Skip to content

Bump rand from 0.9.2 to 0.9.3 in /backend in the cargo group across 1 directory#1156

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/backend/cargo-3df31d4f53
Open

Bump rand from 0.9.2 to 0.9.3 in /backend in the cargo group across 1 directory#1156
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/backend/cargo-3df31d4f53

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Apr 14, 2026

Copy link
Copy Markdown
Contributor

Bumps the cargo group with 1 update in the /backend directory: rand.

Updates rand from 0.9.2 to 0.9.3

Changelog

Sourced from rand's changelog.

[0.9.3] — 2026-02-11

This release back-ports a fix from v0.10. See also #1763.

Changes

  • Deprecate feature log (#1764)
  • Replace usages of doc_auto_cfg (#1764)

#1763: rust-random/rand#1763

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Rust / Cargo 依存関係の更新 labels Apr 14, 2026
@ka2kama

ka2kama commented Apr 27, 2026

Copy link
Copy Markdown
Owner

@dependabot rebase

Bumps the cargo group with 1 update in the /backend directory: [rand](https://github.com/rust-random/rand).


Updates `rand` from 0.9.2 to 0.9.3
- [Release notes](https://github.com/rust-random/rand/releases)
- [Changelog](https://github.com/rust-random/rand/blob/0.9.3/CHANGELOG.md)
- [Commits](rust-random/rand@rand_core-0.9.2...0.9.3)

---
updated-dependencies:
- dependency-name: rand
  dependency-version: 0.9.3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@ka2kama

ka2kama commented Apr 27, 2026

Copy link
Copy Markdown
Owner

本 PR の Security ジョブ失敗は rand 0.9.3 とは無関係で、origin/main が既に保持している依存ツリーの問題(AWS-LC 脆弱性 6 件 / OpenSSL ライセンス / redox_syscall duplicate)が原因と判明しました。

詳細・対応方針の検討は #1163 で実施します。

本 PR は #1163 解決後にリベースして再評価予定です。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Rust / Cargo 依存関係の更新

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant