Conversation
1 task
dadezzz
pushed a commit
to dadezzz/kube-dns-rs
that referenced
this pull request
Sep 24, 2026
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [thiserror](https://github.com/dtolnay/thiserror) | dependencies | patch | `2.0.20` → `2.0.21` | --- ### Release Notes <details> <summary>dtolnay/thiserror (thiserror)</summary> ### [`v2.0.21`](https://github.com/dtolnay/thiserror/releases/tag/2.0.21) [Compare Source](dtolnay/thiserror@2.0.20...2.0.21) - Fix parsing of generic unit variants in display expressions ([#​459](dtolnay/thiserror#459)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTAuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjExMC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
1 task
1 task
djx-y-z
added a commit
to djx-y-z/openmls_dart
that referenced
this pull request
Sep 28, 2026
Carries Dependabot's #47 as an attributed commit instead of merging that branch. #47 was green on all twelve required contexts and still could not be merged: the `Protect main branch` ruleset sets `require_extra_approval_for_unattributed_changes: true` (with `required_approving_review_count: 0`), and the branch carried a second commit — `1c0b2b0a`, the `THIRD_PARTY_NOTICES.txt` regeneration pushed by the App token — whose `verification.verified` is false. Unsigned means unattributed, so the rule asked for a review that could not be given. Dependabot's own commit was verified; #44 and #46 had no second commit and merged without any of this. Re-committing the same two files under a signed commit satisfies the rule by making the change attributed, rather than by weakening the ruleset or by merging with administrator privileges. The contents are byte-identical to #47's head: `rust/Cargo.lock` and `THIRD_PARTY_NOTICES.txt`, taken from that branch rather than regenerated, so nothing here is a second opinion about what the bump should look like. ⚠ Why the notices file is in a `thiserror` bump at all: `verify-third-party-notices` compares the inventory against the resolved cargo graph, and Dependabot cannot run `make third-party-notices` on its own branch. That is what `refresh-notices.yml` is for, and it runs on a daily schedule rather than on `pull_request` — by design, since a Dependabot-triggered run gets a read-only token. It had not fired yet when #47 opened, which is why the pull request was red on that check until `gh workflow run refresh-notices.yml -f pr=47`. Upstream change is one line: "Fix parsing of generic unit variants in display expressions" (dtolnay/thiserror#459). No advisory — `cargo audit` names thiserror at neither version. ⚠ This moves `rust/`, so the published `openmls_frb-2.3.0` binary no longer matches these sources and stage 1 becomes required before the next package release. That is the deliberate cost, accepted because upstream openmls moves rarely and a native release cycle is not worth opening twice. Green: `make verify-third-party-notices`, `make rust-check`, `make rust-audit`, `make rust-deny`.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #332. Closes #458.