Skip to content

ci(deps): bump aws-sigv4 from 1.5.3 to 1.6.0 in the cargo group - #46

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-9ac051b9f8
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-9ac051b9f8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the cargo group with 1 update: aws-sigv4.

Updates aws-sigv4 from 1.5.3 to 1.6.0

Changelog

Sourced from aws-sigv4's changelog.

September 24th, 2026

New this release:

  • 🎉 (all, smithy-rs#4473) Add Smithy RPC v2 CBOR serialization and deserialization support for BigDecimal values.

  • 🐛🎉 (all) A response header value that is not valid UTF-8 no longer fails the whole response.

    An HTTP header value may contain any octet in 0x80..=0xFF (obs-text, RFC 7230), and an arbitrary sequence of those is not necessarily valid UTF-8, so a service can send a value that is not representable as a Rust String. Previously one such value failed the entire response during the HTTP-to-SDK conversion. That happened before deserialization, whether or not anything read that header, and surfaced as a non-retryable DispatchFailure.

    Header values are now stored as received, and the encoding requirement applies where a value is bound to a modeled member. A header bound to no member is harmless. A header bound to a member reports an error naming that member on the client, or a 400 on the server. Nothing is dropped silently.

    For servers this narrows what gets rejected rather than changing the status. A non-UTF-8 value bound to a member was already a 400 and still is; it is now detected at the member binding instead of when the request was converted. A request carrying a non-UTF-8 header that no modeled member is bound to used to be rejected and is now accepted.

    Headers gained byte accessors that return every value, alongside the existing string accessors, which now skip values that are not valid UTF-8:

    • Headers::get_bytes, Headers::get_all_bytes, Headers::iter_bytes
    • HeaderValue::as_bytes, HeaderValue::try_as_str

    Headers::get returns None both for an absent header and for one whose value is not valid UTF-8. Use Headers::try_get where the difference matters: it returns Some(Ok(_)), Some(Err(raw_octets)) and None respectively. Note also that Headers::len and Headers::contains_key count and report values the string accessors skip.

    To tolerate an unreadable value rather than fail, put NonUtf8HeaderHandling::Skip in the config bag from an interceptor. The member then deserializes as if the header were absent, and because the header is left in place the octets stay readable, so a caller that needs the value can decode it however its service encodes it:

    /// Whatever decoding this service's encoding calls for.
    fn decode_latin1(bytes: &[u8]) -> String { /* ... */ }
    #[derive(Clone, Debug, Default)]
    struct ContentDispositionAsLatin1 {
    value: Arc<Mutex<Option<String>>>,
    }
    impl Intercept for ContentDispositionAsLatin1 {
    fn name(&self) -> &'static str {
    "ContentDispositionAsLatin1"
    }
    fn read_before_execution(
        &amp;self,
        _context: &amp;BeforeSerializationInterceptorContextRef&lt;'_&gt;,
        cfg: &amp;mut ConfigBag,
    ) -&gt; Result&lt;(), BoxError&gt; {
        cfg.interceptor_state().store_put(NonUtf8HeaderHandling::Skip);
        Ok(())
    }
    fn read_after_deserialization(
    &amp;self,
    context: &amp;AfterDeserializationInterceptorContextRef&lt;'_&gt;,
    _runtime_components: &amp;RuntimeComponents,
    _cfg: &amp;mut ConfigBag,

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the cargo group with 1 update: [aws-sigv4](https://github.com/smithy-lang/smithy-rs).


Updates `aws-sigv4` from 1.5.3 to 1.6.0
- [Release notes](https://github.com/smithy-lang/smithy-rs/releases)
- [Changelog](https://github.com/smithy-lang/smithy-rs/blob/main/CHANGELOG.md)
- [Commits](https://github.com/smithy-lang/smithy-rs/commits)

---
updated-dependencies:
- dependency-name: aws-sigv4
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 30, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

Looks like aws-sigv4 is updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 7, 2026
@dependabot
dependabot Bot deleted the dependabot/cargo/cargo-9ac051b9f8 branch October 7, 2026 04:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants