Uh oh!
There was an error while loading. Please reload this page.
chore(deps): bump the workspace group across 1 directory with 3 updates - #49
chore(deps): bump the workspace group across 1 directory with 3 updates#49dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the workspace group with 3 updates in the / directory: [clap](https://github.com/clap-rs/clap), [ignore](https://github.com/BurntSushi/ripgrep) and [rmcp](https://github.com/modelcontextprotocol/rust-sdk). Updates `clap` from 4.6.4 to 4.6.6 - [Release notes](https://github.com/clap-rs/clap/releases) - [Changelog](https://github.com/clap-rs/clap/blob/master/CHANGELOG.md) - [Commits](clap-rs/clap@clap_complete-v4.6.4...clap_complete-v4.6.6) Updates `ignore` from 0.4.31 to 0.4.33 - [Release notes](https://github.com/BurntSushi/ripgrep/releases) - [Changelog](https://github.com/BurntSushi/ripgrep/blob/master/CHANGELOG.md) - [Commits](BurntSushi/ripgrep@ignore-0.4.31...ignore-0.4.33) Updates `rmcp` from 3.0.1 to 3.1.2 - [Release notes](https://github.com/modelcontextprotocol/rust-sdk/releases) - [Changelog](https://github.com/modelcontextprotocol/rust-sdk/blob/main/release-plz.toml) - [Commits](modelcontextprotocol/rust-sdk@rmcp-v3.0.1...rmcp-v3.1.2) --- updated-dependencies: - dependency-name: clap dependency-version: 4.6.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: workspace - dependency-name: ignore dependency-version: 0.4.33 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: workspace - dependency-name: rmcp dependency-version: 3.1.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: workspace ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Thermos review
No medium+ findings (security/correctness + code quality).
Dependabot workspace-group Cargo.lock-only bump (+24/−36) on merge-base 68b7b2c → ec48066.
Verified
- Scope: only
Cargo.lock; crates.io checksums match for clap/clap_builder4.6.6, ignore0.4.32, rmcp/rmcp-macros3.1.2, darling0.24.0; none yanked cargo check --locked --workspaceclean; CIci+ Releaseplangreen; CodeQL skippingcargo audit: no advisories on bumped crates (pre-existing memmap2RUSTSEC-2026-0186warning only)- Production MCP path remains stdio (
OxcodeServer::new().serve(stdio())withserver/transport-io/macros); rmcp 3.1.x HTTP/SSE/auth fixes do not apply ignore0.4.32only skips loading ignore files in unvisited/max_depthdirs; oxcode uses reachableWalkBuilder::standard_filters(true).hidden(false)withoutmax_depth- clap changes are help/
get_overridden_usageonly; derive CLI unaffected
Below medium (not blocking)
- Dependabot body claims ignore
0.4.33; lock resolves0.4.32(0.4.33 is pool-capacity/perf only) - Workspace
Cargo.tomlfloors still clap4.5.53/ ignore0.4.25/ rmcp3.0.1while lock is newer via caret — normal lockfile-only Dependabot style
Sent by Cursor Automation: Find vulnerabilities
Looks like these dependencies are updatable in another way, so this is no longer needed. |


Bumps the workspace group with 3 updates in the / directory: clap, ignore and rmcp.
Updates
clapfrom 4.6.4 to 4.6.6Release notes
Sourced from clap's releases.
Changelog
Sourced from clap's changelog.
Commits
348cff3chore: Released478377docs: Update changelog04b9fbbMerge pull request #6414 from koopatroopa787/fix-bash-completion-bracket-glob7075239Merge pull request #6422 from BaumiCoder/fix-fish-indentationsf90a966fix(complete): Use spaces for indentation in fishdd4997bfix(complete): Don't glob-expand bash positionals8387c81Merge pull request #6399 from clap-rs/renovate/crate-ci-typos-1.x8141e11chore(deps): Update compatible (dev) (#6398)8a6bd4echore(deps): Update pre-commit hook crate-ci/typos to v1.47.071a7213chore(deps): Update Rust Stable to v1.96 (#6396)Updates
ignorefrom 0.4.31 to 0.4.33Commits
3fce3b5ignore-0.4.335055264globset-0.4.20020687aignore,globset: increase pool capacity5ed408eignore-0.4.32435f59fignore: skip loading unreachable ignore filesf9c05a9index: remove incorrect README8372866index: add some initial indexing scaffoldingd99ac34core: addindexmodule2ed0c00flags: disable many flags when indexing is enabledUpdates
rmcpfrom 3.0.1 to 3.1.2Release notes
Sourced from rmcp's releases.
... (truncated)
Commits
02c62aechore: release v3.1.2 (#1148)c345078fix(auth): map 401/403 challenges on the SSE GET stream (#1152)f8e6382chore(deps): bump taiki-e/install-action from 2.85.7 to 2.85.8 (#1153)8fb3e04chore(deps): bump github/codeql-action from 4.37.4 to 4.37.6 (#1154)3c8fb2afix(sse): loop instead of recursing when skipping SSE events (#1146)e150d4ffix(auth): preserve issuer trailing slash during discovery (#1145)9a3168achore(deps): bump taiki-e/install-action from 2.85.6 to 2.85.7 (#1139)baac607chore: release v3.1.1 (#1115)f57d585chore: upgrade darling and syn (#1138)07bcda2fix: emit cache hints from handler macros (#1120)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions