Skip to content

Bump the cargo group across 1 directory with 16 updates - #198

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/main/cargo-59906b042c
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/main/cargo-59906b042c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the cargo group with 16 updates in the / directory:

Package From To
toml 1.1.4+spec-1.1.0 1.1.6+spec-1.1.0
diesel 2.3.12 2.3.13
clap 4.6.6 4.6.7
aes-gcm 0.11.0 0.11.1
tun-rs 2.8.8 2.8.10
tokio-rustls 0.26.4 0.26.5
pingora-core 0.8.1 0.9.0
pingora-proxy 0.8.1 0.9.0
pingora-http 0.8.1 0.9.0
pingora-openssl 0.8.1 0.9.0
uuid 1.24.1 1.26.1
rcgen 0.14.9 0.14.10
reqwest 0.13.4 0.13.5
quick-xml 0.41.0 0.42.0
aws-sdk-route53 1.119.0 1.122.0
argon2 0.5.3 0.6.0

Updates toml from 1.1.4+spec-1.1.0 to 1.1.6+spec-1.1.0

Commits
  • 572c005 chore: Release
  • 66d0c53 docs: Update changelog
  • 07af4e7 perf: Reduce allocations in toml_edit parsing and dumping (#1215)
  • 0ff90db perf(display): Write encoded strings directly
  • efb2536 perf(display): Move generated representation strings
  • 075c444 refactor(display): Consolidate key-path encoding
  • b48f338 perf(display): Borrow table keys during document output
  • c6c1de3 perf(parser): Move completed table header keys
  • ec90463 perf(parser): Borrow input when creating editable documents
  • d76a48a test: Benchmark rendering generated keys and values
  • Additional commits viewable in compare view

Updates diesel from 2.3.12 to 2.3.13

Changelog

Sourced from diesel's changelog.

[2.3.13] 2026-09-4

  • Fixed interaction between then_order_by and distinct_on to reject otherwise broken SQL queries
  • Fix a clippy::redundant_field_names lint warning generated by #[derive(QueryableByName)]
  • MySQL and MariaDB now decode a value according to the signedness the server reports for its column, so a SMALLINT UNSIGNED holding 40000 read as Integer returns 40000 rather than -25536
  • Potential stackoverflow on deeply nested JSONB values for the SQLite backend
  • Fixed a possible null pointer dereference in the custom SQLite aggregate function support when SQLite fails to allocate the aggregate state
  • Fixed undefined behavior in SqliteConnection::serialize_database_to_buffer when SQLite returns a null buffer for an empty deserialized database or an allocation failure. SerializedDatabase::as_slice is deprecated in favor of the new SerializedDatabase::try_as_slice, which reports the allocation failure as an error instead of panicking.
  • Fixed SQLite value reads to panic instead of creating invalid slices or returning incorrect data when SQLite allocation fails. Row iteration reports a failed value duplication as an error instead.
  • Fixed a use after free where reading a SQLite value in a second representation, for example a blob as text, invalidated slices another SqliteValue of the same field had returned. Such a read now works on a copy of the value.
  • Fixed broken prepared statement caching for queries using positional ordering and window functions with frame offset clauses
  • Fixed a potential panic while deserializing a PgInterval type from a too short buffer
  • Fixed encoding floating point values without a decimal part in a roundtrip safe way in SQLite's jsonb encoding
  • Fixed a potential panic while deserializing a PgInterval type from a too short buffer
  • Fixed potential code injections in the generated schema.rs file caused by malicious database identifiers
Commits
  • 9628f5c Fix encoding negative integers
  • 3eb6cf4 Fix old serde
  • d2b770f Fix compilation
  • 1abf780 Merge branch 'main' into fix/rust_code_injections
  • 396ea4a Merge pull request #5195 from LucaCappelletti94/fuzz-sqlite-jsonb-float-writer
  • ba02e3a Merge pull request #5196 from weiznich/fix_bigdecimal_cpu_burn
  • 86ae22e Merge pull request #5194 from weiznich/fix_panic_in_pg_interval
  • b9e01d7 Merge pull request #5193 from weiznich/fix_query_id
  • 529f0bd Merge pull request #5183 from LucaCappelletti94/sqlite-serialize-oom-safety
  • 8bd540d Merge pull request #5182 from LucaCappelletti94/sqlite-value-oom-safety
  • Additional commits viewable in compare view

Updates clap from 4.6.6 to 4.6.7

Release notes

Sourced from clap's releases.

v4.6.7

[4.6.7] - 2026-09-14

Features

  • (derive) Add #[command(defer = <bool>)] attribute to opt-in to lazy initialisation of subcommands
Changelog

Sourced from clap's changelog.

[4.6.7] - 2026-09-14

Features

  • (derive) Add #[command(defer = <bool>)] attribute to opt-in to lazy initialisation of subcommands
Commits
  • d3e59a9 chore: Release
  • d997f87 docs: Update changelog
  • fb6058c Merge pull request #6409 from heaths/pwsh-support
  • 2310870 test(complete): Add tests for completer_for_path
  • 5967c17 refactor(complete): Move shell detection to Shells
  • 594602b fix(complete): Detect pwsh for PowerShell
  • 3a4f2d0 Merge pull request #6427 from clap-rs/renovate/shlex-2.x
  • 67ebaed Merge pull request #6426 from clap-rs/renovate/actions-checkout-7.x
  • c968b13 chore(deps): Update Rust crate shlex to v2
  • 8f247cb chore(deps): Update actions/checkout action to v7
  • Additional commits viewable in compare view

Updates aes-gcm from 0.11.0 to 0.11.1

Commits

Updates tun-rs from 2.8.8 to 2.8.10

Release notes

Sourced from tun-rs's releases.

2.8.10

What's Changed

Full Changelog: tun-rs/tun-rs@2.8.8...2.8.10

Commits
  • 2cdb0b8 Update Cargo.toml
  • 5a78e92 Bump cross-platform-actions/action from 1.5.0 to 1.6.0 (#167)
  • 565dea0 Move GSO buffer validation out of hot loop (#164)
  • 034b879 Update bindgen requirement from 0.72.0 to 0.73.1 (#166)
  • 5a1a011 Bump cross-platform-actions/action from 1.3.0 to 1.5.0 (#162)
  • aa6e673 fix(async): size TAP frame buffers from actual MTU on netbsd (#165)
  • 0d0a6c8 Bump Version 2.8.9
  • 93836d6 fix(async): size framed buffers for Ethernet frames, not raw MTU
  • 4965587 fix(windows): interrupt blocking device I/O on drop so tap adapter is removed
  • See full diff in compare view

Updates tokio-rustls from 0.26.4 to 0.26.5

Release notes

Sourced from tokio-rustls's releases.

0.26.5

What's Changed

Commits
  • f8832d2 Bump version to 0.26.5
  • c0fad2f return more data at once from TlsStream::poll_read (#198)
  • edc7306 build(deps): bump futures-util from 0.3.33 to 0.3.34
  • baeadaa build(deps): bump rcgen from 0.14.8 to 0.14.9
  • 1e138ad build(deps): bump taiki-e/cache-cargo-install-action from 3.0.7 to 3.0.8
  • b4ecff6 build(deps): bump taiki-e/cache-cargo-install-action from 3 to 3.0.7
  • f47a689 build(deps): bump rustls from 0.23.42 to 0.23.43
  • e25578e build(deps): bump tokio from 1.53.0 to 1.53.1
  • d2a6d98 server: add rustdoc hinting towards timeout wrapping
  • c2e9b4a client: add rustdoc hinting towards timeout wrapping
  • Additional commits viewable in compare view

Updates pingora-core from 0.8.1 to 0.9.0

Release notes

Sourced from pingora-core's releases.

Pingora 0.9.0

0.9.0 - 2026-09-04

✨ Highlights

  • Reworked connection pooling with sharded storage and a true global LRU, addressing stale entries and race windows.
  • Added an upstream module system that applies before upstream compression.
  • More handling of HTTP parsing and framing edge cases, including non-origin-form request-target preservation, and hop-by-hop header sanitization, obsolete line-fold normalization, stricter request-target validation, and bounded default HTTP/2 limits.
  • Split Prometheus integration into the pingora-prometheus crate and made Prometheus optional.
  • Improved graceful shutdown and upgrade behavior, including responsive load-balancer shutdown, descriptor lifecycle fixes, and lower shutdown-notification contention.

⚠️ Potential Breaking Changes

  • Minimum supported Rust version moves to 1.85 for some crates. pingora-foundations declares an MSRV of 1.88.
  • RequestHeader and ResponseHeader no longer implement DerefMut because unrestricted mutation could violate internal invariants.
  • Removed async_write_vec APIs; consumers should use tokio::io::AsyncWriteExt::write_all_buf.
  • Prometheus integration moved from pingora-core to the separate pingora-prometheus crate; Prometheus is optional.
  • tracing is now optional in pingora-cache.
  • Upgraded to the boring-rs 5.x API.
  • PeerOptions::curve now uses Cow.
  • Upstream requests strip hop-by-hop and Connection-nominated headers by default; legacy behavior requires explicit compatibility settings.
  • Default HTTP/2 server limits are bounded rather than unbounded.
  • Removed the unused LruShard Default implementation and lifted Default bounds on sharded cache structures.
  • Removed the CacheKey namespace parameter.
  • PurgeOutcome enum gains an Expired variant.
  • ForcedFreshness and hit-status reporting gain ForceExpiredServeStale variant.

🚀 Features — Proxy & Sessions

  • Add abort-on-close session configurability.
  • Support HTTP/1.1 downstream request pipelining.
  • Add cancel-safe body and header writer primitives (proxy tasks) to prevent stalled cache misses from applying backpressure.
  • Add an upstream module system and allow modules to adjust after receiving upstream response headers.
  • Add proxy warning-log suppression hooks.
  • Add keepalive-pool callbacks for tracking connection ages.
  • Expose HTTP/1.x request-body bytes accepted by the upstream writer.
  • Report point-in-time available HTTP/2 stream capacity.

🚀 Features — TLS

  • Add ability to configure an offload thread pool for downstream TLS handshakes.
  • Add Acceptor::from_server_config for runtime-built rustls ServerConfig values and in-memory key material.
  • Export TLS keying material, including from pingora-s2n.
  • Add per-peer CA configuration.
  • Add a pre-TLS callback for PROXY protocol support.
  • Expose the rustls certificate type.
  • Add curve and second-keyshare settings to HttpPeer hashing.
  • Avoid compiling aws-lc-rs when the ring provider is selected.

🚀 Features — Server, Runtime & Load Balancing

... (truncated)

Changelog

Sourced from pingora-core's changelog.

0.9.0 - 2026-09-04

✨ Highlights

  • Reworked connection pooling with sharded storage and a true global LRU, addressing stale entries and race windows.
  • Added an upstream module system that applies before upstream compression.
  • More handling of HTTP parsing and framing edge cases, including non-origin-form request-target preservation, and hop-by-hop header sanitization, obsolete line-fold normalization, stricter request-target validation, and bounded default HTTP/2 limits.
  • Split Prometheus integration into the pingora-prometheus crate and made Prometheus optional.
  • Improved graceful shutdown and upgrade behavior, including responsive load-balancer shutdown, descriptor lifecycle fixes, and lower shutdown-notification contention.

⚠️ Potential Breaking Changes

  • Minimum supported Rust version moves to 1.85 for some crates. pingora-foundations declares an MSRV of 1.88.
  • RequestHeader and ResponseHeader no longer implement DerefMut because unrestricted mutation could violate internal invariants.
  • Removed async_write_vec APIs; consumers should use tokio::io::AsyncWriteExt::write_all_buf.
  • Prometheus integration moved from pingora-core to the separate pingora-prometheus crate; Prometheus is optional.
  • tracing is now optional in pingora-cache.
  • Upgraded to the boring-rs 5.x API.
  • PeerOptions::curve now uses Cow.
  • Upstream requests strip hop-by-hop and Connection-nominated headers by default; legacy behavior requires explicit compatibility settings.
  • Default HTTP/2 server limits are bounded rather than unbounded.
  • Removed the unused LruShard Default implementation and lifted Default bounds on sharded cache structures.
  • Removed the CacheKey namespace parameter.
  • PurgeOutcome enum gains an Expired variant.
  • ForcedFreshness and hit-status reporting gain ForceExpiredServeStale variant.

🚀 Features — Proxy & Sessions

  • Add abort-on-close session configurability.
  • Support HTTP/1.1 downstream request pipelining.
  • Add cancel-safe body and header writer primitives (proxy tasks) to prevent stalled cache misses from applying backpressure.
  • Add an upstream module system and allow modules to adjust after receiving upstream response headers.
  • Add proxy warning-log suppression hooks.
  • Add keepalive-pool callbacks for tracking connection ages.
  • Expose HTTP/1.x request-body bytes accepted by the upstream writer.
  • Report point-in-time available HTTP/2 stream capacity.

🚀 Features — TLS

  • Add ability to configure an offload thread pool for downstream TLS handshakes.
  • Add Acceptor::from_server_config for runtime-built rustls ServerConfig values and in-memory key material.
  • Export TLS keying material, including from pingora-s2n.
  • Add per-peer CA configuration.
  • Add a pre-TLS callback for PROXY protocol support.
  • Expose the rustls certificate type.
  • Add curve and second-keyshare settings to HttpPeer hashing.
  • Avoid compiling aws-lc-rs when the ring provider is selected.

🚀 Features — Server, Runtime & Load Balancing

... (truncated)

Commits
  • 702f690 Update changelog for 0.9.0
  • 13ad329 Bump pingora to version 0.9.0
  • b01edce Shard the HttpProxy shutdown Notify to cut lock contention
  • accfac0 report available H2 stream capacity
  • 1ed40d4 Prevent reuse after incomplete H1 responses
  • b7ef13e Fix racy closes_only_unclaimed_fds tests
  • 9c9acc3 Let a purge expire an asset instead of deleting it
  • 6fa3835 Update default error_while_proxy retry conditions
  • ee78ceb Represent the raw request-target as a single value
  • baf4fe5 Parse non-origin-form request targets without mangling the URI
  • Additional commits viewable in compare view

Updates pingora-proxy from 0.8.1 to 0.9.0

Release notes

Sourced from pingora-proxy's releases.

Pingora 0.9.0

0.9.0 - 2026-09-04

✨ Highlights

  • Reworked connection pooling with sharded storage and a true global LRU, addressing stale entries and race windows.
  • Added an upstream module system that applies before upstream compression.
  • More handling of HTTP parsing and framing edge cases, including non-origin-form request-target preservation, and hop-by-hop header sanitization, obsolete line-fold normalization, stricter request-target validation, and bounded default HTTP/2 limits.
  • Split Prometheus integration into the pingora-prometheus crate and made Prometheus optional.
  • Improved graceful shutdown and upgrade behavior, including responsive load-balancer shutdown, descriptor lifecycle fixes, and lower shutdown-notification contention.

⚠️ Potential Breaking Changes

  • Minimum supported Rust version moves to 1.85 for some crates. pingora-foundations declares an MSRV of 1.88.
  • RequestHeader and ResponseHeader no longer implement DerefMut because unrestricted mutation could violate internal invariants.
  • Removed async_write_vec APIs; consumers should use tokio::io::AsyncWriteExt::write_all_buf.
  • Prometheus integration moved from pingora-core to the separate pingora-prometheus crate; Prometheus is optional.
  • tracing is now optional in pingora-cache.
  • Upgraded to the boring-rs 5.x API.
  • PeerOptions::curve now uses Cow.
  • Upstream requests strip hop-by-hop and Connection-nominated headers by default; legacy behavior requires explicit compatibility settings.
  • Default HTTP/2 server limits are bounded rather than unbounded.
  • Removed the unused LruShard Default implementation and lifted Default bounds on sharded cache structures.
  • Removed the CacheKey namespace parameter.
  • PurgeOutcome enum gains an Expired variant.
  • ForcedFreshness and hit-status reporting gain ForceExpiredServeStale variant.

🚀 Features — Proxy & Sessions

  • Add abort-on-close session configurability.
  • Support HTTP/1.1 downstream request pipelining.
  • Add cancel-safe body and header writer primitives (proxy tasks) to prevent stalled cache misses from applying backpressure.
  • Add an upstream module system and allow modules to adjust after receiving upstream response headers.
  • Add proxy warning-log suppression hooks.
  • Add keepalive-pool callbacks for tracking connection ages.
  • Expose HTTP/1.x request-body bytes accepted by the upstream writer.
  • Report point-in-time available HTTP/2 stream capacity.

🚀 Features — TLS

  • Add ability to configure an offload thread pool for downstream TLS handshakes.
  • Add Acceptor::from_server_config for runtime-built rustls ServerConfig values and in-memory key material.
  • Export TLS keying material, including from pingora-s2n.
  • Add per-peer CA configuration.
  • Add a pre-TLS callback for PROXY protocol support.
  • Expose the rustls certificate type.
  • Add curve and second-keyshare settings to HttpPeer hashing.
  • Avoid compiling aws-lc-rs when the ring provider is selected.

🚀 Features — Server, Runtime & Load Balancing

... (truncated)

Changelog

Sourced from pingora-proxy's changelog.

0.9.0 - 2026-09-04

✨ Highlights

  • Reworked connection pooling with sharded storage and a true global LRU, addressing stale entries and race windows.
  • Added an upstream module system that applies before upstream compression.
  • More handling of HTTP parsing and framing edge cases, including non-origin-form request-target preservation, and hop-by-hop header sanitization, obsolete line-fold normalization, stricter request-target validation, and bounded default HTTP/2 limits.
  • Split Prometheus integration into the pingora-prometheus crate and made Prometheus optional.
  • Improved graceful shutdown and upgrade behavior, including responsive load-balancer shutdown, descriptor lifecycle fixes, and lower shutdown-notification contention.

⚠️ Potential Breaking Changes

  • Minimum supported Rust version moves to 1.85 for some crates. pingora-foundations declares an MSRV of 1.88.
  • RequestHeader and ResponseHeader no longer implement DerefMut because unrestricted mutation could violate internal invariants.
  • Removed async_write_vec APIs; consumers should use tokio::io::AsyncWriteExt::write_all_buf.
  • Prometheus integration moved from pingora-core to the separate pingora-prometheus crate; Prometheus is optional.
  • tracing is now optional in pingora-cache.
  • Upgraded to the boring-rs 5.x API.
  • PeerOptions::curve now uses Cow.
  • Upstream requests strip hop-by-hop and Connection-nominated headers by default; legacy behavior requires explicit compatibility settings.
  • Default HTTP/2 server limits are bounded rather than unbounded.
  • Removed the unused LruShard Default implementation and lifted Default bounds on sharded cache structures.
  • Removed the CacheKey namespace parameter.
  • PurgeOutcome enum gains an Expired variant.
  • ForcedFreshness and hit-status reporting gain ForceExpiredServeStale variant.

🚀 Features — Proxy & Sessions

  • Add abort-on-close session configurability.
  • Support HTTP/1.1 downstream request pipelining.
  • Add cancel-safe body and header writer primitives (proxy tasks) to prevent stalled cache misses from applying backpressure.
  • Add an upstream module system and allow modules to adjust after receiving upstream response headers.
  • Add proxy warning-log suppression hooks.
  • Add keepalive-pool callbacks for tracking connection ages.
  • Expose HTTP/1.x request-body bytes accepted by the upstream writer.
  • Report point-in-time available HTTP/2 stream capacity.

🚀 Features — TLS

  • Add ability to configure an offload thread pool for downstream TLS handshakes.
  • Add Acceptor::from_server_config for runtime-built rustls ServerConfig values and in-memory key material.
  • Export TLS keying material, including from pingora-s2n.
  • Add per-peer CA configuration.
  • Add a pre-TLS callback for PROXY protocol support.
  • Expose the rustls certificate type.
  • Add curve and second-keyshare settings to HttpPeer hashing.
  • Avoid compiling aws-lc-rs when the ring provider is selected.

🚀 Features — Server, Runtime & Load Balancing

... (truncated)

Commits
  • 702f690 Update changelog for 0.9.0
  • 13ad329 Bump pingora to version 0.9.0
  • b01edce Shard the HttpProxy shutdown Notify to cut lock contention
  • accfac0 report available H2 stream capacity
  • 1ed40d4 Prevent reuse after incomplete H1 responses
  • b7ef13e Fix racy closes_only_unclaimed_fds tests
  • 9c9acc3 Let a purge expire an asset instead of deleting it
  • 6fa3835 Update default error_while_proxy retry conditions
  • ee78ceb Represent the raw request-target as a single value
  • baf4fe5 Parse non-origin-form request targets without mangling the URI
  • Additional commits viewable in compare view

Updates pingora-http from 0.8.1 to 0.9.0

Release notes

Sourced from pingora-http's releases.

Pingora 0.9.0

0.9.0 - 2026-09-04

✨ Highlights

  • Reworked connection pooling with sharded storage and a true global LRU, addressing stale entries and race windows.
  • Added an upstream module system that applies before upstream compression.
  • More handling of HTTP parsing and framing edge cases, including non-origin-form request-target preservation, and hop-by-hop header sanitization, obsolete line-fold normalization, stricter request-target validation, and bounded default HTTP/2 limits.
  • Split Prometheus integration into the pingora-prometheus crate and made Prometheus optional.
  • Improved graceful shutdown and upgrade behavior, including responsive load-balancer shutdown, descriptor lifecycle fixes, and lower shutdown-notification contention.

⚠️ Potential Breaking Changes

  • Minimum supported Rust version moves to 1.85 for some crates. pingora-foundations declares an MSRV of 1.88.
  • RequestHeader and ResponseHeader no longer implement DerefMut because unrestricted mutation could violate internal invariants.
  • Removed async_write_vec APIs; consumers should use tokio::io::AsyncWriteExt::write_all_buf.
  • Prometheus integration moved from pingora-core to the separate pingora-prometheus crate; Prometheus is optional.
  • tracing is now optional in pingora-cache.
  • Upgraded to the boring-rs 5.x API.
  • PeerOptions::curve now uses Cow.
  • Upstream requests strip hop-by-hop and Connection-nominated headers by default; legacy behavior requires explicit compatibility settings.
  • Default HTTP/2 server limits are bounded rather than unbounded.
  • Removed the unused LruShard Default implementation and lifted Default bounds on sharded cache structures.
  • Removed the CacheKey namespace parameter.
  • PurgeOutcome enum gains an Expired variant.
  • ForcedFreshness and hit-status reporting gain ForceExpiredServeStale variant.

🚀 Features — Proxy & Sessions

  • Add abort-on-close session configurability.
  • Support HTTP/1.1 downstream request pipelining.
  • Add cancel-safe body and header writer primitives (proxy tasks) to prevent stalled cache misses from applying backpressure.
  • Add an upstream module system and allow modules to adjust after receiving upstream response headers.
  • Add proxy warning-log suppression hooks.
  • Add keepalive-pool callbacks for tracking connection ages.
  • Expose HTTP/1.x request-body bytes accepted by the upstream writer.
  • Report point-in-time available HTTP/2 stream capacity.

🚀 Features — TLS

  • Add ability to configure an offload thread pool for downstream TLS handshakes.
  • Add Acceptor::from_server_config for runtime-built rustls ServerConfig values and in-memory key material.
  • Export TLS keying material, including from pingora-s2n.
  • Add per-peer CA configuration.
  • Add a pre-TLS callback for PROXY protocol support.
  • Expose the rustls certificate type.
  • Add curve and second-keyshare settings to HttpPeer hashing.
  • Avoid compiling aws-lc-rs when the ring provider is selected.

🚀 Features — Server, Runtime & Load Balancing

... (truncated)

Changelog

Sourced from pingora-http's changelog.

0.9.0 - 2026-09-04

✨ Highlights

  • Reworked connection pooling with sharded storage and a true global LRU, addressing stale entries and race windows.
  • Added an upstream module system that applies before upstream compression.
  • More handling of HTTP parsing and framing edge cases, including non-origin-form request-target preservation, and hop-by-hop header sanitization, obsolete line-fold normalization, stricter request-target validation, and bounded default HTTP/2 limits.
  • Split Prometheus integration into the pingora-prometheus crate and made Prometheus optional.
  • Improved graceful shutdown and upgrade behavior, including responsive load-balancer shutdown, descriptor lifecycle fixes, and lower shutdown-notification contention.

⚠️ Potential Breaking Changes

  • Minimum supported Rust version moves to 1.85 for some crates. pingora-foundations declares an MSRV of 1.88.
  • RequestHeader and ResponseHeader no longer implement DerefMut because unrestricted mutation could violate internal invariants.
  • Removed async_write_vec APIs; consumers should use tokio::io::AsyncWriteExt::write_all_buf.
  • Prometheus integration moved from pingora-core to the separate pingora-prometheus crate; Prometheus is optional.
  • tracing is now optional in pingora-cache.
  • Upgraded to the boring-rs 5.x API.
  • PeerOptions::curve now uses Cow.
  • Upstream requests strip hop-by-hop and Connection-nominated headers by default; legacy behavior requires explicit compatibility settings.
  • Default HTTP/2 server limits are bounded rather than unbounded.
  • Removed the unused LruShard Default implementation and lifted Default bounds on sharded cache structures.
  • Removed the CacheKey namespace parameter.
  • PurgeOutcome enum gains an Expired variant.
  • ForcedFreshness and hit-status reporting gain ForceExpiredServeStale variant.

🚀 Features — Proxy & Sessions

  • Add abort-on-close session configurability.
  • Support HTTP/1.1 downstream request pipelining.
  • Add cancel-safe body and header writer primitives (proxy tasks) to prevent stalled cache misses from applying backpressure.
  • Add an upstream module system and allow modules to adjust after receiving upstream response headers.
  • Add proxy warning-log suppression hooks.
  • Add keepalive-pool callbacks for tracking connection ages.
  • Expose HTTP/1.x request-body bytes accepted by the upstream writer.
  • Report point-in-time available HTTP/2 stream capacity.

🚀 Features — TLS

  • Add ability to configure an offload thread pool for downstream TLS handshakes.
  • Add Acceptor::from_server_config for runtime-built rustls ServerConfig values and in-memory key material.
  • Export TLS keying material, including from pingora-s2n.
  • Add per-peer CA configuration.
  • Add a pre-TLS callback for PROXY protocol support.
  • Expose the rustls certificate type.
  • Add curve and second-keyshare settings to HttpPeer hashing.
  • Avoid compiling aws-lc-rs when the ring provider is selected.

🚀 Features — Server, Runtime & Load Balancing

... (truncated)

Commits
  • 702f690 Update changelog for 0.9.0
  • 13ad329 Bump pingora to version 0.9.0
  • b01edce Shard the HttpProxy shutdown Notify to cut lock contention
  • accfac0 report available H2 stream capacity
  • 1ed40d4 Prevent reuse after incomplete H1 responses
  • b7ef13e Fix racy closes_only_unclaimed_fds tests
  • 9c9acc3 Let a purge expire an asset instead of deleting it
  • 6fa3835 Update default error_while_proxy retry conditions
  • ee78ceb Represent the raw request-target as a single value
  • baf4fe5 Parse non-origin-form request targets without mangling the URI
  • Additional commits viewable in compare view

Updates pingora-openssl from 0.8.1 to 0.9.0

Release notes

Sourced from pingora-openssl's releases.

Pingora 0.9.0

0.9.0 - 2026-09-04

✨ Highlights

  • Reworked connection pooling with sharded storage and a true global LRU, addressing stale entries and race windows.
  • Added an upstream module system that applies before upstream compression.
  • More handling of HTTP parsing and framing edge cases, including non-origin-form request-target preservation, and hop-by-hop header sanitization, obsolete line-fold normalization, stricter request-target validation, and bounded default HTTP/2 limits.
  • Split Prometheus integration into the pingora-prometheus crate and made Prometheus optional.
  • Improved graceful shutdown and upgrade behavior, including responsive load-balancer shutdown, descriptor lifecycle fixes, and lower shutdown-notification contention.

⚠️ Potential Breaking Changes

  • Minimum supported Rust version moves to 1.85 for some crates. pingora-foundations declares an MSRV of 1.88.
  • RequestHeader and ResponseHeader no longer implement DerefMut because unrestricted mutation could violate internal invariants.
  • Removed async_write_vec APIs; consumers should use tokio::io::AsyncWriteExt::write_all_buf.
  • Prometheus integration moved from pingora-core to the separate pingora-prometheus crate; Prometheus is optional.
  • tracing is now optional in pingora-cache.
  • Upgraded to the boring-rs 5.x API.
  • PeerOptions::curve now uses Cow.
  • Upstream requests strip hop-by-hop and Connection-nominated headers by default; legacy behavior requires explicit compatibility settings.
  • Default HTTP/2 server limits are bounded rather than unbounded.
  • Removed the unused LruShard Default implementation and lifted Default bounds on sharded cache structures.
  • Removed the CacheKey namespace parameter.
  • PurgeOutcome enum gains an Expired variant.
  • ForcedFreshness and hit-status reporting gain ForceExpiredServeStale variant.

🚀 Features — Proxy & Sessions

  • Add abort-on-close session configurability.
  • Support HTTP/1.1 downstream request pipelining.
  • Add cancel-safe body and header writer primitives (proxy tasks) to prevent stalled cache misses from applying backpressure.
  • Add an upstream module system and allow modules to adjust after receiving upstream response headers.
  • Add proxy warning-log suppression hooks.
  • Add keepalive-pool callbacks for tracking connection ages.
  • Expose HTTP/1.x request-body bytes accepted by the upstream writer.
  • Report point-in-time available HTTP/2 stream capacity.

🚀 Features — TLS

  • Add ability to configure an offload thread pool for downstream TLS handshakes.
  • Add Acceptor::from_server_config for runtime-built rustls ServerConfig values and in-memory key material.
  • Export TLS keying material, including from pingora-s2n.
  • Add per-peer CA configuration.
  • Add a pre-TLS callback for PROXY protocol support.
  • Expose the rustls certificate type.
  • Add curve and second-keyshare settings to HttpPeer hashing.
  • Avoid compiling aws-lc-rs when the ring provider is selected.

🚀 Features — Server, Runtime & Load Balancing

... (truncated)

Changelog

Sourced from pingora-openssl's changelog.

0.9.0 - 2026-09-04

✨ Highlights

  • Reworked connection pooling with sharded storage and a true global LRU, addressing stale entries and race windows.
  • Added an upstream module system that applies before upstream compression.
  • More handling of HTTP parsing and framing edge cases, including non-origin-form request-target preservation, and hop-by-hop header sanitization, obsolete line-fold normalization, stricter request-target validation, and bounded default HTTP/2 limits.
  • Split Prometheus integration into the pingora-prometheus crate and made Prometheus optional.
  • Improved graceful shutdown and upgrade behavior, including responsive load-balancer shutdown, descriptor lifecycle fixes, and lower shutdown-notification contention.

⚠️ Potential Breaking Changes

  • Minimum supported Rust version moves to 1.85 for some crates. pingora-foundations declares an MSRV of 1.88.
  • RequestHeader and ResponseHeader no longer implement DerefMut because unrestricted mutation could violate internal invariants.
  • Removed async_write_vec APIs; consumers should use tokio::io::AsyncWriteExt::write_all_buf.
  • Prometheus integration moved from pingora-core to the separate pingora-prometheus crate; Prometheus is optional.
  • tracing is now optional in pingora-cache.
  • Upgraded to the boring-rs 5.x API.
  • PeerOptions::curve now uses Cow.
  • Upstream requests strip hop-by-hop and Connection-nominated headers by default; legacy behavior requires explicit compatibility settings.
  • Default HTTP/2 server limits are bounded rather than unbounded.
  • Removed the unused LruShard Default implementation and lifted Default bounds on sharded cache structures.
  • Removed the CacheKey namespace parameter.
  • PurgeOutcome enum gains an Expired variant.
  • ForcedFreshness and hit-status reporting gain ForceExpiredServeStale variant.

🚀 Features — Proxy & Sessions

  • Add abort-on-close session configurability.
  • Support HTTP/1.1 downstream request pipelining.
  • Add cancel-safe body and header writer primitives (proxy tasks) to prevent stalled cache misses from applying backpressure.
  • Add an upstream module system and allow modules to adjust after receiving upstream response headers.
  • Add proxy warning-log suppression hooks.
  • Add keepalive-pool callbacks for tracking connection ages.
  • Expose HTTP/1.x request-body bytes accepted by the upstream writer.
  • Report point-in-time available HTTP/2 stream capacity.

🚀 Features — TLS

  • Add ability to configure an offload thread pool for downstream TLS handshakes.
  • Add Acceptor::from_server_config for runtime-built rustls ServerConfig values and in-memory key material.
  • Export TLS keying material, including from pingora-s2n.
  • Add per-peer CA configuration.
  • Add a pre-TLS callback for PROXY protocol support.
  • Expose the rustls certificate type.
  • Add curve and second-keyshare settings to HttpPeer hashing.
  • Avoid compiling aws-lc-rs when the ring provider is selected.

🚀 Features — Server, Runtime & Load Balancing

... (truncated)

Commits
  • 702f690 Update changelog for 0.9.0
  • 13ad329 Bump pingora to version 0.9.0
  • b01edce Shard the HttpProxy shutdown Notify to cut lock contention
  • accfac0 report available H2 stream capacity
  • 1ed40d4 Prevent reuse after incomplete H1 responses
  • b7ef13e Fix racy closes_only_unclaimed_fds tests
  • 9c9acc3 Let a purge expire an asset instead of deleting it
  • 6fa3835 Update default error_while_proxy retry conditions
  • ee78ceb Represent the raw request-target as a single value
  • baf4fe5 Parse non-origin-form request targets without mangling the URI
  • Additional commits viewable in compare view

Updates uuid from 1.24.1 to 1.26.1

Release notes

Sourced from uuid's releases.

v1.26.1

What's Changed

New Contributors

Full Changelog: uuid-rs/uuid@v1.26.0...v1.26.1

v1.26.0

What's Changed

Full Changelog: uuid-rs/uuid@1.25.0...v1.26.0

1.25.0

What's Changed

New Contributors

Full Changelog: uuid-rs/uuid@v1.24.1...1.25.0

Commits
  • 9f92712 Merge pull request #910 from uuid-rs/cargo/v1.26.1
  • d4df8f0 prepare for 1.26.1 release
  • 5613f23 Merge pull request #909 from uuid-rs/fix/ts-conversion-overflow
  • fda00eb don't panic in overflowing Timestamp to SystemTime conversion
  • c82e88c Merge pull request #907 from lenamonj/v7-counter-placement
  • ac065a6 Align the counter diagram
  • 34ec102 Seat the v7 counter below the version nibble
  • cdc96a8 Merge pull request #905 from uuid-rs/cargo/v1.26.0
  • 34e4f49 don't test macros under miri
  • d9e7242 update nightly used for miri
  • Additional commits viewable in compare view

Updates rcgen from 0.14.9 to 0.14.10

Release notes

Sourced from rcgen's releases.

0.14.10

What's Changed

Commits
  • f4a3b16 Bump version to 0.14.10
  • dea3d4d Upgrade to botan 0.13
  • 788b093 Upgrade to pem 4
  • 7ce21f4 Take advantage of stable ML-DSA in aws-lc-rs
  • e2dba45 Remove unused RSASSA-PSS signature algorithm
  • 37070de Omit reasonCode unspecified(0) from CRL entry extensions
  • b247a87 Write extensions for certs that only set KeyUsage or CRLDP
  • 85eafdd Reject empty CRL distribution point URIs
  • 3a99b50 Encode CRL invalidityDate as GeneralizedTime
  • See full diff in compare view

Updates reqwest from 0.13.4 to 0.13.5

Release notes

Sourced from reqwest's releases.

v0.13.5

tl;dr

  • Add Error::is_dns() to identify errors caused by DNS resolution failures.
  • Add ClientBuilder::http1_max_headers(usize) to configure the maximum number of headers accepted in an HTTP/1 response (default 100).
  • Add TLS version to TlsInfo extension.
  • Fix hickory-dns feature to use Ip...

    Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update Rust code labels Sep 22, 2026
Bumps the cargo group with 16 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [toml](https://github.com/toml-rs/toml) | `1.1.4+spec-1.1.0` | `1.1.6+spec-1.1.0` |
| [diesel](https://github.com/diesel-rs/diesel) | `2.3.12` | `2.3.13` |
| [clap](https://github.com/clap-rs/clap) | `4.6.6` | `4.6.7` |
| [aes-gcm](https://github.com/RustCrypto/AEADs) | `0.11.0` | `0.11.1` |
| [tun-rs](https://github.com/tun-rs/tun-rs) | `2.8.8` | `2.8.10` |
| [tokio-rustls](https://github.com/rustls/tokio-rustls) | `0.26.4` | `0.26.5` |
| [pingora-core](https://github.com/cloudflare/pingora) | `0.8.1` | `0.9.0` |
| [pingora-proxy](https://github.com/cloudflare/pingora) | `0.8.1` | `0.9.0` |
| [pingora-http](https://github.com/cloudflare/pingora) | `0.8.1` | `0.9.0` |
| [pingora-openssl](https://github.com/cloudflare/pingora) | `0.8.1` | `0.9.0` |
| [uuid](https://github.com/uuid-rs/uuid) | `1.24.1` | `1.26.1` |
| [rcgen](https://github.com/rustls/rcgen) | `0.14.9` | `0.14.10` |
| [reqwest](https://github.com/seanmonstar/reqwest) | `0.13.4` | `0.13.5` |
| [quick-xml](https://github.com/tafia/quick-xml) | `0.41.0` | `0.42.0` |
| [aws-sdk-route53](https://github.com/awslabs/aws-sdk-rust) | `1.119.0` | `1.122.0` |
| [argon2](https://github.com/RustCrypto/password-hashes) | `0.5.3` | `0.6.0` |



Updates `toml` from 1.1.4+spec-1.1.0 to 1.1.6+spec-1.1.0
- [Commits](toml-rs/toml@toml-v1.1.4...toml-v1.1.6)

Updates `diesel` from 2.3.12 to 2.3.13
- [Release notes](https://github.com/diesel-rs/diesel/releases)
- [Changelog](https://github.com/diesel-rs/diesel/blob/main/CHANGELOG.md)
- [Commits](diesel-rs/diesel@v2.3.12...v2.3.13)

Updates `clap` from 4.6.6 to 4.6.7
- [Release notes](https://github.com/clap-rs/clap/releases)
- [Changelog](https://github.com/clap-rs/clap/blob/main/CHANGELOG.md)
- [Commits](clap-rs/clap@clap_complete-v4.6.6...clap_complete-v4.6.7)

Updates `aes-gcm` from 0.11.0 to 0.11.1
- [Commits](RustCrypto/AEADs@aes-gcm-v0.11.0...aes-gcm-v0.11.1)

Updates `tun-rs` from 2.8.8 to 2.8.10
- [Release notes](https://github.com/tun-rs/tun-rs/releases)
- [Commits](tun-rs/tun-rs@2.8.8...2.8.10)

Updates `tokio-rustls` from 0.26.4 to 0.26.5
- [Release notes](https://github.com/rustls/tokio-rustls/releases)
- [Commits](rustls/tokio-rustls@v/0.26.4...v/0.26.5)

Updates `pingora-core` from 0.8.1 to 0.9.0
- [Release notes](https://github.com/cloudflare/pingora/releases)
- [Changelog](https://github.com/cloudflare/pingora/blob/main/CHANGELOG.md)
- [Commits](cloudflare/pingora@0.8.1...0.9.0)

Updates `pingora-proxy` from 0.8.1 to 0.9.0
- [Release notes](https://github.com/cloudflare/pingora/releases)
- [Changelog](https://github.com/cloudflare/pingora/blob/main/CHANGELOG.md)
- [Commits](cloudflare/pingora@0.8.1...0.9.0)

Updates `pingora-http` from 0.8.1 to 0.9.0
- [Release notes](https://github.com/cloudflare/pingora/releases)
- [Changelog](https://github.com/cloudflare/pingora/blob/main/CHANGELOG.md)
- [Commits](cloudflare/pingora@0.8.1...0.9.0)

Updates `pingora-openssl` from 0.8.1 to 0.9.0
- [Release notes](https://github.com/cloudflare/pingora/releases)
- [Changelog](https://github.com/cloudflare/pingora/blob/main/CHANGELOG.md)
- [Commits](cloudflare/pingora@0.8.1...0.9.0)

Updates `uuid` from 1.24.1 to 1.26.1
- [Release notes](https://github.com/uuid-rs/uuid/releases)
- [Commits](uuid-rs/uuid@v1.24.1...v1.26.1)

Updates `rcgen` from 0.14.9 to 0.14.10
- [Release notes](https://github.com/rustls/rcgen/releases)
- [Commits](rustls/rcgen@v/0.14.9...v0.14.10)

Updates `reqwest` from 0.13.4 to 0.13.5
- [Release notes](https://github.com/seanmonstar/reqwest/releases)
- [Changelog](https://github.com/seanmonstar/reqwest/blob/master/CHANGELOG.md)
- [Commits](seanmonstar/reqwest@v0.13.4...v0.13.5)

Updates `quick-xml` from 0.41.0 to 0.42.0
- [Release notes](https://github.com/tafia/quick-xml/releases)
- [Changelog](https://github.com/tafia/quick-xml/blob/master/Changelog.md)
- [Commits](tafia/quick-xml@v0.41.0...v0.42.0)

Updates `aws-sdk-route53` from 1.119.0 to 1.122.0
- [Release notes](https://github.com/awslabs/aws-sdk-rust/releases)
- [Commits](https://github.com/awslabs/aws-sdk-rust/commits)

Updates `argon2` from 0.5.3 to 0.6.0
- [Commits](RustCrypto/password-hashes@argon2-v0.5.3...argon2-v0.6.0)

---
updated-dependencies:
- dependency-name: aes-gcm
  dependency-version: 0.11.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: argon2
  dependency-version: 0.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo
- dependency-name: aws-sdk-route53
  dependency-version: 1.122.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo
- dependency-name: clap
  dependency-version: 4.6.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: diesel
  dependency-version: 2.3.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: pingora-core
  dependency-version: 0.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo
- dependency-name: pingora-http
  dependency-version: 0.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo
- dependency-name: pingora-openssl
  dependency-version: 0.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo
- dependency-name: pingora-proxy
  dependency-version: 0.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo
- dependency-name: quick-xml
  dependency-version: 0.42.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo
- dependency-name: rcgen
  dependency-version: 0.14.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: reqwest
  dependency-version: 0.13.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: tokio-rustls
  dependency-version: 0.26.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: toml
  dependency-version: 1.1.6+spec-1.1.0
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: tun-rs
  dependency-version: 2.8.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo
- dependency-name: uuid
  dependency-version: 1.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/cargo/main/cargo-59906b042c branch from 8de907c to 27a1cec Compare September 22, 2026 10:39
@dependabot @github

dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 29, 2026
@dependabot
dependabot Bot deleted the dependabot/cargo/main/cargo-59906b042c branch September 29, 2026 06:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update Rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants