Skip to content

chore(cargo deps): Bump candid from 0.10.35 to 0.10.36 - #245

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/candid-0.10.36
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/candid-0.10.36

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps candid from 0.10.35 to 0.10.36.

Changelog

Sourced from candid's changelog.

Candid 0.10.36

  • Bug fixes:
    • Scope the decode fast paths of a map to their own half of an entry, so a map entry's key and value each decode under their own declared type. deserialize_map derives a big-integer fast path from the map's value type and a text fast path from its key type; each previously stayed active for the whole entry. The big-integer path is now cleared for the duration of the key and restored for the value, the text path is cleared for the duration of the value, and the value's expected and wire types are re-established on every entry. Each half of an entry therefore goes through its own type's entry point, keeping its own encoding (SLEB128 for int, LEB128 for nat) and its own subtype check, for every combination of key and value type — including a value whose type shares an encoding with the key's, such as blob against text. The wire format is unchanged, and entries whose key and value types agree decode identically.
    • Share the undecoded argument queue behind a reference count. The option/backtracking path snapshots the deserializer to restore on a subtype mismatch, which previously copied the whole queue of remaining arguments on every present opt. The queue is only mutated at the top level, so it is now shared rather than copied and the snapshot is a refcount bump. Skipping many present optional arguments is no longer superlinear in the argument count; the decode result is unchanged.

2026-08-14

candid_parser 0.4.1

  • Bug fixes:
    • Escape the method names of a service type in the Rust binding. A Candid method name is an arbitrary text value, but pp_ty_service emitted it raw between the quotes of a Rust string literal inside candid::define_service!. A name containing " therefore closed the literal and the macro invocation, and the rest of the name was compiled as Rust — a .did file could inject arbitrary items into the bindings generated from it, and from there into the consumer's binary. Names are now escaped with escape_debug, as pp_function and the #[serde(rename)] attributes already were. The value seen by define_service! is unchanged, and names that are ordinary identifiers generate byte-identical output.

2026-08-11

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [candid](https://github.com/dfinity/candid) from 0.10.35 to 0.10.36.
- [Release notes](https://github.com/dfinity/candid/releases)
- [Changelog](https://github.com/dfinity/candid/blob/master/CHANGELOG.md)
- [Commits](https://github.com/dfinity/candid/commits)

---
updated-dependencies:
- dependency-name: candid
  dependency-version: 0.10.36
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update Rust code labels Sep 28, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 28, 2026 14:45
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update Rust code labels Sep 28, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #246.

@dependabot dependabot Bot closed this Oct 5, 2026
@dependabot
dependabot Bot deleted the dependabot/cargo/candid-0.10.36 branch October 5, 2026 14:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update Rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants