Skip to content

Bump tracing-subscriber from 0.3.19 to 0.3.20 in the cargo group across 1 directory - #2251

Merged
miratepuffin merged 3 commits into
masterfrom
dependabot/cargo/cargo-2dc5bac7e8
Sep 16, 2025
Merged

Bump tracing-subscriber from 0.3.19 to 0.3.20 in the cargo group across 1 directory#2251
miratepuffin merged 3 commits into
masterfrom
dependabot/cargo/cargo-2dc5bac7e8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 29, 2025

Copy link
Copy Markdown
Contributor

Bumps the cargo group with 1 update in the / directory: tracing-subscriber.

Updates tracing-subscriber from 0.3.19 to 0.3.20

Release notes

Sourced from tracing-subscriber's releases.

tracing-subscriber 0.3.20

Security Fix: ANSI Escape Sequence Injection (CVE-TBD)

Impact

Previous versions of tracing-subscriber were vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be injected into terminal output when logged, potentially allowing attackers to:

  • Manipulate terminal title bars
  • Clear screens or modify terminal display
  • Potentially mislead users through terminal manipulation

In isolation, impact is minimal, however security issues have been found in terminal emulators that enabled an attacker to use ANSI escape sequences via logs to exploit vulnerabilities in the terminal emulator.

Solution

Version 0.3.20 fixes this vulnerability by escaping ANSI control characters in when writing events to destinations that may be printed to the terminal.

Affected Versions

All versions of tracing-subscriber prior to 0.3.20 are affected by this vulnerability.

Recommendations

Immediate Action Required: We recommend upgrading to tracing-subscriber 0.3.20 immediately, especially if your application:

  • Logs user-provided input (form data, HTTP headers, query parameters, etc.)
  • Runs in environments where terminal output is displayed to users

Migration

This is a patch release with no breaking API changes. Simply update your Cargo.toml:

[dependencies]
tracing-subscriber = "0.3.20"

Acknowledgments

We would like to thank zefr0x who responsibly reported the issue at security@tokio.rs.

If you believe you have found a security vulnerability in any tokio-rs project, please email us at security@tokio.rs.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the cargo group with 1 update in the / directory: [tracing-subscriber](https://github.com/tokio-rs/tracing).


Updates `tracing-subscriber` from 0.3.19 to 0.3.20
- [Release notes](https://github.com/tokio-rs/tracing/releases)
- [Commits](tokio-rs/tracing@tracing-subscriber-0.3.19...tracing-subscriber-0.3.20)

---
updated-dependencies:
- dependency-name: tracing-subscriber
  dependency-version: 0.3.20
  dependency-type: direct:production
  dependency-group: cargo
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update Rust code labels Aug 29, 2025
@CLAassistant

CLAassistant commented Aug 29, 2025

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you all sign our Contributor License Agreement before we can accept your contribution.
1 out of 2 committers have signed the CLA.

✅ miratepuffin
❌ dependabot[bot]
You have signed the CLA already but the status is still pending? Let us recheck it.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Performance Alert ⚠️

Possible performance regression was detected for benchmark 'GraphQL Benchmark'.
Benchmark result of this commit is worse than the previous benchmark result exceeding threshold 2.

Benchmark suite Current: 475ec37 Previous: f14de7d Ratio
addNode 15 req/s 1460 req/s 97.33

This comment was automatically generated by workflow using github-action-benchmark.

@miratepuffin
miratepuffin merged commit 4eb2b5a into master Sep 16, 2025
29 of 30 checks passed
@miratepuffin
miratepuffin deleted the dependabot/cargo/cargo-2dc5bac7e8 branch September 16, 2025 12:39
ljeub-pometry added a commit that referenced this pull request Sep 17, 2025
* Fix/top k (#2228)

* add linear top_k implementation

* update top_k to use new linear top_k implementation

* cleanup

* chore: apply tidy-public auto-fixes

---------

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

* Fix/fastrp (#2229)

* update fastrp to properly average embeddings instead of just summing

* fix import issue

* add helper function to test pairwise distances

* cleanup and update python test

* chore: apply tidy-public auto-fixes

---------

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

* fix docker ci (#2227)

* sort ci action and create new Dockerfile for python

* add missing dockerfile

* remove env from docker ci action

* fix python dockerfile

* chore: apply tidy-public auto-fixes

* add action input to be able to build the python image

* add permissions

* read base input

* fix typo

* change default branch to master

* chore: apply tidy-public auto-fixes

* fix using wrong username on merge step

* change manual docker release to also build python

* fix digest name conflicts

* change choice to boolean for action input

* fix digest name using old variable

* sort versioning and add nightly action

* add permissions to nightly action

* add permissions to manual docker release action

* read dry-run from the docker action

* add dry_run to docker action

---------

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

* graphql bench on CI and vector bench (#2198)

* rewrite the vector bench script

* try disabling available memory setting

* try arroy append api

* add graphql benchmarks

* chore: apply tidy-public auto-fixes

* add parallel workflow for graphql bench

* chore: apply tidy-public auto-fixes

* setup python

* setup k6

* chore: apply tidy-public auto-fixes

* get output file out of the results folder

* add pnpm-workspace.yaml

* fix ci error

* chore: apply tidy-public auto-fixes

* fix ci for good this time?

* test gh pages branch

* chore: apply tidy-public auto-fixes

* test different dir for graphql

* reduce target

* add -100 for testing

* chore: apply tidy-public auto-fixes

* add TODO

* chore: apply tidy-public auto-fixes

* cleanup PR

* re-enable base benches

* fix flaky bench

* remove -100

* remove cell from results.ipynb

* sort parent workflow

* add missing bench.ts

* chore: apply tidy-public auto-fixes

* some final bits

* print json output on ci to make sure numbers are valid

* fix ci

* set iteration target to 6400

---------

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

* James/graphql docstrings (#2210)

* init

* docstrings

* docstrings for edges

* docstrings for edges

* regen schema and docs

* run formatting

* chore: apply tidy-public auto-fixes

* more docstrings

* backticks are not used by docs parser so remove

* more docstrings

* chore: apply tidy-public auto-fixes

* more docstrings

* chore: apply tidy-public auto-fixes

* more docstrings

* more docstrings

* update schema and format

* chore: apply tidy-public auto-fixes

* more docstrings

* chore: apply tidy-public auto-fixes

* more docstrings

* chore: apply tidy-public auto-fixes

* more docstrings

* chore: apply tidy-public auto-fixes

* more docstrings

* more docstrings

* cleanup

* more docstrings

* chore: apply tidy-public auto-fixes

* testcase for inputs

* cleanup

* chore: apply tidy-public auto-fixes

* more docstrings

* cleanup

* chore: apply tidy-public auto-fixes

* more docstrings

* cleanup

* chore: apply tidy-public auto-fixes

* fix page  docstrings

* cleanup

* remove latin

* chore: apply tidy-public auto-fixes

* initial fixes

* fmt

* chore: apply tidy-public auto-fixes

---------

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Ben Steer <ben.steer@pometry.com>

* Release v0.16.1 (#2236)

chore: Release

Co-authored-by: Pometry-Team <ben.steer@pometry.com>

* Fix explode layers for filtered persistent graph (#2241)

* explode layers for valid graph is broken

* explode_layers was ignoring layer filters for persistent semantics

* chore: apply tidy-public auto-fixes

---------

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

* James/graphql docstrings fixes (#2239)

* init

* docstrings

* docstrings for edges

* docstrings for edges

* regen schema and docs

* run formatting

* chore: apply tidy-public auto-fixes

* more docstrings

* backticks are not used by docs parser so remove

* more docstrings

* chore: apply tidy-public auto-fixes

* more docstrings

* chore: apply tidy-public auto-fixes

* more docstrings

* more docstrings

* update schema and format

* chore: apply tidy-public auto-fixes

* more docstrings

* chore: apply tidy-public auto-fixes

* more docstrings

* chore: apply tidy-public auto-fixes

* more docstrings

* chore: apply tidy-public auto-fixes

* more docstrings

* more docstrings

* cleanup

* more docstrings

* chore: apply tidy-public auto-fixes

* testcase for inputs

* cleanup

* chore: apply tidy-public auto-fixes

* more docstrings

* cleanup

* chore: apply tidy-public auto-fixes

* more docstrings

* cleanup

* chore: apply tidy-public auto-fixes

* fix page  docstrings

* cleanup

* remove latin

* chore: apply tidy-public auto-fixes

* initial fixes

* fmt

* chore: apply tidy-public auto-fixes

* fix double spacing

* review fixes

* specify layers for has_edge

* tidy

* chore: apply tidy-public auto-fixes

---------

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Ben Steer <ben.steer@pometry.com>
Co-authored-by: Ben Steer <b.a.steer@qmul.ac.uk>

* James/graphql-userguide-16-x (#2233)

* update ui  image

* mutation and views

* persistent and event distinction

* clean up running steps and add cli

* subtitle

* proper hierarchy

* props and metadata examples

* Add troubleshooting

* add missing cli parameter

* chore: apply tidy-public auto-fixes

* add default save location to troubleshooting

* markdown formatting

* chore: apply tidy-public auto-fixes

* chore: apply tidy-public auto-fixes

* Clarify docker basics

* Clarify docker basics

---------

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Ben Steer <b.a.steer@qmul.ac.uk>

* fix nightly release action (#2244)

* fix nightly release action

* fix versions missing

* chore: apply tidy-public auto-fixes

---------

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

* add docker retag action (#2245)

* add docker retag action

* add permissions

* chore: apply tidy-public auto-fixes

---------

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

* update Slack invite link (#2252)

* test strings in df loaders

* Increase sleep time on graphql bench (#2278)

Update Makefile

* remove polars from parquet and df loading

* Bump tracing-subscriber from 0.3.19 to 0.3.20 in the cargo group across 1 directory (#2251)

* Bump tracing-subscriber in the cargo group across 1 directory

Bumps the cargo group with 1 update in the / directory: [tracing-subscriber](https://github.com/tokio-rs/tracing).


Updates `tracing-subscriber` from 0.3.19 to 0.3.20
- [Release notes](https://github.com/tokio-rs/tracing/releases)
- [Commits](tokio-rs/tracing@tracing-subscriber-0.3.19...tracing-subscriber-0.3.20)

---
updated-dependencies:
- dependency-name: tracing-subscriber
  dependency-version: 0.3.20
  dependency-type: direct:production
  dependency-group: cargo
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore: apply tidy-public auto-fixes

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Ben Steer <b.a.steer@qmul.ac.uk>

* community detection (#2276)

Covers changes for ticket #2268 and adds an introduction to community detection with a tutorial using our existing algorithms and UI. This should apear first in the search results.

* initial introduction

* add karate example

* add karate example

* add assets and tests

* fix tests

* fix tests

* fix tests

* chore: apply tidy-public auto-fixes

* review: simplify node type assignment

* chore: apply tidy-public auto-fixes

* review: swap to csv file

---------

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

* Use raphtory from python dir (#2275)

* Use raphtory from python dir

* comment to match

* chore: apply tidy-public auto-fixes

---------

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

* add batch_size argument for the low-level functions

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: wyatt-joyner-pometry <wyatt.joyner@pometry.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Pedro Rico Pinazo <ricopinazo@gmail.com>
Co-authored-by: James Baross <james.baross@pometry.com>
Co-authored-by: Ben Steer <ben.steer@pometry.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Ben Steer <b.a.steer@qmul.ac.uk>
Co-authored-by: edsherrington <ed.sherrington@pometry.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update Rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants