Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): Bump url from 2.5.0 to 2.5.4 (idna from 0.5.0 to 1.0.3) #19730

Merged
merged 2 commits into from
Dec 10, 2024

Conversation

xiangjinwu
Copy link
Contributor

@xiangjinwu xiangjinwu commented Dec 10, 2024

I hereby agree to the terms of the RisingWave Labs, Inc. Contributor License Agreement.

What's changed and what's your intention?

Resolves #19727 (but NOT #19726 or #19725)

Generated by cargo update url.

idna is only used by url, and url is used by many crates. It only takes a patch version update of url so there is no API breakage to downstream crates.

But idna 1.0.3 by default would introduce a lot of new dependencies. In this PR we opt to disable IDNA support via cargo update -p idna_adapter --precise 1.0.0 according to the doc.

For context, IDNA is short for Internationalizing Domain Names in Applications, a mechanism to allow non-ASCII in domain names. We can consider supporting it when really needed.

Checklist

  • I have written necessary rustdoc comments
  • I have added necessary unit tests and integration tests
  • I have added test labels as necessary. See details.
  • I have added fuzzing tests or opened an issue to track them. (Optional, recommended for new SQL features Sqlsmith: Sql feature generation #7934).
  • My PR contains breaking changes. (If it deprecates some features, please create a tracking issue to remove them in the future).
  • All checks passed in ./risedev check (or alias, ./risedev c)
  • My PR changes performance-critical code. (Please run macro/micro-benchmarks and show the results.)
  • My PR contains critical fixes that are necessary to be merged into the latest release. (Please check out the details)

Documentation

  • My PR needs documentation updates. (Please use the Release note section below to summarize the impact on users)

Release note

If this PR includes changes that directly affect users or other significant modifications relevant to the community, kindly draft a release note to provide a concise summary of these changes. Please prioritize highlighting the impact these changes will have on users.

@xiangjinwu xiangjinwu requested a review from a team as a code owner December 10, 2024 05:50
@xiangjinwu xiangjinwu requested a review from stdrc December 10, 2024 05:50
```
cargo update -p idna_adapter --precise 1.0.0
```
@xiangjinwu xiangjinwu added this pull request to the merge queue Dec 10, 2024
Merged via the queue into main with commit f31e762 Dec 10, 2024
30 of 31 checks passed
@xiangjinwu xiangjinwu deleted the rustsec/cargo/url-2.5.4 branch December 10, 2024 07:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

RUSTSEC-2024-0421: idna 0.5.0 accepts Punycode labels that do not produce any non-ASCII when decoded
2 participants