Skip to content

chore(deps): bump tar from 0.4.45 to 0.4.46 in the cargo group across 1 directory#423

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-8529595794
Open

chore(deps): bump tar from 0.4.45 to 0.4.46 in the cargo group across 1 directory#423
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-8529595794

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the cargo group with 1 update in the / directory: tar.

Updates tar from 0.4.45 to 0.4.46

Release notes

Sourced from tar's releases.

0.4.46

Security

See also GHSA-3cv2-h65g-fgmm

Other changes

New Contributors

Full Changelog: composefs/tar-rs@0.4.45...0.4.46

Commits


Note

Low Risk
Lockfile-only dependency bump with a targeted archive parsing security fix; no source changes, though tar handling of malicious archives is security-sensitive.

Overview
Bumps the transitive tar crate from 0.4.45 to 0.4.46 via Cargo.lock only (Dependabot cargo group).

The meaningful change is adopting 0.4.46, which includes a security fix for PAX header desync (GHSA-3cv2-h65g-fgmm). The rest of the lockfile diff is collateral windows-sys version resolution churn for unrelated crates, not direct application code changes.

Reviewed by Cursor Bugbot for commit 6a27be2. Bugbot is set up for automated code reviews on this repo. Configure here.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Jun 4, 2026
Bumps the cargo group with 1 update in the / directory: [tar](https://github.com/composefs/tar-rs).


Updates `tar` from 0.4.45 to 0.4.46
- [Release notes](https://github.com/composefs/tar-rs/releases)
- [Commits](composefs/tar-rs@0.4.45...0.4.46)

---
updated-dependencies:
- dependency-name: tar
  dependency-version: 0.4.46
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot force-pushed the dependabot/cargo/cargo-8529595794 branch from f09c462 to 6a27be2 Compare June 10, 2026 13:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants