Skip to content

Bump tar from 0.4.44 to 0.4.45#207

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/cargo/tar-0.4.45
Open

Bump tar from 0.4.44 to 0.4.45#207
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/cargo/tar-0.4.45

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Mar 20, 2026

Bumps tar from 0.4.44 to 0.4.45.

Commits
  • 096e3d1 Bump to 0.4.45 (#443)
  • 17b1fd8 archive: Prevent symlink-directory collision chmod attack (#442)
  • de1a587 archive: Unconditionally honor PAX size (#441)
  • 6071cbe ci: Consolidate workflows (#439)
  • ad1fde9 build-sys: Promote unused_code to an error
  • c8cb250 tests: Squash a warning
  • 638c495 ci: Add xtask infra + reverse dependency testing (#435)
  • 32a9bbb tests: Add RandomReader to exercise partial-read resilience (#436)
  • 9c5df0b Fix GNU long-name extension stream corruption on validation error (#434)
  • 88b1e3b Fix docs typo in header.rs (#431)
  • Additional commits viewable in compare view


Note

Low Risk
Lockfile-only dependency bump; main impact is updated transitive crates (notably windows-sys/windows-targets versions) which could affect Windows builds but doesn’t change project code.

Overview
Updates the tar crate from 0.4.44 to 0.4.45 in Cargo.lock.

This refresh also rewires several transitive dependencies, primarily standardizing multiple crates to use older windows-sys/windows-targets versions (and adding an additional windows-sys entry for stacker).

Reviewed by Cursor Bugbot for commit 4cb54a7. Bugbot is set up for automated code reviews on this repo. Configure here.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Mar 20, 2026
@vercel
Copy link
Copy Markdown

vercel Bot commented Mar 20, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
runmat Ready Ready Preview, Comment, Open in v0 Apr 9, 2026 5:22am

Request Review

Bumps [tar](https://github.com/alexcrichton/tar-rs) from 0.4.44 to 0.4.45.
- [Commits](alexcrichton/tar-rs@0.4.44...0.4.45)

---
updated-dependencies:
- dependency-name: tar
  dependency-version: 0.4.45
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants