Skip to content

chore(deps): bump the cargo group across 1 directory with 2 updates - #736

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/src-tauri/cargo-eab70290d7
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/src-tauri/cargo-eab70290d7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the cargo group with 2 updates in the /src-tauri directory: dirs and rmcp.

Updates dirs from 6.0.0 to 7.0.0

Updates rmcp from 3.4.0 to 3.5.0

Release notes

Sourced from rmcp's releases.

rmcp-macros-v3.5.0

Fixed

  • (macros) accept const paths and concat! in tool/prompt descriptions (#1243)

rmcp-v3.5.0

Added

  • update LATEST and add LATEST_WITH_INITIALIZE (#1105)

Fixed

  • (model) decode float fields through serde_json::Number (#1300)
  • (rmcp) reject duplicate sep-2243 headers (#1274)
  • (transport) match explicit default ports in Origin allowlist (#1270)
  • (rmcp) tolerate empty cacheScope instead of silently dropping the whole result (#1281)
  • (model) preserve explicit null structuredContent in CallToolResult (#1295)

Other

  • cargo fmt fixes on validate_standard_headers changes (#1275)

rmcp-macros-v3.4.1

Fixed

  • (macros) accept const paths and concat! in tool/prompt descriptions (#1243)

rmcp-v3.4.1

Fixed

  • (transport) fall back after JSON discover rejections (#1288)
  • (macros) accept const paths and concat! in tool/prompt descriptions (#1243)

Other

  • (deps) update rstest requirement from 0.26.1 to 0.27.0 (#1276)
Commits
  • 0cde3c5 chore: release v3.5.0 (#1296)
  • e02efbf fix(model): decode float fields through serde_json::Number (#1300)
  • 972af86 feat: update LATEST and add LATEST_WITH_INITIALIZE (#1105)
  • 6e47ca3 chore(deps): bump the github-actions group with 2 updates (#1297)
  • 6255c37 chore: reduce dependency update noise (#1293)
  • 22ef52a fix(rmcp): reject duplicate sep-2243 headers (#1274)
  • 26f3b2e fix(transport): match explicit default ports in Origin allowlist (#1270)
  • 6677eee style: cargo fmt fixes on validate_standard_headers changes (#1275)
  • fbed447 fix(rmcp): tolerate empty cacheScope instead of silently dropping the whole r...
  • 90516bf fix(model): preserve explicit null structuredContent in CallToolResult (#1295)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Dependency updates rust Rust/Cargo updates labels Sep 27, 2026
EVWorth pushed a commit that referenced this pull request Oct 4, 2026
Combines the three open bot PRs, each fixed so CI can pass:

- cargo (#736): rmcp 3.3.0 -> 3.4.0. Dependabot bumped only mas-mcp, but
  the app crate pins rmcp to the same exact version, so cargo could not
  resolve. Bump both. rmcp 3.4 deprecates the ServerInfo alias in favour
  of ServerConfig; rename the three uses in mas-mcp so clippy -D warnings
  stays clean. dirs 6 -> 7 is listed in that PR's title but its diff never
  changed it, so it is left for a separate PR.
- npm (#737): the 13 group updates. jsdom 30.1.0 pulls whatwg-url 17.1.1,
  whose registry metadata advertises a provenance attestation the registry
  serves as 404, which fails `npm audit signatures`. Lock jsdom's copy at
  17.1.2 instead (same dependencies; 13 days old, inside min-release-age).
- dprint (#738): @dprint/json 0.23.0 -> 0.24.0, plus the package.json key
  order it now enforces.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg
EVWorth added a commit that referenced this pull request Oct 5, 2026
Combines the three open bot PRs, each fixed so CI can pass:

- cargo (#736): rmcp 3.3.0 -> 3.4.0. Dependabot bumped only mas-mcp, but
  the app crate pins rmcp to the same exact version, so cargo could not
  resolve. Bump both. rmcp 3.4 deprecates the ServerInfo alias in favour
  of ServerConfig; rename the three uses in mas-mcp so clippy -D warnings
  stays clean. dirs 6 -> 7 is listed in that PR's title but its diff never
  changed it, so it is left for a separate PR.
- npm (#737): the 13 group updates. jsdom 30.1.0 pulls whatwg-url 17.1.1,
  whose registry metadata advertises a provenance attestation the registry
  serves as 404, which fails `npm audit signatures`. Lock jsdom's copy at
  17.1.2 instead (same dependencies; 13 days old, inside min-release-age).
- dprint (#738): @dprint/json 0.23.0 -> 0.24.0, plus the package.json key
  order it now enforces.


Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg

Co-authored-by: Claude <noreply@anthropic.com>
@dependabot dependabot Bot changed the title chore(deps): bump the cargo group in /src-tauri with 2 updates chore(deps): bump the cargo group across 1 directory with 2 updates Oct 5, 2026
@dependabot
dependabot Bot force-pushed the dependabot/cargo/src-tauri/cargo-eab70290d7 branch from 19fcb63 to 5a84df0 Compare October 5, 2026 01:05
@dependabot
dependabot Bot force-pushed the dependabot/cargo/src-tauri/cargo-eab70290d7 branch from 5a84df0 to 8f4851d Compare October 5, 2026 03:13
Bumps the cargo group with 2 updates in the /src-tauri directory: dirs and [rmcp](https://github.com/modelcontextprotocol/rust-sdk).


Updates `dirs` from 6.0.0 to 7.0.0

Updates `rmcp` from 3.4.0 to 3.5.0
- [Release notes](https://github.com/modelcontextprotocol/rust-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/rust-sdk/blob/main/release-plz.toml)
- [Commits](modelcontextprotocol/rust-sdk@rmcp-v3.4.0...rmcp-v3.5.0)

---
updated-dependencies:
- dependency-name: dirs
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: cargo
- dependency-name: rmcp
  dependency-version: 3.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/cargo/src-tauri/cargo-eab70290d7 branch from 8f4851d to 593a06a Compare October 5, 2026 03:20
@EVWorth EVWorth closed this in #750 Oct 5, 2026
EVWorth added a commit that referenced this pull request Oct 5, 2026
… rmcp once (#750)

Two Dependabot shapes kept producing PRs that cannot pass:

- Tauri: npm and cargo were proposed separately, so a Tauri release
  arrived as npm-only (#745), which check-tauri-versions.sh fails and
  `tauri build` refuses. The plugin crates never moved at all: each new
  plugin minor requires the new `tauri`, and a per-ecosystem update
  moves one dependency at a time. A `tauri` multi-ecosystem group now
  owns @tauri-apps/* on npm and tauri, tauri-build, tauri-plugin-* on
  cargo, so both halves land in one PR. Its member entries carry the
  same 7-day cooldown and hold back majors; the regular npm and cargo
  entries ignore those names so nothing is proposed twice.
- rmcp: pinned exactly in both the app crate and crates/mas-mcp, and
  Dependabot bumped only one (#736, twice), which cannot resolve. The
  pin moves to [workspace.dependencies]; both crates inherit it, so a
  bump is one edit. The lockfile does not change.

Checked against SchemaStore's dependabot-2.0 schema (0 errors).


Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg

Co-authored-by: Claude <noreply@anthropic.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/cargo/src-tauri/cargo-eab70290d7 branch October 5, 2026 03:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates rust Rust/Cargo updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants