Skip to content

build(deps): bump tar from 0.4.44 to 0.4.45#31

Closed
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/cargo/tar-0.4.45
Closed

build(deps): bump tar from 0.4.44 to 0.4.45#31
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/cargo/tar-0.4.45

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 24, 2026

Bumps tar from 0.4.44 to 0.4.45.

Commits
  • 096e3d1 Bump to 0.4.45 (#443)
  • 17b1fd8 archive: Prevent symlink-directory collision chmod attack (#442)
  • de1a587 archive: Unconditionally honor PAX size (#441)
  • 6071cbe ci: Consolidate workflows (#439)
  • ad1fde9 build-sys: Promote unused_code to an error
  • c8cb250 tests: Squash a warning
  • 638c495 ci: Add xtask infra + reverse dependency testing (#435)
  • 32a9bbb tests: Add RandomReader to exercise partial-read resilience (#436)
  • 9c5df0b Fix GNU long-name extension stream corruption on validation error (#434)
  • 88b1e3b Fix docs typo in header.rs (#431)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [tar](https://github.com/alexcrichton/tar-rs) from 0.4.44 to 0.4.45.
- [Commits](alexcrichton/tar-rs@0.4.44...0.4.45)

---
updated-dependencies:
- dependency-name: tar
  dependency-version: 0.4.45
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Mar 24, 2026
Copy link

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Surge (small)

Details
Benchmark suite Current: 26cd0c3 Previous: e725b87 Ratio
Archive create (zstd=1) 17.463732 ms 17.146755 ms 1.02
Archive create (zstd=3) 16.999123 ms 16.566456 ms 1.03
Archive extract 28.889635000000002 ms 29.780818 ms 0.97
SHA-256 (in-memory) 8.049769999999999 ms 7.776651 ms 1.04
SHA-256 (file) 9.10868 ms 8.929936 ms 1.02
Zstd compress (level=1) 7.8472420000000005 ms 7.798511 ms 1.01
Zstd compress (level=3) 5.841883 ms 6.451878000000001 ms 0.91
Zstd decompress 1.5760859999999999 ms 1.526138 ms 1.03
bsdiff 683.183778 ms 635.251533 ms 1.08
bspatch 49.232659 ms 46.850379 ms 1.05
chunked bsdiff 652.1068 ms 603.8098659999999 ms 1.08
chunked bspatch 48.271222 ms 45.692266000000004 ms 1.06
Full package build 15.543712 ms 15.017826 ms 1.04
Delta package build 642.976106 ms 589.141802 ms 1.09
Apply 1 delta 49.604481 ms 46.617909 ms 1.06
Apply 5x deltas 245.95778700000002 ms 233.437929 ms 1.05
Installer (web) 0.087834 ms
Installer (offline) 22.679603999999998 ms 20.984662 ms 1.08

This comment was automatically generated by workflow using github-action-benchmark.

Copy link

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Surge (medium)

Details
Benchmark suite Current: 26cd0c3 Previous: e725b87 Ratio
Archive create (zstd=1) 46.045147 ms 45.096346000000004 ms 1.02
Archive create (zstd=3) 63.448276 ms 60.378063000000004 ms 1.05
Archive extract 82.11022799999999 ms 75.484161 ms 1.09
SHA-256 (in-memory) 39.841234 ms 39.695802 ms 1.00
SHA-256 (file) 43.786001999999996 ms 43.526 ms 1.01
Zstd compress (level=1) 25.072783 ms 25.250013000000003 ms 0.99
Zstd compress (level=3) 27.746613 ms 27.132124 ms 1.02
Zstd decompress 11.837369 ms 11.175182000000001 ms 1.06
bsdiff 4124.7877419999995 ms 3885.526697 ms 1.06
bspatch 244.613361 ms 228.879566 ms 1.07
chunked bsdiff 4012.1962030000004 ms 3845.897143 ms 1.04
chunked bspatch 247.27730300000002 ms 233.493975 ms 1.06
Full package build 63.906326 ms 60.816680999999996 ms 1.05
Delta package build 4011.6658960000004 ms 3873.596336 ms 1.04
Apply 1 delta 246.96693 ms 235.78355100000002 ms 1.05
Apply 5x deltas 1246.087454 ms 1176.044034 ms 1.06
Installer (web) 0.09493800000000001 ms
Installer (offline) 86.463288 ms 85.49140299999999 ms 1.01

This comment was automatically generated by workflow using github-action-benchmark.

Copy link

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Surge (large)

Details
Benchmark suite Current: 26cd0c3 Previous: e725b87 Ratio
Archive create (zstd=1) 79.153705 ms 79.03569300000001 ms 1.00
Archive create (zstd=3) 107.932932 ms 106.799285 ms 1.01
Archive extract 133.734719 ms 138.24129499999998 ms 0.97
SHA-256 (in-memory) 77.902338 ms 86.520219 ms 0.90
SHA-256 (file) 87.18867499999999 ms 86.83184800000001 ms 1.00
Zstd compress (level=1) 44.600167000000006 ms 42.423359 ms 1.05
Zstd compress (level=3) 54.865522999999996 ms 49.408598999999995 ms 1.11
Zstd decompress 22.512284 ms 21.805075 ms 1.03
bsdiff 8663.743388 ms 8413.766651 ms 1.03
bspatch 467.410711 ms 461.653602 ms 1.01
chunked bsdiff 4638.620825 ms 4499.425674 ms 1.03
chunked bspatch 279.28049799999997 ms 262.790008 ms 1.06
Full package build 109.807471 ms 106.988466 ms 1.03
Delta package build 4632.411671 ms 4515.601756 ms 1.03
Apply 1 delta 275.752408 ms 264.87306900000004 ms 1.04
Apply 5x deltas 1389.491001 ms 1318.68008 ms 1.05
Installer (web) 0.07878700000000001 ms
Installer (offline) 157.85496700000002 ms 158.841734 ms 0.99

This comment was automatically generated by workflow using github-action-benchmark.

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Mar 24, 2026

Looks like tar is up-to-date now, so this is no longer needed.

@dependabot dependabot bot closed this Mar 24, 2026
@dependabot dependabot bot deleted the dependabot/cargo/tar-0.4.45 branch March 24, 2026 09:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants