From c523add8955bcc4bd205a47d542bde5164c2e295 Mon Sep 17 00:00:00 2001
From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com>
Date: Sat, 15 Nov 2025 18:46:37 +1100
Subject: [PATCH] build(deps): bump zip from 5.1.1 to 6.0.0 in /rust (#10829)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Bumps [zip](https://github.com/zip-rs/zip2) from 5.1.1 to 6.0.0.
Release notes
Sourced from zip's
releases.
v6.0.0
🐛 Bug Fixes
- panic when reading empty extended-timestamp field (#404) (#422)
- Restore original file timestamp when unzipping with
chrono (#46)
⚙️ Miscellaneous Tasks
- Configure Amazon Q rules (#421)
Changelog
Sourced from zip's
changelog.
6.0.0
- 2025-10-09
🚀 Features
- Add by_index_with_options(), which can be used to ignore encryption
in a file's metadata (#439) and
may be used for other file-specific overrides in the future.
⚙️ Miscellaneous Tasks
- [breaking]
FileOptions::add_extra_data
is now generic and accepts any AsRef<[u8]>. (#435)
Commits
abfc23d
feat: Upgrade [Extended]FileOptions::add_extra_data() data from
Box<[u8]> to ...
eb1b586
docs: Update zip_writer documentation example (#431)
26e6e08
feat: Add by_index_with_options() for ignoring encryption (#439)
165415d
chore(deps): update nt-time requirement from 0.10.6 to 0.12.1 (#429)
1d5d4ed
chore(deps): update lzma-rust2 requirement from 0.13 to 0.14 (#432)
72cce40
chore(deps): update nt-time requirement from 0.10.6 to 0.12.1 (#428)
2ef4d3e
chore(deps): update nt-time requirement from 0.10.6 to 0.12.1 (#427)
9cf28cb
test(ci): Fix: rename can't be skipped
5987cdd
test(ci): Fix: need recursive rename
74f8a3c
test(ci): Need to rename more files during fuzz runs
- Additional commits viewable in compare
view
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
Signed-off-by: dependabot[bot]
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
---
rust/Cargo.lock | 4 ++--
rust/Cargo.toml | 2 +-
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/rust/Cargo.lock b/rust/Cargo.lock
index 94dcec338..bf110c243 100644
--- a/rust/Cargo.lock
+++ b/rust/Cargo.lock
@@ -10117,9 +10117,9 @@ dependencies = [
[[package]]
name = "zip"
-version = "5.1.1"
+version = "6.0.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
-checksum = "2f852905151ac8d4d06fdca66520a661c09730a74c6d4e2b0f27b436b382e532"
+checksum = "eb2a05c7c36fde6c09b08576c9f7fb4cda705990f73b58fe011abf7dfb24168b"
dependencies = [
"arbitrary",
"crc32fast",
diff --git a/rust/Cargo.toml b/rust/Cargo.toml
index 33a543d20..e35570235 100644
--- a/rust/Cargo.toml
+++ b/rust/Cargo.toml
@@ -224,7 +224,7 @@ windows-implement = "0.60.0"
windows-service = "0.8.0"
winreg = "0.55.0"
zbus = "5.11.0"
-zip = { version = "5", default-features = false }
+zip = { version = "6", default-features = false }
[workspace.lints.clippy]
dbg_macro = "warn"