Repository navigation
deps: bump sha2 from 0.10.9 to 0.11.0 - #48
Conversation
Bumps [sha2](https://github.com/RustCrypto/hashes) from 0.10.9 to 0.11.0. - [Commits](RustCrypto/hashes@sha2-v0.10.9...sha2-v0.11.0) --- updated-dependencies: - dependency-name: sha2 dependency-version: 0.11.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
The digest was formatted with the lower-hex formatter, which drops leading zeros and produces a shorter, incorrect hash. Each byte is now encoded as two hex digits so the checksum is always the full 64 characters. Auto-committed-on: dragonfly Co-authored-by: Medulla <medulla@tinyhumans.ai>
The digest was previously formatted by mapping each byte to a new String and collecting them, which allocated once per byte. It is now written directly into a pre-sized buffer, avoiding the intermediate allocations while producing the same lowercase hex output. Auto-committed-on: dragonfly Co-authored-by: Medulla <medulla@tinyhumans.ai>
Tiny Sweeper reviewTiny Sweeper reviewed this change across 6 lane(s) and found 0 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below. State: Ready for maintainer review Review snapshot
Completeness: Complete What changedThe review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below. FeaturesNone identified with supported citations. TestsNo supported feature-to-test mapping was produced. Test execution is not inferred. FindingsNo active actionable findings. Before mergeNone. How this fits togetherflowchart LR
n0["CurlTool<br/>changed"]:::changed
n1["Tool"]:::impacted
n2["tool"]:::impacted
n3["resolve_dest"]:::impacted
n4["NetGate"]:::impacted
n5["new"]:::impacted
n6["execute"]:::impacted
n0 -->|implements| n1
n0 -->|uses| n4
n2 -->|uses| n0
n3 -->|calls| n5
n5 -->|uses| n4
n6 -->|calls| n3
n6 -->|calls| n5
classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Agent review detailscritique
security
tests
commits
description
e2e
Evidence and run details
|
There was a problem hiding this comment.
tinysweeper found nothing blocking. Approving.
$0.0039 · 44,027 in / 2,704 out · 5,604 cached (13%) · gpt-5.6-luna, glm-5.3-flash
critique: $0.0021 · 14,096 in / 781 out · 2,031 cached (14%) · gpt-5.6-luna
security: $0.0017 · 18,051 in / 767 out · 3,573 cached (20%) · gpt-5.6-luna
tests: $0.0000 · 4,313 in / 305 out · 0 cached (0%) · glm-5.3-flash
description: $0.0000 · 5,107 in / 155 out · 0 cached (0%) · glm-5.3-flash
Bumps sha2 from 0.10.9 to 0.11.0.
Commits
ffe0939Release sha2 0.11.0 (#806)8991b65Use the standard order of the[package]section fields (#807)3d2bc57sha2: refactor backends (#802)faa55fbsha3: bumpkeccakto v0.2 (#803)d3e6489sha3 v0.11.0-rc.9 (#801)bbf6f51sha2: tweak backend docs (#800)155dbbfsha3: add default value for theDSgeneric parameter onTurboShake128/256...ed514f2Use published version ofkeccakv0.2 (#799)702bcd8Migrate to closure-basedkeccak(#796)827c043sha3 v0.11.0-rc.8 (#794)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)