Skip to content

build(deps): bump feedparser-rs from 0.5.5 to 0.5.6 - #20

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/feedparser-rs-0.5.6
Open

build(deps): bump feedparser-rs from 0.5.5 to 0.5.6#20
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/feedparser-rs-0.5.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 28, 2026

Copy link
Copy Markdown
Contributor

Bumps feedparser-rs from 0.5.5 to 0.5.6.

Release notes

Sourced from feedparser-rs's releases.

v0.5.6

Installation

Rust (crates.io):

cargo add feedparser-rs

Python (PyPI):

pip install feedparser-rs

Node.js (npm):

npm install feedparser-rs

Links

See https://github.com/bug-ops/feedparser-rs/blob/HEAD/CHANGELOG.md for details.

What's Changed

Full Changelog: bug-ops/feedparser-rs@v0.5.5...v0.5.6

Changelog

Sourced from feedparser-rs's changelog.

[0.5.6] - 2026-07-27

Security

  • Update brace-expansion to 5.0.8 and js-yaml to 4.3.0 (transitive Node.js dev dependencies) to address high-severity npm audit advisories (DoS via numeric-range expansion and YAML merge-key chains) (#415)
  • Update ammonia to 4.1.4 to address RUSTSEC-2026-0213 (XSS via SVG animate/set animation tags with javascript: scheme) (#415)
  • Update quinn-proto (transitive, via reqwest) to 0.11.15 to address RUSTSEC-2026-0185/GHSA-4w2j-m93h-cj5j (remote memory exhaustion from unbounded out-of-order stream reassembly) (#420)

Fixed

  • Root and binding READMEs: corrected nonexistent fetch_and_parse/fetchAndParse API references to the real parse_url/parseUrl functions, fixed Node.js binding docs (synchronous parseUrl, bozoException naming, date field shapes, missing parseWithOptions/parseUrlWithOptions and HTTP fields, supported Node.js versions), fixed the Python binding's itunes.duration example, and bumped a stale version pin in the core crate README (#411)

Changed

  • Bump compact_str from 0.9.1 to 0.10.0 (#426)
  • Bump napi from 3.10.3 to 3.11.0 and napi-derive from 3.5.9 to 3.6.0 (#419, #425)
  • Bump regex from 1.12.4 to 1.13.1 (#414, #419)
  • Bump anyhow, memchr, serde, serde_json, and thiserror in the patch-updates group (#419)
  • Bump @biomejs/biome, @napi-rs/cli, and c8 (Node.js dev tooling) (#415, #424)
  • Bump actions/labeler from 6 to 7 (#423)
  • Bump actions/setup-python from 6 to 7 (#421)
  • Bump actions/setup-node from 6 to 7 (#416)
  • Bump lewagon/wait-on-check-action from 1.8.1 to 1.9.0 (#422)
Commits
  • 78b67a4 fix(ci): bump Node.js to 22 in npm publish job
  • f1d6dbf release: prepare v0.5.6 (#427)
  • e39abca chore(deps): bump compact_str from 0.9.1 to 0.10.0 (#426)
  • 0783a9c chore(deps): bump the minor-updates group with 2 updates (#425)
  • b191065 chore: bump the npm-updates group (#424)
  • 6d251c2 chore(deps): bump actions/labeler from 6 to 7 (#423)
  • dd16647 chore(deps): bump lewagon/wait-on-check-action from 1.8.1 to 1.9.0 (#422)
  • 59f45d5 chore(deps): bump actions/setup-python from 6 to 7 (#421)
  • 2b676ff fix(deps): bump quinn-proto to 0.11.15 (#420)
  • 57f7caa chore(deps): bump the patch-updates group across 1 directory with 8 updates (...
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [feedparser-rs](https://github.com/bug-ops/feedparser-rs) from 0.5.5 to 0.5.6.
- [Release notes](https://github.com/bug-ops/feedparser-rs/releases)
- [Changelog](https://github.com/bug-ops/feedparser-rs/blob/main/CHANGELOG.md)
- [Commits](bug-ops/feedparser-rs@v0.5.5...v0.5.6)

---
updated-dependencies:
- dependency-name: feedparser-rs
  dependency-version: 0.5.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Jul 28, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedcargo/​feedparser-rs@​0.5.5 ⏵ 0.5.610010093100100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants