Skip to content

Bump sha2 from 0.10.9 to 0.11.0#425

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/cargo/sha2-0.11.0
Open

Bump sha2 from 0.10.9 to 0.11.0#425
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/cargo/sha2-0.11.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 7, 2026

Bumps sha2 from 0.10.9 to 0.11.0.

Commits


Note

Medium Risk
Upgrades a core hashing dependency (sha2), which could affect build compatibility or hashing behavior if upstream changes introduced subtle differences, though no application logic changes are included.

Overview
Bumps the sha2 dependency from 0.10.9 to 0.11.0 in Cargo.toml.

Updates Cargo.lock to resolve the new sha2/digest dependency stack (adding newer digest, block-buffer, crypto-common, cpufeatures, const-oid, typenum, and hybrid-array versions) and pins dependent crates to the appropriate sha2 versions.

Reviewed by Cursor Bugbot for commit 1c0ae71. Bugbot is set up for automated code reviews on this repo. Configure here.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added Changed Required label for PR that categorizes merge commit message as "Changed" for changelog dependencies Pull requests that update a dependency file rust Pull requests that update Rust code labels Apr 7, 2026
@socket-security
Copy link
Copy Markdown

socket-security Bot commented Apr 7, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedcargo/​sha2@​0.11.010010093100100

View full report

@socket-security
Copy link
Copy Markdown

socket-security Bot commented Apr 7, 2026

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 16, 2026

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

1 similar comment
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 16, 2026

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

@dependabot dependabot Bot force-pushed the dependabot/cargo/sha2-0.11.0 branch from 27169f2 to 0d44690 Compare April 21, 2026 02:59
Bumps [sha2](https://github.com/RustCrypto/hashes) from 0.10.9 to 0.11.0.
- [Commits](RustCrypto/hashes@sha2-v0.10.9...sha2-v0.11.0)

---
updated-dependencies:
- dependency-name: sha2
  dependency-version: 0.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/cargo/sha2-0.11.0 branch from 0d44690 to 1c0ae71 Compare April 23, 2026 05:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Changed Required label for PR that categorizes merge commit message as "Changed" for changelog dependencies Pull requests that update a dependency file rust Pull requests that update Rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants