Skip to content

chore(deps): update salvo requirement from =0.96.0 to =1.0.0 - #22

Open
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/cargo/salvo-eq-1.0.0
Open

dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/cargo/salvo-eq-1.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on salvo to permit the latest version.

Release notes

Sourced from salvo's releases.

v1.0.0

What's Changed

Full Changelog: salvo-rs/salvo@v0.96.0...v1.0.0

Changelog

Sourced from salvo's changelog.

[1.0.0] - 2026-09-24

Security

  • Static file responses no longer serve XML-based documents inline, which allowed stored XSS when an application served attacker-supplied uploads. image/svg+xml and text/xml were classified as inline by their top-level image/text type, so an uploaded SVG carrying <script> — or an XML document naming an XSLT stylesheet through <?xml-stylesheet ?> — executed script in the serving origin when opened. XML-based content types now default to attachment, matching how application/xml and application/xhtml+xml already behaved. That covers the +xml suffix, an xml subtype, RFC 7303's xml-dtd and xml-external-parsed-entity, and the legacy text/xsl that <?xml-stylesheet ?> itself names. text/html still defaults to inline. Reported by sl91994.
  • NamedFile and StaticEmbed responses now carry X-Content-Type-Options: nosniff.
  • salvo-otel no longer records the full request URI. Metrics dropped url.full entirely, so query strings no longer become metric dimensions. Tracing replaced it with url.path plus a url.query whose sig, Signature, AWSAccessKeyId and X-Goog-Signature values are redacted, as the semantic conventions require.

Added

  • NamedFileBuilder::use_content_type_options and NamedFile::use_content_type_options to control the X-Content-Type-Options header.
  • StaticDir::disposition_type, StaticDir::use_content_type_options, StaticFile::disposition_type, StaticFile::attached_name and StaticFile::use_content_type_options, so applications serving trusted assets can opt back into inline rendering, which previously had no public API on either handler.
  • NamedFileBuilder::disposition_name, which sets the name Content-Disposition reports without forcing the disposition to attachment the way attached_name does.
  • Cookie extractors now support structured JSON values. CookieParam<T> falls back to JSON when scalar conversion fails, while #[derive(Extractible)] accepts explicit cookie field sources such as #[salvo(extract(source(from = "cookie", parse = "json")))].
  • Changelog established for upcoming releases.
  • Opt-in RFC 9457 Problem Details responses with typed extension members and OpenAPI integration via the rfc9457 feature.
  • Initial opt-in OpenAPI 3.2 document support in salvo-oapi, including the $self field.
  • OpenAPI 3.2 object model in salvo-oapi:
    • Tag Object summary, parent and kind.
    • Server Object name.
    • Path Item Object query (via PathItemType::Query) and additionalOperations.
    • Parameter Object in: querystring (ParameterIn::QueryString) and style: cookie (ParameterStyle::Cookie).
    • Media Type Object itemSchema, prefixEncoding and itemEncoding.
    • Encoding Object nested encoding, prefixEncoding and itemEncoding.
    • Example Object dataValue and serializedValue.
    • Response Object summary, and description is now optional on input.
    • Components Object mediaTypes.
    • Discriminator Object defaultMapping.
    • XML Object nodeType (new XmlNodeType enum).
    • Security Scheme Object deprecated and oauth2MetadataUrl.

... (truncated)

Commits
  • bab1a7c Release 1.0.0
  • fcff5db build(deps): upgrade OpenTelemetry crates to 0.33 together (#1709)
  • 6aec86a fix(serve-static): block paths beneath dot directories (#1708)
  • 9beb091 build(deps): update zstd requirement from 0.13 to 0.14 (#1703)
  • ca0748a feat(otel)!: follow the OpenTelemetry HTTP semantic conventions (#1700)
  • 568afd4 Upgrade certon to 0.3 (#1702)
  • 51be293 build(deps): update brotli requirement from 8 to 9 (#1701)
  • 8f5d643 fix(tls): pass the rustls CryptoProvider explicitly instead of relying on cra...
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [salvo](https://github.com/salvo-rs/salvo) to permit the latest version.
- [Release notes](https://github.com/salvo-rs/salvo/releases)
- [Changelog](https://github.com/salvo-rs/salvo/blob/main/CHANGELOG.md)
- [Commits](salvo-rs/salvo@v0.96.0...v1.0.0)

---
updated-dependencies:
- dependency-name: salvo
  dependency-version: 1.0.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, rust. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants