cargo-crev
cargo-crev copied to clipboard
Bump ed25519-dalek from 1.0.1 to 2.1.1
Bumps ed25519-dalek from 1.0.1 to 2.1.1.
Changelog
Sourced from ed25519-dalek's changelog.
2.1.1
- Update the optional
packed-simd
dependency to rely on a newer, maintained version of thepacked-simd-2
crate.2.1.0
- Make
Scalar::from_bits
aconst fn
, allowing its use inconst
contexts.2.0.0
- Fix a data modeling error in the
serde
feature pointed out by Trevor Perrin which caused points and scalars to be serialized with length fields rather than as fixed-size 32-byte arrays. This is a breaking change, but it fixes compatibility withserde-json
and ensures that theserde-bincode
encoding matches the conventional encoding for X/Ed25519.- Update
rand_core
to0.5
, allowing use with newrand
versions.- Switch from
clear_on_drop
tozeroize
(by Tony Arcieri).- Require
subtle = ^2.2.1
and remove the note advising nightly Rust, which is no longer required as of that version ofsubtle
. See thesubtle
changelog for more details.- Update
README.md
for2.x
series.- Remove the
build.rs
hack which loaded the entire crate into its ownbuild.rs
to generate constants, and keep the constants in the source code.The only significant change is the data model change to the
serde
feature; besides therand_core
version bump, there are no other user-visible changes.1.x series
1.2.4
- Specify a semver bound for
clear_on_drop
rather than an exact version, addressing an issue where changes to inline assembly in rustc preventedclear_on_drop
from working without an update.1.2.3
- Fix an issue identified by a Quarkslab audit (and Jack Grigg), where manually constructing unreduced
Scalar
values, as needed for X/Ed25519, and then performing scalar/scalar arithmetic could compute incorrect results.- Switch to upstream Rust intrinsics for the IFMA backend now that they exist in Rust and don't need to be defined locally.
- Ensure that the NAF computation works correctly, even for parameters never used elsewhere in the codebase.
- Minor refactoring to EdwardsPoint decompression.
- Fix broken links in documentation.
- Fix compilation on nightly broken due to changes to the
#[doc(include)]
path root (not quite correctly done in 1.2.2).
... (truncated)
Commits
0f07443
Bump curve25519-dalek to 2.1.1.bb889e4
Remove deprecated feature flags from .travis.yml.d00d4a5
Fix CHANGELOG so that we can note backported patches.e6d8afc
Add link to Cargo.toml with explanation of packed_simd renamingdd71df6
adjusted dependency entry like to pick up latest pick up the latest packed_si...6ffc8dd
bumped packed_simd to 0.3.4. resolves #3333fc47ef
Bump version to 2.1.0f04b830
Merge branch 'master' into develope342f25
Merge pull request #325 from rubdos/const_fn_for_scalar_from_bits3a61a0b
Make Scalar::from_bits a const fn.- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)