Skip to content

build: bump the cargo-minor-and-patch group in /src-tauri with 9 updates - #60

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/src-tauri/cargo-minor-and-patch-eb64f77813
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/src-tauri/cargo-minor-and-patch-eb64f77813

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the cargo-minor-and-patch group in /src-tauri with 9 updates:

Package From To
tauri 2.11.6 2.12.0
tauri-plugin-dialog 2.7.3 2.8.0
tauri-plugin-opener 2.5.5 2.7.0
tauri-plugin-process 2.3.1 2.4.0
tauri-plugin-window-state 2.4.1 2.5.0
hyper-util 0.1.20 0.1.21
tauri-plugin-updater 2.12.0 2.13.1
tauri-plugin-single-instance 2.4.5 2.5.1
tauri-build 2.6.3 2.7.1

Updates tauri from 2.11.6 to 2.12.0

Release notes

Sourced from tauri's releases.

tauri-cli v2.12.0

Fetching advisory database from `https://github.com/RustSec/advisory-db.git`
      Loaded 1271 security advisories (from /home/runner/.cargo/advisory-db)
    Updating crates.io index
    Scanning Cargo.lock for vulnerabilities (1091 crate dependencies)
Crate:     fxhash
Version:   0.2.1
Warning:   unmaintained
Title:     fxhash - no longer maintained
Date:      2025-09-05
ID:        RUSTSEC-2025-0057
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0057

Crate: paste
Version: 1.0.15
Warning: unmaintained
Title: paste - no longer maintained
Date: 2024-10-07
ID: RUSTSEC-2024-0436
URL: https://rustsec.org/advisories/RUSTSEC-2024-0436

Crate: rustls-pemfile
Version: 2.2.0
Warning: unmaintained
Title: rustls-pemfile is unmaintained
Date: 2025-11-28
ID: RUSTSEC-2025-0134
URL: https://rustsec.org/advisories/RUSTSEC-2025-0134

Crate: rustybuzz
Version: 0.20.1
Warning: unmaintained
Title: rustybuzz is unmaintained
Date: 2026-07-11
ID: RUSTSEC-2026-0206
URL: https://rustsec.org/advisories/RUSTSEC-2026-0206

Crate: ttf-parser
Version: 0.25.1
Warning: unmaintained
Title: ttf-parser is unmaintained
Date: 2026-06-28
ID: RUSTSEC-2026-0192
URL: https://rustsec.org/advisories/RUSTSEC-2026-0192

warning: 5 allowed warnings found
</tr></table>

... (truncated)

Commits
  • 447fa9f fix(core): tauri-utils publish
  • 4f46cfc fix(ci): pnpm publish should use "debug" loglevel instead of "silly"
  • 726822c apply version updates (#15634)
  • 9f8922a docs(core): extend app_directories_override documentation (#16139)
  • dc894d4 chore: remove change file for unreleased fix (#16140)
  • 152529e Revert "feat(core): add android activityEmbedding config (#15255)" (#16138)
  • 7456ddd Revert "fix(core): proper unique identifier for menu items on channels store"...
  • 15468de fix(bundler): recognize deb and rpm as self-contained updater targets (#16064)
  • 8e70283 fix(bundler): update linuxdeploy and linuxdeploy-plugin-gtk (#16062)
  • 1b91b7b fix(cli): list all locked crate versions in tauri info (#16102)
  • Additional commits viewable in compare view

Updates tauri-plugin-dialog from 2.7.3 to 2.8.0

Release notes

Sourced from tauri-plugin-dialog's releases.

http-js v2.8.0

[2.8.0]

npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-http@2.8.0
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 2.6kB README.md
npm notice 7.7kB dist-js/index.cjs
npm notice 3.4kB dist-js/index.d.ts
npm notice 7.7kB dist-js/index.js
npm notice 655B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-http
npm notice version: 2.8.0
npm notice filename: tauri-apps-plugin-http-2.8.0.tgz
npm notice package size: 5.5 kB
npm notice unpacked size: 23.0 kB
npm notice shasum: 1cf059a5c97cadea0e5f6a07c22931a118c60ffc
npm notice integrity: sha512-cPvZvfUSaBkqG[...]jyXRPNo6Cky6g==
npm notice total files: 6
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=3005263804
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-http@2.8.0
Commits
  • 6e2e7e4 publish new versions (#3070)
  • 9a2c98f temp: remove updater changefiles
  • 4a2ecb6 chore(deps): update rkyv, closes #3196
  • 31415ef docs(shell): update example to include Encoding usage in Command::spawn (#3...
  • 04b33ea chore(deps): update dependency typescript-eslint to v8.50.1 (#3181)
  • 54e21f1 chore(deps): update dependency rollup to v4.54.0 (#3179)
  • d528c88 chore(deps): update dependency rollup to v4.53.5 (#3172)
  • 69146fa chore(deps): update dependency rollup to v4.53.4 (#3167)
  • 9f68f2d chore(deps): update dependency typescript-eslint to v8.50.0 (#3170)
  • 3d0d2e0 fix(opener): ignore inAppBrowser on desktop (#3163)
  • Additional commits viewable in compare view

Updates tauri-plugin-opener from 2.5.5 to 2.7.0

Release notes

Sourced from tauri-plugin-opener's releases.

opener-js v2.7.0

[2.7.0]

  • ecd3273e (#3480 by @​renovate) Updated windows-rs dependencies:

    • deep-link: updated windows-registry to 0.6 and windows-result to 0.4. The public Error::Windows variant wraps windows_result::Error; applications using this type directly should update their windows-result dependency.
    • opener: updated windows to 0.62. The public Error::Win32Error variant wraps windows::core::Error; applications using this type directly should update their windows dependency.
    • single-instance: updated windows-sys to 0.61
    • updater: updated windows-sys to 0.61
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-opener@2.7.0
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 4.2kB README.md
npm notice 3.1kB dist-js/index.cjs
npm notice 2.0kB dist-js/index.d.ts
npm notice 3.1kB dist-js/index.js
npm notice 11B dist-js/init.d.ts
npm notice 730B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-opener
npm notice version: 2.7.0
npm notice filename: tauri-apps-plugin-opener-2.7.0.tgz
npm notice package size: 3.5 kB
npm notice unpacked size: 14.1 kB
npm notice shasum: 14d631a70282cbc07b46f4442ba6085d2200f301
npm notice integrity: sha512-mBorYfVKh9Lt7[...]5OHHVmipjuGMw==
npm notice total files: 7
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=3005263072
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-opener@2.7.0

opener v2.7.0

[2.7.0]

... (truncated)

Commits
  • 51b430b ci: delete .changes/updater-new-bundle-support.md
  • fd439b1 Publish New Versions (v2) (#2964)
  • 2522b71 fix(deep-link): revert the breaking change introduced by #2928 (#2970)
  • 9021a73 chore(deps): update dependency rollup to v4.50.0 (#2966)
  • 625bb1c feat(log): re-export the log crate (#2965)
  • 6215afe chore(deps): update dependency rollup to v4.49.0 (#2962)
  • 8cf8eea feat(updater): inject bundle_type into endpoint url (#2960)
  • 509eba8 feat: support message dialogs with 3 buttons (#2641)
  • 9ac5fe8 feat(updater): support bundle-specific targets (#2624)
  • c247410 chore(deps): update dependency typescript-eslint to v8.41.0 (#2956)
  • Additional commits viewable in compare view

Updates tauri-plugin-process from 2.3.1 to 2.4.0

Release notes

Sourced from tauri-plugin-process's releases.

stronghold-js v2.4.0

[2.4.0]

  • ae3c808e (#3602) The plugin's global API script (used with app.withGlobalTauri) now resolves the core API from window.__TAURI__ instead of bundling its own copy of @tauri-apps/api. Values created with the core API are now accepted by plugin APIs in global mode (e.g. an Image from window.__TAURI__.image passed to clipboardManager.writeImage, which previously failed the instanceof check against the plugin's private copy), and the script is considerably smaller.
  • 9b29b601 Update MSRV to 1.90 to match tauri.
  • a87a3c7d Update documentation.
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-stronghold@2.4.0
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 4.7kB README.md
npm notice 19.4kB dist-js/index.cjs
npm notice 21.1kB dist-js/index.d.ts
npm notice 19.2kB dist-js/index.js
npm notice 750B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-stronghold
npm notice version: 2.4.0
npm notice filename: tauri-apps-plugin-stronghold-2.4.0.tgz
npm notice package size: 8.7 kB
npm notice unpacked size: 66.0 kB
npm notice shasum: 47b370840be057acd7d8f76046a9978a622cfcbe
npm notice integrity: sha512-5FIKueS+4xs66[...]j7Mzwt0NX4r1A==
npm notice total files: 6
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=2969525576
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-stronghold@2.4.0

stronghold v2.4.0

[2.4.0]

  • ae3c808e (#3602) The plugin's global API script (used with app.withGlobalTauri) now resolves the core API from window.__TAURI__ instead of bundling its own copy of @tauri-apps/api. Values created with the core API are now accepted by plugin APIs in global mode (e.g. an Image from window.__TAURI__.image passed to clipboardManager.writeImage, which previously failed the instanceof check against the plugin's private copy), and the script is considerably smaller.
  • 9b29b601 Update MSRV to 1.90 to match tauri.
  • a87a3c7d Update documentation.

... (truncated)

Commits

Updates tauri-plugin-window-state from 2.4.1 to 2.5.0

Release notes

Sourced from tauri-plugin-window-state's releases.

sql-js v2.5.0

[2.5.0]

  • ae3c808e (#3602) The plugin's global API script (used with app.withGlobalTauri) now resolves the core API from window.__TAURI__ instead of bundling its own copy of @tauri-apps/api. Values created with the core API are now accepted by plugin APIs in global mode (e.g. an Image from window.__TAURI__.image passed to clipboardManager.writeImage, which previously failed the instanceof check against the plugin's private copy), and the script is considerably smaller.
  • 9b29b601 Update MSRV to 1.90 to match tauri.
  • a87a3c7d Update documentation.
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-sql@2.5.0
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 6.2kB README.md
npm notice 6.5kB dist-js/index.cjs
npm notice 6.1kB dist-js/index.d.ts
npm notice 6.5kB dist-js/index.js
npm notice 703B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-sql
npm notice version: 2.5.0
npm notice filename: tauri-apps-plugin-sql-2.5.0.tgz
npm notice package size: 5.3 kB
npm notice unpacked size: 27.0 kB
npm notice shasum: f2806141a23eab9347aed34efa0efa15930e8dae
npm notice integrity: sha512-wHzfXAgMbn3G1[...]kFZrgTyu8zBkw==
npm notice total files: 6
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=2969525463
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-sql@2.5.0

sql v2.5.0

[2.5.0]

  • ae3c808e (#3602) The plugin's global API script (used with app.withGlobalTauri) now resolves the core API from window.__TAURI__ instead of bundling its own copy of @tauri-apps/api. Values created with the core API are now accepted by plugin APIs in global mode (e.g. an Image from window.__TAURI__.image passed to clipboardManager.writeImage, which previously failed the instanceof check against the plugin's private copy), and the script is considerably smaller.
  • 9b29b601 Update MSRV to 1.90 to match tauri.
  • a87a3c7d Update documentation.

... (truncated)

Commits
  • d6a3898 Publish New Versions (v2) (#3268)
  • 2e5bcdf chore(deps): fix audits (#3373)
  • 4374b4f chore(notification): remove unused dev-deps (#3372)
  • f75d21d chore(deps): remove used of tauri-utils build feature (#3360)
  • 4b95f5e chore(deps): update dependency eslint to v10.1.0 (#3357)
  • 99c3e37 chore(deps): bump tar in /plugins/updater/tests/updater-migration/v1-app (#3352)
  • eaac19a chore(deps): update rust crate tar to v0.4.45 [security] (#3353)
  • 5183e31 chore(deps): update dependency typescript-eslint to v8.57.1 (#3344)
  • 2c0883e chore(deps): update dependency vite to v8 (#3346)
  • 024ec0c fix(deep-link): ChromeOS deep link calls filtered and ignored by plugin (fix ...
  • Additional commits viewable in compare view

Updates hyper-util from 0.1.20 to 0.1.21

Release notes

Sourced from hyper-util's releases.

v0.1.21

Additions

  • Add crate-level documentation. (#327)
  • Add client::legacy::Builder::http2_header_table_size() method. (#274)
  • Add client::legacy::Builder::http2_max_concurrent_streams() method. (#274)
  • Add client::legacy::Builder::http2_max_local_error_reset_streams() method. (#277)
  • Add client::legacy::connect::HttpConnector::set_mark() method. (#303)
  • Add rt::tracing::WithSpanExecutor<E>, hyper_util::rt::tracing::CurrentSpanExecutor<E>, and hyper_util::rt::tracing::MkSpanExecutor<E, F> executors. (#323)

Fixes

  • Fix client::legacy::Client so that it properly validates CONNECT responses. (#315)
  • Fix client::legacy::Client to cancel the idle interval once its pool empties. (#292)
  • Fix client::legacy::Client to properly handle IPv6 addresses when using a SOCKS proxy. (#302)
  • Fix client::pool::cache to preserve readiness with clones. (#297)
  • Fix client::pool::cache to wake its waiters in FIFO order. (#298)
  • Fix client::pool::singleton::Singleton to properly handle cancellation. (#299)
  • Fix client::pool::singleton::Singleton to share errors with all waiters. (#296)
  • Fix client::proxy::matcher handling for IP wildcards. (#309)
  • The tokio/net feature is narrowed to the client-legacy feature flag, from the client feature flag. (#276)
  • Various fixes to the client::legacy::Client's SOCKS proxying. (#302) (#307) (#308) (#310)

Changes

This release contains a minor behavioral change for users of the tracing feature flag to be aware of.

This feature flag was introduced in v0.1.11. When enabled, rt::TokioExecutor<E> began propagating the currently active tracing::Span to spawned tasks when hyper::rt::Executor::execute() is called. This caused issues for some users, due to background tasks keeping a span open for the duration of a long-lived connection.

This behavior has now been removed from rt::TokioExecutor<E> (#322) by default. A collection of executor wrappers have been added to a new rt::tracing submodule, to provide facilities for instrumenting a client or server's spawned tasks. See the module-level documentation of rt::tracing for more information.

To temporarily preserve the previous rt::TokioExecutor<E> span propagation behavior, enable the rt-tracing-exec-force feature. Note that this feature flag will be removed in a future release.

This release bumps the minimal supported Rust version (MSRV) from 1.64 to 1.85.

This release bumps the rust edition from 2021 to 2024.

... (truncated)

Changelog

Sourced from hyper-util's changelog.

0.1.21 (2026-09-24)

This release bumps the minimal supported Rust version (MSRV) from 1.64 to 1.85.

This release bumps the rust edition from 2021 to 2024.

Additions

  • Add crate-level documentation. (#327)
  • Add client::legacy::Builder::http2_header_table_size() method. (#274)
  • Add client::legacy::Builder::http2_max_concurrent_streams() method. (#274)
  • Add client::legacy::Builder::http2_max_local_error_reset_streams() method. (#277)
  • Add client::legacy::connect::HttpConnector::set_mark() method. (#303)
  • Add rt::tracing::WithSpanExecutor<E>, hyper_util::rt::tracing::CurrentSpanExecutor<E>, and hyper_util::rt::tracing::MkSpanExecutor<E, F> executors. (#323)

Fixes

  • Fix client::legacy::Client so that it properly validates CONNECT responses. (#315)
  • Fix client::legacy::Client to cancel the idle interval once its pool empties. (#292)
  • Fix client::legacy::Client to properly handle IPv6 addresses when using a SOCKS proxy. (#302)
  • Fix client::pool::cache to preserve readiness with clones. (#297)
  • Fix client::pool::cache to wake its waiters in FIFO order. (#298)
  • Fix client::pool::singleton::Singleton to properly handle cancellation. (#299)
  • Fix client::pool::singleton::Singleton to share errors with all waiters. (#296)
  • Fix client::proxy::matcher handling for IP wildcards. (#309)
  • The tokio/net feature is narrowed to the client-legacy feature flag, from the client feature flag. (#276)
  • Various fixes to the client::legacy::Client's SOCKS proxying. (#302) (#307) (#308) (#310)

Changes

This release contains a minor behavioral change for users of the tracing feature flag to be aware of.

This feature flag was introduced in v0.1.11. When enabled, rt::TokioExecutor<E> began propagating the currently active tracing::Span to spawned tasks when hyper::rt::Executor::execute() is called. This caused issues for some users, due to background tasks keeping a span open for the duration of a long-lived connection.

This behavior has now been removed from rt::TokioExecutor<E> (#322) by default. A collection of executor wrappers have been added to a new rt::tracing submodule, to provide facilities for instrumenting a client or server's spawned tasks. See the module-level documentation of rt::tracing for more information.

To temporarily preserve the previous rt::TokioExecutor<E> span propagation behavior, enable the rt-tracing-exec-force feature. Note that this feature flag will be removed in a future release.

Commits
  • 23a8689 v0.1.21
  • cdb2346 doc(client/pool): add broken_intra_doc_links allowance (#326)
  • 13b6110 chore(error): remove disabled hyper_util::error submodule (#325)
  • b9ee451 docs(lib): add crate-level documentation (#327)
  • d6b7d7e feat(rt/tracing): introduce tracing executors (#323)
  • f2da915 feat(client): add HttpConnector::set_mark for SO_MARK (#303)
  • 4dbd494 feat(rt): change TokioExecutor to not trace, add rt-tracing-exec-force feat...
  • d480d9f fix(client): parse proxy CONNECT response with httparse (#315)
  • 7e0958b chore(ci): simplify msrv check (#317)
  • 0734568 chore(ci): update to actions/checkout@v7 (#316)
  • Additional commits viewable in compare view

Updates tauri-plugin-updater from 2.12.0 to 2.13.1

Release notes

Sourced from tauri-plugin-updater's releases.

updater-js v2.13.1

[2.13.1]

  • ecd3273e (#3480 by @​renovate) Updated windows-rs dependencies:

    • deep-link: updated windows-registry to 0.6 and windows-result to 0.4. The public Error::Windows variant wraps windows_result::Error; applications using this type directly should update their windows-result dependency.
    • opener: updated windows to 0.62. The public Error::Win32Error variant wraps windows::core::Error; applications using this type directly should update their windows dependency.
    • single-instance: updated windows-sys to 0.61
    • updater: updated windows-sys to 0.61
  • 90b9869e (#3573 by @​renovate) Updated dirs to v7

  • 22e286f3 (#3501 by @​renovate) Updated dependency infer to 0.22

npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-updater@2.13.1
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 3.2kB README.md
npm notice 6.7kB dist-js/index.cjs
npm notice 7.1kB dist-js/index.d.ts
npm notice 6.6kB dist-js/index.js
npm notice 659B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-updater
npm notice version: 2.13.1
npm notice filename: tauri-apps-plugin-updater-2.13.1.tgz
npm notice package size: 4.8 kB
npm notice unpacked size: 25.1 kB
npm notice shasum: 2ad227ba05293fe34c5c59c0ff8a1cd690c8e9a8
npm notice integrity: sha512-+STDzJ0sdQLIm[...]/AJz0jxysytiw==
npm notice total files: 6
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=3005269671
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-updater@2.13.1

updater v2.13.1

... (truncated)

Commits
  • e511284 publish new versions (#3647)
  • ce59e96 docs(log): remove unrelated single-instance comment from log readme
  • 29130c2 ci: run clippy on all platforms (#3650)
  • 4353819 chore: add changefile to re-release plugin-http npm package as 2.8.0 (#3656)
  • ec14142 chore(deps): update dependency @​types/node to v24 (#3649)
  • 90b9869 chore(deps): update rust crate dirs to v7 (#3573)
  • 22e286f chore(deps): update rust crate infer to 0.22 (#3501)
  • ecd3273 chore(deps): update windows-rs and webview2 crates (#3480)
  • aa2cc64 fix(android): Migrate Gradle scripts to compilerOptions DSL (#3478)
  • a2364a5 fix: integration test
  • Additional commits viewable in compare view

Updates tauri-plugin-single-instance from 2.4.5 to 2.5.1

Release notes

Sourced from tauri-plugin-single-instance's releases.

single-instance v2.5.1

[2.5.1]

  • ecd3273e (#3480 by @​renovate) Updated windows-rs dependencies:

    • deep-link: updated windows-registry to 0.6 and windows-result to 0.4. The public Error::Windows variant wraps windows_result::Error; applications using this type directly should update their windows-result dependency.
    • opener: updated windows to 0.62. The public Error::Win32Error variant wraps windows::core::Error; applications using this type directly should update their windows dependency.
    • single-instance: updated windows-sys to 0.61
    • updater: updated windows-sys to 0.61

Dependencies

  • Upgraded to deep-link@2.6.0
Updating crates.io index
   Packaging tauri-plugin-single-instance v2.5.1 (/home/runner/work/plugins-workspace/plugins-workspace/plugins/single-instance)
    Updating crates.io index
    Packaged 15 files, 168.2KiB (46.0KiB compressed)
   Uploading tauri-plugin-single-instance v2.5.1 (/home/runner/work/plugins-workspace/plugins-workspace/plugins/single-instance)
    Uploaded tauri-plugin-single-instance v2.5.1 to registry `crates-io`
note: waiting for tauri-plugin-single-instance v2.5.1 to be available at registry `crates-io`
help: you may press ctrl-c to skip waiting; the crate should be available shortly
warning: timed out waiting for tauri-plugin-single-instance v2.5.1 to be available in registry `crates-io`
  |
  = note: the registry may have a backlog that is delaying making the crate available. The crate should be available soon.

barcode-scanner-js v2.5.1

[2.5.1]

  • 569ee82c Fix the docs.rs build for Android: the build script now detects docs.rs through the DOCS_RS environment variable, since cfg(docsrs) is never set for build scripts.
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-barcode-scanner@2.5.1
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
</tr></table> 

... (truncated)

Commits
  • 5c7668b publish new versions (#3397)
  • ec05401 chore(deps): update rust crate toml to v1 (#3323)
  • b86e999 chore(deps): update tauri packages to 2.11 (#3407)
  • c463d8a chore(deps): update rustls-webpki in lockfile, ignore core2 in audit (#3405)
  • 1bb7beb chore(deps): bump openssl (#3402)
  • 3412fa2 docs(readme): fix platform support matrix (opener supports mobile)
  • af81fda docs(readme): fix platform support matrix (mobile is supported)
  • c1fd33b fix(opener): allow open network share locations (#3343)
  • 250857b chore(deps): update dependency typescript to v6 (#3363)
  • 964e13f fix(store): dead lock trying to set while exiting (#3395)
  • Additional commits viewable in compare view

Updates tauri-build from 2.6.3 to 2.7.1

Release notes

Sourced from tauri-build's releases.

tauri-build v2.7.1

Fetching advisory database from `https://github.com/RustSec/advisory-db.git`
      Loaded 1277 security advisories (from /home/runner/.cargo/advisory-db)
    Updating crates.io index
    Scanning Cargo.lock for vulnerabilities (1091 crate dependencies)
Crate:     fxhash
Version:   0.2.1
Warning:   unmaintained
Title:     fxhash - no longer maintained
Date:      2025-09-05
ID:        RUSTSEC-2025-0057
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0057

Crate: paste
Version: 1.0.15
Warning: unmaintained
Title: paste - no longer maintained
Date: 2024-10-07
ID: RUSTSEC-2024-0436
URL: https://rustsec.org/advisories/RUSTSEC-2024-0436

Crate: rustls-pemfile
Version: 2.2.0
Warning: unmaintained
Title: rustls-pemfile is unmaintained
Date: 2025-11-28
ID: RUSTSEC-2025-0134
URL: https://rustsec.org/advisories/RUSTSEC-2025-0134

Crate: rustybuzz
Version: 0.20.1
Warning: unmaintained
Title: rustybuzz is unmaintained
Date: 2026-07-11
ID: RUSTSEC-2026-0206
URL: https://rustsec.org/advisories/RUSTSEC-2026-0206

Crate: ttf-parser
Version: 0.25.1
Warning: unmaintained
Title: ttf-parser is unmaintained
Date: 2026-06-28
ID: RUSTSEC-2026-0192
URL: https://rustsec.org/advisories/RUSTSEC-2026-0192

warning: 5 allowed warnings found
</tr></table>

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the cargo-minor-and-patch group in /src-tauri with 9 updates:

| Package | From | To |
| --- | --- | --- |
| [tauri](https://github.com/tauri-apps/tauri) | `2.11.6` | `2.12.0` |
| [tauri-plugin-dialog](https://github.com/tauri-apps/plugins-workspace) | `2.7.3` | `2.8.0` |
| [tauri-plugin-opener](https://github.com/tauri-apps/plugins-workspace) | `2.5.5` | `2.7.0` |
| [tauri-plugin-process](https://github.com/tauri-apps/plugins-workspace) | `2.3.1` | `2.4.0` |
| [tauri-plugin-window-state](https://github.com/tauri-apps/plugins-workspace) | `2.4.1` | `2.5.0` |
| [hyper-util](https://github.com/hyperium/hyper-util) | `0.1.20` | `0.1.21` |
| [tauri-plugin-updater](https://github.com/tauri-apps/plugins-workspace) | `2.12.0` | `2.13.1` |
| [tauri-plugin-single-instance](https://github.com/tauri-apps/plugins-workspace) | `2.4.5` | `2.5.1` |
| [tauri-build](https://github.com/tauri-apps/tauri) | `2.6.3` | `2.7.1` |


Updates `tauri` from 2.11.6 to 2.12.0
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](tauri-apps/tauri@tauri-v2.11.6...tauri-v2.12.0)

Updates `tauri-plugin-dialog` from 2.7.3 to 2.8.0
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@dialog-v2.7.3...log-v2.8.0)

Updates `tauri-plugin-opener` from 2.5.5 to 2.7.0
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@http-v2.5.5...log-v2.7.0)

Updates `tauri-plugin-process` from 2.3.1 to 2.4.0
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@os-v2.3.1...os-v2.4.0)

Updates `tauri-plugin-window-state` from 2.4.1 to 2.5.0
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@fs-v2.4.1...fs-v2.5.0)

Updates `hyper-util` from 0.1.20 to 0.1.21
- [Release notes](https://github.com/hyperium/hyper-util/releases)
- [Changelog](https://github.com/hyperium/hyper-util/blob/master/CHANGELOG.md)
- [Commits](hyperium/hyper-util@v0.1.20...v0.1.21)

Updates `tauri-plugin-updater` from 2.12.0 to 2.13.1
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@updater-v2.12.0...updater-v2.13.1)

Updates `tauri-plugin-single-instance` from 2.4.5 to 2.5.1
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@fs-v2.4.5...fs-v2.5.1)

Updates `tauri-build` from 2.6.3 to 2.7.1
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](tauri-apps/tauri@tauri-build-v2.6.3...tauri-build-v2.7.1)

---
updated-dependencies:
- dependency-name: tauri
  dependency-version: 2.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-minor-and-patch
- dependency-name: tauri-plugin-dialog
  dependency-version: 2.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-minor-and-patch
- dependency-name: tauri-plugin-opener
  dependency-version: 2.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-minor-and-patch
- dependency-name: tauri-plugin-process
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-minor-and-patch
- dependency-name: tauri-plugin-window-state
  dependency-version: 2.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-minor-and-patch
- dependency-name: hyper-util
  dependency-version: 0.1.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-minor-and-patch
- dependency-name: tauri-plugin-updater
  dependency-version: 2.13.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-minor-and-patch
- dependency-name: tauri-plugin-single-instance
  dependency-version: 2.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-minor-and-patch
- dependency-name: tauri-build
  dependency-version: 2.7.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 4, 2026
eduardoghi added a commit that referenced this pull request Oct 10, 2026
Supersedes Dependabot's #60, which moved the Rust crates to tauri 2.12.0 and left the npm packages behind. 2.12.0's MockRuntime gates WindowBuilder::transparent behind a cfg that hides it on macOS without macos-private-api, so the macOS leg failed to compile the tests (E0046), and 2.12.1 drops that gate. The npm packages move with the crates (api and cli to 2.12.1, dialog 2.8.1, opener 2.7.0, process 2.4.0, updater 2.13.1) because tauri build refuses mismatched major.minor pairs, a check CI never runs. A debug tauri build passes it.
eduardoghi added a commit that referenced this pull request Oct 10, 2026
tauri build refuses an @tauri-apps npm package and its Rust crate on
different major.minor releases, and ci.yml never runs tauri build, so the
skew only showed up in release.yml. Dependabot bumps the two sides in
separate PRs, which is how PR #60 left the crates on 2.12 with npm on 2.11.
The new gate reads both lockfiles and pairs @tauri-apps/api with tauri and
each @tauri-apps/plugin-<name> with tauri-plugin-<name>.
@dependabot @github

dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 10, 2026
@dependabot
dependabot Bot deleted the dependabot/cargo/src-tauri/cargo-minor-and-patch-eb64f77813 branch October 10, 2026 00:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants