Skip to content

build(deps): bump tauri-build from 2.6.3 to 2.7.1 - #522

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/tauri-build-2.7.1
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/tauri-build-2.7.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps tauri-build from 2.6.3 to 2.7.1.

Release notes

Sourced from tauri-build's releases.

tauri-build v2.7.1

Fetching advisory database from `https://github.com/RustSec/advisory-db.git`
      Loaded 1277 security advisories (from /home/runner/.cargo/advisory-db)
    Updating crates.io index
    Scanning Cargo.lock for vulnerabilities (1091 crate dependencies)
Crate:     fxhash
Version:   0.2.1
Warning:   unmaintained
Title:     fxhash - no longer maintained
Date:      2025-09-05
ID:        RUSTSEC-2025-0057
URL:       https://rustsec.org/advisories/RUSTSEC-2025-0057

Crate: paste
Version: 1.0.15
Warning: unmaintained
Title: paste - no longer maintained
Date: 2024-10-07
ID: RUSTSEC-2024-0436
URL: https://rustsec.org/advisories/RUSTSEC-2024-0436

Crate: rustls-pemfile
Version: 2.2.0
Warning: unmaintained
Title: rustls-pemfile is unmaintained
Date: 2025-11-28
ID: RUSTSEC-2025-0134
URL: https://rustsec.org/advisories/RUSTSEC-2025-0134

Crate: rustybuzz
Version: 0.20.1
Warning: unmaintained
Title: rustybuzz is unmaintained
Date: 2026-07-11
ID: RUSTSEC-2026-0206
URL: https://rustsec.org/advisories/RUSTSEC-2026-0206

Crate: ttf-parser
Version: 0.25.1
Warning: unmaintained
Title: ttf-parser is unmaintained
Date: 2026-06-28
ID: RUSTSEC-2026-0192
URL: https://rustsec.org/advisories/RUSTSEC-2026-0192

warning: 5 allowed warnings found
</tr></table>

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [tauri-build](https://github.com/tauri-apps/tauri) from 2.6.3 to 2.7.1.
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](tauri-apps/tauri@tauri-build-v2.6.3...tauri-build-v2.7.1)

---
updated-dependencies:
- dependency-name: tauri-build
  dependency-version: 2.7.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: rust. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 5, 2026
fstubner added a commit that referenced this pull request Oct 5, 2026
* Update Tauri to 2.12 in Rust and JavaScript together

Combines Dependabot #515 and #522-#527. Tauri needs its Rust crates and
@tauri-apps/* packages on matching minor versions, so landing them one PR
at a time leaves the desktop build broken in between.

tauri 2.12.1, tauri-build 2.7.1, plugins dialog 2.8.1, opener 2.7.0,
process 2.4.0, updater 2.13.1; @tauri-apps/api and cli 2.12.1 and the
matching JS plugins. Cargo.lock from cargo update on those crates, which
lands on exactly the versions Dependabot proposed.

* The rest of the 2026-10-05 Dependabot batch

Desktop app: vite 8.3.2 (#514), lucide-react 1.49.0 (#516), vitest 5.0.3
(#517), typescript-eslint 8.71.0 (#518), selenium-webdriver 4.50.0 (#520).
Site: @astrojs/starlight 0.42.5 (#528), chromedriver 154.0.1 (#529),
selenium-webdriver 4.50.0 (#530). Rust: tokio-rustls 0.26.6 (#519),
mac_address 1.2.0 (#521).

Taken together rather than one PR each: three share a lockfile apiece, so
each merge would conflict the rest and need a Dependabot rebase.
@fstubner

fstubner commented Oct 5, 2026

Copy link
Copy Markdown
Owner

Included in #534, merged.

@fstubner fstubner closed this Oct 5, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/cargo/tauri-build-2.7.1 branch October 5, 2026 22:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant