deps: Bump aes from 0.8.4 to 0.9.1#6
Conversation
|
Holding — not merging yet. aes 0.9 moves to cipher 0.5, but |
|
Still holding (unaffected by today's vgi 0.6 / Rust 1.90 bump); blocked on the crypto API change / fpe requiring aes 0.8. |
|
Holding this open as a tracker — not mergeable yet. |
Bumps [aes](https://github.com/RustCrypto/block-ciphers) from 0.8.4 to 0.9.1. - [Commits](RustCrypto/block-ciphers@aes-v0.8.4...aes-v0.9.1) --- updated-dependencies: - dependency-name: aes dependency-version: 0.9.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
00954c7 to
24d3fb2
Compare
FF1 FPE runs through `fpe` (latest 0.6.1), which still requires aes ^0.8 / cipher ^0.4. A direct aes 0.9 bump forces two incompatible aes/cipher majors and won't compile, so dependabot's aes 0.9 PR (#6) is unmergeable. Hold aes on 0.8.x until fpe moves to cipher 0.5. No security driver (aes 0.8 has no advisory; 0.8->0.9 is trait-API churn). Patches within 0.8.x still flow. Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Closing — aes 0.9 is unmergeable while |
|
Looks like aes is no longer being updated by Dependabot, so this is no longer needed. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps aes from 0.8.4 to 0.9.1.
Commits
507938cRelease aes v0.9.1 (#563)957dba9aes: fix min version ofzeroizeand build warnings on AArch64 (#562)c69a235Release new versions dependent oncipherv0.5 (#553)582b178Movegifttogift-cipherandspecktospeck-cipher(#554)001e740Adopt Trusted Publishing (#552)d908618Release aes v0.9.0 (#539)b612904aes: removezeroize_workstest (#551)042fa86Update Cargo.lock (#547)7290b2bci: use Dependabot to update Cargo.lock (#546)d1910c1ci: bump actions/checkout to v6 (#545)