Skip to content

chore(deps): Bump the windows-rust group across 2 directories with 3 updates - #1384

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/apps/windows/crates/tono-plugin-core/windows-rust-237dd88c96
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/apps/windows/crates/tono-plugin-core/windows-rust-237dd88c96

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps the windows-rust group with 2 updates in the /apps/windows/crates/tono-plugin-core directory: tauri and tauri-plugin.
Bumps the windows-rust group with 1 update in the /apps/windows/service directory: minisign-verify.

Updates tauri from 2.11.6 to 2.12.1

Release notes

Sourced from tauri's releases.

tauri-cli v2.12.1

Fetching advisory database from `https://github.com/RustSec/advisory-db.git`
      Loaded 1277 security advisories (from /home/runner/.cargo/advisory-db)
    Updating crates.io index
    Scanning Cargo.lock for vulnerabilities (1091 crate dependencies)
Crate:     fxhash
Version:   0.2.1
Warning:   unmaintained
Title:     fxhash - no longer maintained
Date:      2025-09-05
ID:        RUSTSEC-2025-0057
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0057

Crate: paste
Version: 1.0.15
Warning: unmaintained
Title: paste - no longer maintained
Date: 2024-10-07
ID: RUSTSEC-2024-0436
URL: https://rustsec.org/advisories/RUSTSEC-2024-0436

Crate: rustls-pemfile
Version: 2.2.0
Warning: unmaintained
Title: rustls-pemfile is unmaintained
Date: 2025-11-28
ID: RUSTSEC-2025-0134
URL: https://rustsec.org/advisories/RUSTSEC-2025-0134

Crate: rustybuzz
Version: 0.20.1
Warning: unmaintained
Title: rustybuzz is unmaintained
Date: 2026-07-11
ID: RUSTSEC-2026-0206
URL: https://rustsec.org/advisories/RUSTSEC-2026-0206

Crate: ttf-parser
Version: 0.25.1
Warning: unmaintained
Title: ttf-parser is unmaintained
Date: 2026-06-28
ID: RUSTSEC-2026-0192
URL: https://rustsec.org/advisories/RUSTSEC-2026-0192

warning: 5 allowed warnings found
</tr></table>

... (truncated)

Commits

Updates tauri-plugin from 2.6.3 to 2.7.1

Release notes

Sourced from tauri-plugin's releases.

tauri-plugin v2.7.1

Fetching advisory database from `https://github.com/RustSec/advisory-db.git`
      Loaded 1277 security advisories (from /home/runner/.cargo/advisory-db)
    Updating crates.io index
    Scanning Cargo.lock for vulnerabilities (1091 crate dependencies)
Crate:     fxhash
Version:   0.2.1
Warning:   unmaintained
Title:     fxhash - no longer maintained
Date:      2025-09-05
ID:        RUSTSEC-2025-0057
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0057

Crate: paste
Version: 1.0.15
Warning: unmaintained
Title: paste - no longer maintained
Date: 2024-10-07
ID: RUSTSEC-2024-0436
URL: https://rustsec.org/advisories/RUSTSEC-2024-0436

Crate: rustls-pemfile
Version: 2.2.0
Warning: unmaintained
Title: rustls-pemfile is unmaintained
Date: 2025-11-28
ID: RUSTSEC-2025-0134
URL: https://rustsec.org/advisories/RUSTSEC-2025-0134

Crate: rustybuzz
Version: 0.20.1
Warning: unmaintained
Title: rustybuzz is unmaintained
Date: 2026-07-11
ID: RUSTSEC-2026-0206
URL: https://rustsec.org/advisories/RUSTSEC-2026-0206

Crate: ttf-parser
Version: 0.25.1
Warning: unmaintained
Title: ttf-parser is unmaintained
Date: 2026-06-28
ID: RUSTSEC-2026-0192
URL: https://rustsec.org/advisories/RUSTSEC-2026-0192

warning: 5 allowed warnings found
</tr></table>

... (truncated)

Commits

Updates minisign-verify from 0.2.5 to 0.3.0

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…updates

Bumps the windows-rust group with 2 updates in the /apps/windows/crates/tono-plugin-core directory: [tauri](https://github.com/tauri-apps/tauri) and [tauri-plugin](https://github.com/tauri-apps/tauri).
Bumps the windows-rust group with 1 update in the /apps/windows/service directory: [minisign-verify](https://github.com/jedisct1/rust-minisign-verify).


Updates `tauri` from 2.11.6 to 2.12.1
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](tauri-apps/tauri@tauri-v2.11.6...tauri-v2.12.1)

Updates `tauri-plugin` from 2.6.3 to 2.7.1
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](tauri-apps/tauri@tauri-plugin-v2.6.3...tauri-plugin-v2.7.1)

Updates `minisign-verify` from 0.2.5 to 0.3.0
- [Commits](jedisct1/rust-minisign-verify@0.2.5...0.3.0)

---
updated-dependencies:
- dependency-name: tauri
  dependency-version: 2.12.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: windows-rust
- dependency-name: tauri-plugin
  dependency-version: 2.7.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: windows-rust
- dependency-name: minisign-verify
  dependency-version: 0.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: windows-rust
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 4, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: windows. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@raydocs

raydocs commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Superseded by #1421 (main aaa0c1d), which refreshes all four Windows Cargo.lock files together. Held: minisign-verify stays at =0.2.5 so the service verifies update packages with the same implementation as the app's tauri-plugin-updater 2.13.1, which still locks 0.2.5; both move together when the updater does. Record: docs/changelog.d/2026-10-06-deps-windows.md.

@raydocs raydocs closed this Oct 6, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/cargo/apps/windows/crates/tono-plugin-core/windows-rust-237dd88c96 branch October 6, 2026 20:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant