Update Rust crate quick-xml to 0.41.0 #65
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/quick-xml-0.x"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
0.40.0→0.41.0Release Notes
tafia/quick-xml (quick-xml)
v0.41.0Compare Source
New Features
NsReader::resolver_mut()andNamespaceResolver::{max_declarations_per_element, set_max_declarations_per_element}.Bug Fixes
Attributes(and anything that iteratesBytesStart::attributes()with the default
with_checks(true)) no longer takes O(N²) time on a starttag with a large number of attributes. Small tags keep the previous linear
scan; larger ones switch to a 64-bit hash pre-filter, so the whole tag is
O(N). The exact
AttrError::Duplicated(new, prev)positions are unchanged.NamespaceResolver::push(and hence everyNsReaderStart/Emptyevent) now rejects a start tag that declares more than
DEFAULT_MAX_DECLARATIONS_PER_ELEMENT(256)xmlns/xmlns:*namespacebindings, returning the new
NamespaceError::TooManyDeclarations. Previouslypushallocated oneNamespaceBindingper declaration with no upper bound,before the event was returned to the caller, so an
NsReaderconsumer couldnot bound its memory exposure on untrusted input. The limit is configurable
via
NamespaceResolver::set_max_declarations_per_element(useusize::MAXto disable).
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate.
fc3000cec935a3e27591