| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
Bumps [rand](https://github.com/rust-random/rand) from 0.9.2 to 0.9.5. - [Release notes](https://github.com/rust-random/rand/releases) - [Changelog](https://github.com/rust-random/rand/blob/0.9.5/CHANGELOG.md) - [Commits](rust-random/rand@rand_core-0.9.2...0.9.5) --- updated-dependencies: - dependency-name: rand dependency-version: 0.9.5 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
| Back | FazBrowse Home | New Git URL |
Bumps rand from 0.9.2 to 0.9.5.
ChangelogSourced from rand's changelog.
CommitsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
You can disable automated security fix PRs for this repo from the Security Alerts page.
Note
Low Risk
Lockfile-only patch bump with no repo code changes; risk is limited to transitive rand behavior, and the update reduces exposure to a known deserialization memory-safety bug.
Overview
Dependency-only change: Cargo.lock pins rand 0.9.2 → 0.9.5; no application source or Cargo.toml edits in this diff.
The bump pulls in upstream patch releases, notably 0.9.5’s fix for a possible memory-safety issue when deserializing UniformChar from untrusted input (rust-random/rand#1803). Minor releases in between are doc/build and deprecation housekeeping.
Reviewers should treat this as a routine transitive lockfile refresh; behavior should stay the same unless the project deserializes UniformChar or relies on affected rand APIs.
Reviewed by Cursor Bugbot for commit db49f9d. Bugbot is set up for automated code reviews on this repo. Configure here.