Skip to content

Bump maxminddb from 0.30.3 to 0.32.0 in the major group - #267

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/cargo/major-74695035d6
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/cargo/major-74695035d6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the major group with 1 update: maxminddb.

Updates maxminddb from 0.30.3 to 0.32.0

Release notes

Sourced from maxminddb's releases.

0.32.0

  • Reused precharged map-key bytes for raw identifier decoding, avoiding a second header parse while preserving payload limits and other Serde entry points. Added raw-string adapter and generic JSON decoding benchmarks.
  • Breaking: Removed the simdutf8 feature and its optional dependency. It did not improve lookup performance in benchmarks using production GeoIP2 City and Country databases. Remove simdutf8 from dependency feature lists when upgrading.
  • Improved record decoding performance by reducing internal error storage and streamlining pointer and payload decoding. Public error types and validation limits are unchanged.
  • Fixed decoder cursor restoration when a typed pointer exceeds the nesting limit.
  • Improved search-tree lookup performance for 24-bit and 28-bit databases by reading each child pointer from a single word within the node.
  • Improved decode_path() performance by specializing map-key header decoding for inline strings and all pointer widths, including long keys.

0.31.0

  • Fixed a denial-of-service issue when decoding records or metadata. A crafted database could repeatedly reference shared data, causing excessive CPU and memory use. Decoding now limits the number of values and the amount of string and byte data expanded in a single operation. Operations that exceed these limits return MaxMindDbError::ResourceLimit.
  • Limited subdivision lists in the built-in City and Enterprise types to 32 entries to prevent excessive allocation from untrusted data.
  • Reader::verify() now checks data referenced by unknown metadata fields.
  • Limited the work performed by Reader::verify() to prevent excessive CPU use from databases with overlapping string payloads. Verification returns MaxMindDbError::ResourceLimit when this limit is exceeded.
  • Improved record decoding performance by accelerating short ASCII string validation and inlining decoding entry points.
Changelog

Sourced from maxminddb's changelog.

0.32.0 - 2026-09-12

  • Reused precharged map-key bytes for raw identifier decoding, avoiding a second header parse while preserving payload limits and other Serde entry points. Added raw-string adapter and generic JSON decoding benchmarks.
  • Breaking: Removed the simdutf8 feature and its optional dependency. It did not improve lookup performance in benchmarks using production GeoIP2 City and Country databases. Remove simdutf8 from dependency feature lists when upgrading.
  • Improved record decoding performance by reducing internal error storage and streamlining pointer and payload decoding. Public error types and validation limits are unchanged.
  • Fixed decoder cursor restoration when a typed pointer exceeds the nesting limit.
  • Improved search-tree lookup performance for 24-bit and 28-bit databases by reading each child pointer from a single word within the node.
  • Improved decode_path() performance by specializing map-key header decoding for inline strings and all pointer widths, including long keys.

0.31.0 - 2026-09-07

  • Fixed a denial-of-service issue when decoding records or metadata. A crafted database could repeatedly reference shared data, causing excessive CPU and memory use. Decoding now limits the number of values and the amount of string and byte data expanded in a single operation. Operations that exceed these limits return MaxMindDbError::ResourceLimit.
  • Limited subdivision lists in the built-in City and Enterprise types to 32 entries to prevent excessive allocation from untrusted data.
  • Reader::verify() now checks data referenced by unknown metadata fields.
  • Limited the work performed by Reader::verify() to prevent excessive CPU use from databases with overlapping string payloads. Verification returns MaxMindDbError::ResourceLimit when this limit is exceeded.
  • Improved record decoding performance by accelerating short ASCII string validation and inlining decoding entry points.
Commits
  • b0e5d54 Prepare v0.32.0 release
  • 88adf14 Set release date
  • d066b16 Merge pull request #130 from oschwald/optimize-map-key-decoding
  • 41c3697 Expand Dependabot coverage
  • c91c5b5 Reuse precharged map keys for raw identifiers
  • 4e47001 Merge pull request #129 from oschwald/greg/repo-cleanup
  • be7230d Document automatic benchmark report generation
  • dee93e8 Deduplicate the mmap dependency example
  • 4300698 Remove redundant TryInto import
  • f254660 Remove inferred Cargo manifest settings
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the major group with 1 update: [maxminddb](https://github.com/oschwald/maxminddb-rust).


Updates `maxminddb` from 0.30.3 to 0.32.0
- [Release notes](https://github.com/oschwald/maxminddb-rust/releases)
- [Changelog](https://github.com/oschwald/maxminddb-rust/blob/main/CHANGELOG.md)
- [Commits](oschwald/maxminddb-rust@v0.30.3...v0.32.0)

---
updated-dependencies:
- dependency-name: maxminddb
  dependency-version: 0.32.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants