Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build(deps): bump prost-build from 0.7.0 to 0.8.0 #1136

Closed
wants to merge 1 commit into from

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jul 8, 2021

Bumps prost-build from 0.7.0 to 0.8.0.

Release notes

Sourced from prost-build's releases.

v0.8.0

PROST! is a Protocol Buffers implementation for the Rust Language. prost generates simple, idiomatic Rust code from proto2 and proto3 files.

NOTE: This version contains a security fix for prost-types and is recommend that you upgrade to it from <0.7.

prost 0.8.0 includes breaking changes:

  • Timestamp's From implementation for converting into SystemTime has been converted to a fallible TryFrom implementation.
  • prost-build's compile_protos now takes impl AsRef<Path> to allow each parameter to use its own generic type.
  • Bundled protoc version bumped to 3.15.8

As well as many new (non-breaking) changes:

  • @​pluth enabled zero-copy support for Bytes based fields.
  • @​sfackler for fixing message optionals and oneofs in prost-build.
  • @​rubdos for adding the ability to encode prost messages directly to a Vec<u8>.

and numerous smaller fixes. Many thanks to the generous contributors who have helped out since 0.7:

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [prost-build](https://github.com/tokio-rs/prost) from 0.7.0 to 0.8.0.
- [Release notes](https://github.com/tokio-rs/prost/releases)
- [Commits](tokio-rs/prost@v0.7.0...v0.8.0)

---
updated-dependencies:
- dependency-name: prost-build
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot requested a review from a team July 8, 2021 19:16
@dependabot dependabot bot added dependencies Pull requests that update a dependency file rust Pull requests that update Rust code labels Jul 8, 2021
@hawkw
Copy link
Member

hawkw commented Jul 8, 2021

It looks like the security advisories check is failing on the prost-types advisory for the issue fixed in prost-types 0.8 (updated in #1135). but in order to pick up the fix we also need to update the proxy-api crate, i think?

olix0r pushed a commit that referenced this pull request Jul 9, 2021
This updates `prost`, `prost-types`, and `prost-build` to v0.8, which
includes a fix for a panic (and potential denial-of-service attack) when
converting a protobuf duration into a Rust `Duration`. Although we don't
use the vulnerable APIs in the proxy or in `linkerd2-proxy-api`, this is
necessary in order to fix a RUSTSEC advisory warning. In order to update
`prost`, we must also update `tonic` and `tonic-build` to v0.5, which
depends on `prost` 0.8, and update the `linkerd2-proxy-api` crate to
include linkerd/linkerd2-proxy-api#71.

Since these crates all depend on each other, we need to update them all
at the same time. Dependabot has opened separate PRs for these crates,
but none of them will pass CI, since they depend on incompatible
versions. This PR, on the other hand, should pass, since it updates all
the crates atomically in one commit. Also, some minor code changes
were required due to breaking API changes in `tonic` 0.5.

Closes #1134, #1135, and #1136; should fix CI.
@olix0r olix0r closed this Jul 9, 2021
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Jul 9, 2021

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot bot deleted the dependabot/cargo/prost-build-0.8.0 branch July 9, 2021 14:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file rust Pull requests that update Rust code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants