Skip to content

chore(deps): bump tar from 0.4.45 to 0.4.46 in the cargo group across 1 directory - #423

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-8529595794
Closed

chore(deps): bump tar from 0.4.45 to 0.4.46 in the cargo group across 1 directory#423
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-8529595794

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the cargo group with 1 update in the / directory: tar.

Updates tar from 0.4.45 to 0.4.46

Release notes

Sourced from tar's releases.

0.4.46

Security

See also GHSA-3cv2-h65g-fgmm

Other changes

New Contributors

Full Changelog: composefs/tar-rs@0.4.45...0.4.46

Commits


Note

Low Risk
Lockfile-only dependency bump with a targeted archive parsing security fix; no source changes, though tar handling of malicious archives is security-sensitive.

Overview
Bumps the transitive tar crate from 0.4.45 to 0.4.46 via Cargo.lock only (Dependabot cargo group).

The meaningful change is adopting 0.4.46, which includes a security fix for PAX header desync (GHSA-3cv2-h65g-fgmm). The rest of the lockfile diff is collateral windows-sys version resolution churn for unrelated crates, not direct application code changes.

Reviewed by Cursor Bugbot for commit 6a27be2. Bugbot is set up for automated code reviews on this repo. Configure here.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Jun 4, 2026
Bumps the cargo group with 1 update in the / directory: [tar](https://github.com/composefs/tar-rs).


Updates `tar` from 0.4.45 to 0.4.46
- [Release notes](https://github.com/composefs/tar-rs/releases)
- [Commits](composefs/tar-rs@0.4.45...0.4.46)

---
updated-dependencies:
- dependency-name: tar
  dependency-version: 0.4.46
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/cargo/cargo-8529595794 branch from f09c462 to 6a27be2 Compare June 10, 2026 13:24
@paolodamico

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Looks like tar is no longer updatable, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 1, 2026
@dependabot
dependabot Bot deleted the dependabot/cargo/cargo-8529595794 branch September 1, 2026 19:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants