Skip to content

build(deps): Bump rwml-fonts from 0.1.3 to 0.1.4 in the cargo-minor group across 1 directory - #36

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-minor-a1981dcb60
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-minor-a1981dcb60

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 3, 2026

Copy link
Copy Markdown
Contributor

Bumps the cargo-minor group with 1 update in the / directory: rwml-fonts.

Updates rwml-fonts from 0.1.3 to 0.1.4

Release notes

Sourced from rwml-fonts's releases.

rwml 0.1.4

What's Changed

Full Changelog: HyunjoJung/rwml@v0.1.3...v0.1.4

Changelog

Sourced from rwml-fonts's changelog.

[0.1.4] - 2026-08-29

Changed

  • The rwml CLI now automatically registers the deterministic OFL font subsets when built with bundled-fonts, so rwml to-pdf uses the bundled Korean, Arabic, and Hebrew coverage without a separate library call.
  • The opt-in renderer now uses parley 0.11.1, including corrected emoji variation-selector font fallback and refreshed Fontations/HarfRust shaping dependencies. The render MSRV remains 1.92 because krilla 0.8.2 sets the current render-stack floor.
  • Public edit and legacy-oracle release validation now use authoritative recursive manifests and fail closed on empty, missing, or partial evidence.
  • Public contribution guidance now uses a right-sized issue/PR workflow, with optional BMad planning kept external and all review decisions recorded in the public repository.

Security

  • quick-xml is upgraded from 0.36.2 to 0.41.0 to address reachable CPU- exhaustion (RUSTSEC-2026-0194) and namespace-allocation (RUSTSEC-2026-0195) denial-of-service paths, with regression coverage.
  • OPC metadata XML is capped at 256 namespace declarations per element and 128 nested elements. Over-depth metadata remains read-only and byte-preserved on no-op saves.
Commits
  • 1ae59d9 Prepare rwml 0.1.4 release
  • b5b6527 Update parley and synchronize render lockfiles
  • fdaeb26 Defer incompatible quick-xml minor updates
  • 0c789cb Bound OPC metadata XML nesting depth
  • e0d4c7d Bump thiserror from 2.0.19 to 2.0.20
  • c14ecd3 Harden release validation and contributor workflow
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 3, 2026
@dependabot
dependabot Bot requested a review from P4suta as a code owner September 3, 2026 10:15
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 3, 2026
Bumps the cargo-minor group with 1 update in the / directory: [rwml-fonts](https://github.com/HyunjoJung/rwml).


Updates `rwml-fonts` from 0.1.3 to 0.1.4
- [Release notes](https://github.com/HyunjoJung/rwml/releases)
- [Changelog](https://github.com/HyunjoJung/rwml/blob/main/CHANGELOG.md)
- [Commits](HyunjoJung/rwml@v0.1.3...v0.1.4)

---
updated-dependencies:
- dependency-name: rwml-fonts
  dependency-version: 0.1.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps): Bump rwml-fonts from 0.1.3 to 0.1.4 in the cargo-minor group build(deps): Bump rwml-fonts from 0.1.3 to 0.1.4 in the cargo-minor group across 1 directory Sep 7, 2026
@dependabot
dependabot Bot force-pushed the dependabot/cargo/cargo-minor-a1981dcb60 branch from 207f997 to 4747450 Compare September 7, 2026 14:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants