Skip to content

build(deps): bump act-types from 0.14.1 to 0.14.2 - #57

Merged
GamePad64 merged 1 commit into
mainfrom
dependabot/cargo/act-types-0.14.2
Oct 4, 2026
Merged

GamePad64 merged 1 commit into
mainfrom
dependabot/cargo/act-types-0.14.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Bumps act-types from 0.14.1 to 0.14.2.

Changelog

Sourced from act-types's changelog.

[0.14.2] - 2026-09-23

This patch release contains two breaking changes, both in act-sdk: a credential accessor that assumed field names is gone, and the consent check can no longer be called with its polarity backwards. A component depending on act-sdk = "0.14" picks it up on cargo update; one that calls Secret::as_basic or passes a bool to consent::check stops compiling. Pin =0.14.1 to stay where you are.

Added

  • Helpers for an act:consent call site (act_sdk::consent). The SDK cannot make the host call itself — bindgen expands in the component's crate — so these are the parts around it: encoding the request args, and turning the decision into a Result that short-circuits with ?. A refusal converts into ActError as std:capability-denied.
  • impl_consent_decision!, which implements the new ConsentDecision trait for a component's own generated Decision enum. See Changed for why.

Changed

  • consent::check takes the decision, not a bool. It is now check<D: ConsentDecision>. The bool form let matches!(d, Decision::Deny) compile and proceed on a refusal — a polarity mistake already in circulation in examples. The bool-taking function survives as check_allowed, under a name that cannot be mistaken for the trait form.
  • The consent args encoder accepts exactly the maps the host accepts. It used to let through non-text keys, non-finite floats and out-of-range integers, which the host silently drops.
  • wit-bindgen 0.60 → 0.62 and wasip3 0.7.1 → 0.9.0, bumped together so one generator version resolves. Components built with the SDK still export tool-provider as async func and still import wasi:http@0.3.0.
  • syn 3 and darling 0.24 in act-sdk-macros, and base64 0.23 in act-types.

Removed

  • Secret::as_basic. Read credential fields by the names your component asked for, with field_str. ACT-CONSTANTS.md no longer registers credential field names, so an accessor keyed on std:username / std:password assumed a vocabulary that does not exist. as_oauth2 stays: it takes the field name from the caller.

[0.14.0] - 2026-08-11

Added

  • std.author and std.license on component metadata (StdComponentInfo). Both optional; act-build fills them from the language manifest (Cargo.toml [package], pyproject.toml [project], package.json), and an act.toml [std] entry overrides it. Omitted from the CBOR section when absent, and sections written before this release still parse.
  • act_sdk::spawn_local — re-exported from wit-bindgen, for tools that need to run a task concurrently with the call they are serving (e.g. filling a

... (truncated)

Commits
  • b5e2cff Release 0.14.2
  • 15b955f build(deps): syn 3 and darling 0.24 in act-sdk-macros
  • ca4716f build(deps): refresh the lockfile, base64 0.22 -> 0.23
  • 0522985 deps: wit-bindgen 0.60 -> 0.62, wasip3 0.7.1 -> 0.9.0
  • edf9216 build: refuse cfg-if and assert_matches, which std now replaces
  • 399d0fb docs(examples): credentials is not the only host-import interface
  • 55fdc6a ci: run act-sdk's tests and clippy
  • 3c3be36 fix(act-sdk)!: make consent::check() fail-closed on decision polarity
  • 0627161 docs(sdk): correct consent metadata round-trip claims
  • ac8a625 docs(sdk): worked example of a consent call site
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 3, 2026
@socket-security

socket-security Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedcargo/​act-types@​0.14.1 ⏵ 0.14.210010093100100

View full report

Bumps [act-types](https://github.com/actcore/act-sdk-rs) from 0.14.1 to 0.14.2.
- [Changelog](https://github.com/actcore/act-sdk-rs/blob/main/CHANGELOG.md)
- [Commits](actcore/act-sdk-rs@0.14.1...0.14.2)

---
updated-dependencies:
- dependency-name: act-types
  dependency-version: 0.14.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/cargo/act-types-0.14.2 branch from 54d5da1 to dd20c5e Compare October 3, 2026 11:49
@GamePad64
GamePad64 merged commit 8b76b33 into main Oct 4, 2026
45 checks passed
@GamePad64
GamePad64 deleted the dependabot/cargo/act-types-0.14.2 branch October 4, 2026 10:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant