6j-xcff HIGH, GHSA-v6wh-96g9-6wx3), js-yaml→4.2.0 (GHSA-h67p-54hq-rp68), brace-expansion→5.0.6 (GHSA-jxxr-4gwj-5jf2), @babel/core≥7.29.6 (GHSA-4x5r-pxfx-6jf8) via pnpm.overrides. Docs: bumped Rust toolchain references (1.95→1.96) in maintainer guide and deployment doc to track the Dockerfile bump. * chore(frontend): migrate to pnpm 11 Bumps the pinned package manager to pnpm 11.7.0 and updates every reference following the existing toolchain-bump pattern (manifest, Docker, CI, docs). - packageManager: pnpm@10.11.0 → pnpm@11.7.0 (CI's `corepack enable pnpm` reads this field, so the version propagates to all CI jobs automatically) - frontend/Dockerfile.frontend: corepack prepare pnpm@11.7.0; COPY the new pnpm-workspace.yaml into the dev stage so the frozen install sees overrides - Move `pnpm.overrides` out of package.json (pnpm 11 no longer reads that field) into frontend/pnpm-workspace.yaml, its new home - Disable pnpm 11's default 24h minimumReleaseAge supply-chain delay (minimumReleaseAge: 0) to preserve pnpm 10 install behavior and keep CI deterministic on same-day Dependabot bumps - README.md / maintainer-guide.md: pnpm 10+ → pnpm 11+ prerequisite Lockfile unchanged — relocating overrides does not alter resolution. Full frontend gate (frozen install, lint, tsc, prettier, test, build, audit) green under pnpm 11.7.0.
Bumps http from 1.4.0 to 1.4.1.
Release notes
Sourced from http's releases.
Changelog
Sourced from http's changelog.
Commits
a24c968v1.4.1bc3b044fix(header): use a set_len guard in IntoIter drop (#838)1b968dcfix(header): fix stacked borrows for IterMut/ValuesIterMut (#837)6e2dd42fix: clamp Extend size hint so HeaderMap reserve cannot overflow (#833)68e0abbdocs: fix typo in request builder docs (#831)29dd307docs(extensions): rephrase internal comment (#827)ae48fb5fix(uri): reject Path::from_shared/from_static if doesn't start with slash (#...1ad200erefactor(uri): consolidate PathAndQuery::from_shared and from_static (#825)d59d939refactor: Remove usage of float instruction (#823)ed680c4tests: update to rand 0.10 (#818)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)