Skip to content

chore(deps): Bump lz4_flex from 0.11.5 to 0.11.6#699

Merged
duesee merged 1 commit into
mainfrom
dependabot/cargo/lz4_flex-0.11.6
Jun 3, 2026
Merged

chore(deps): Bump lz4_flex from 0.11.5 to 0.11.6#699
duesee merged 1 commit into
mainfrom
dependabot/cargo/lz4_flex-0.11.6

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Mar 16, 2026

Bumps lz4_flex from 0.11.5 to 0.11.6.

Changelog

Sourced from lz4_flex's changelog.

0.11.6 (2026-03-14)

Security Fix

Invalid match offsets (offset == 0) during decompression were not properly
handled, which could lead to invalid memory reads on untrusted input.
Users on 0.11.x should upgrade to 0.11.6.
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update Rust code labels Mar 16, 2026
@coveralls
Copy link
Copy Markdown
Collaborator

coveralls commented Mar 16, 2026

Coverage Report for CI Build 26914491554

Coverage remained the same at 91.358%

Details

  • Coverage remained the same as the base build.
  • Patch coverage: No coverable lines changed in this PR.
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 11594
Covered Lines: 10592
Line Coverage: 91.36%
Coverage Strength: 917.01 hits per line

💛 - Coveralls

@duesee duesee force-pushed the dependabot/cargo/lz4_flex-0.11.6 branch from 0054037 to b914354 Compare June 2, 2026 18:28
@duesee
Copy link
Copy Markdown
Owner

duesee commented Jun 3, 2026

@dependabot rebase

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Jun 3, 2026

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@duesee
Copy link
Copy Markdown
Owner

duesee commented Jun 3, 2026

@dependabot recreate

Bumps [lz4_flex](https://github.com/pseitz/lz4_flex) from 0.11.5 to 0.11.6.
- [Release notes](https://github.com/pseitz/lz4_flex/releases)
- [Changelog](https://github.com/PSeitz/lz4_flex/blob/main/CHANGELOG.md)
- [Commits](PSeitz/lz4_flex@0.11.5...0.11.6)

---
updated-dependencies:
- dependency-name: lz4_flex
  dependency-version: 0.11.6
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/cargo/lz4_flex-0.11.6 branch from b914354 to a77488e Compare June 3, 2026 21:35
@duesee duesee merged commit e2c8ab2 into main Jun 3, 2026
10 checks passed
@duesee duesee deleted the dependabot/cargo/lz4_flex-0.11.6 branch June 3, 2026 21:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update Rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants