From 22d8037bb5540c1e030566a5a0915b8c7cb4a68a Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 3 Oct 2026 19:02:56 +0000 Subject: [PATCH 1/2] chore(deps): bump the rust group across 1 directory with 2 updates Bumps the rust group with 2 updates in the / directory: [sdl3](https://github.com/vhspace/sdl3-rs) and [ureq](https://github.com/algesten/ureq). Updates `sdl3` from 0.18.4 to 0.20.0 - [Release notes](https://github.com/vhspace/sdl3-rs/releases) - [Changelog](https://github.com/vhspace/sdl3-rs/blob/master/CHANGELOG.md) - [Commits](https://github.com/vhspace/sdl3-rs/compare/v0.18.4...v0.20.0) Updates `ureq` from 3.4.0 to 3.4.2 - [Changelog](https://github.com/algesten/ureq/blob/main/CHANGELOG.md) - [Commits](https://github.com/algesten/ureq/compare/3.4.0...3.4.2) --- updated-dependencies: - dependency-name: sdl3 dependency-version: 0.20.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: rust - dependency-name: ureq dependency-version: 3.4.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: rust ... Signed-off-by: dependabot[bot] --- Cargo.lock | 40 ++++++++++++++++++++-------------------- Cargo.toml | 2 +- 2 files changed, 21 insertions(+), 21 deletions(-) diff --git a/Cargo.lock b/Cargo.lock index bb8e2ab..8658c90 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -548,9 +548,9 @@ dependencies = [ [[package]] name = "sdl3" -version = "0.18.4" +version = "0.20.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "25bd22eb1bbc9137e914022b4994ed35591eea0884e9e3e98e6d9895cad6e1d2" +checksum = "f90c470b564b34e7f9ff0719ed7dc05ec71bc73fa4b28e0750a17b8987cf45f8" dependencies = [ "bitflags", "libc", @@ -562,15 +562,15 @@ dependencies = [ [[package]] name = "sdl3-image-src" -version = "3.4.4" +version = "3.4.6" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "fe273101c7dab94551183212eee9adef1a7bf274d407f0b7bfe72482960ab25c" +checksum = "bd9494480b91011c3eff1d15235a30c34f758ac4ee6b0a97579b0291d4fc2c85" [[package]] name = "sdl3-image-sys" -version = "0.6.4+SDL-image-3.4.4" +version = "0.7.0+SDL-image-3.4.6" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "5a445f781b39a1c1bc751f5f4612191e0402006e35ad5d02d9193281afad1cf4" +checksum = "e12eec1cd8dcb6be4430976d9b01ae1dcccc674aea5f5ca2bd7ffb2c881ed79d" dependencies = [ "cmake", "pkg-config", @@ -588,9 +588,9 @@ checksum = "9cd815ae87084588c7dbd027c1667b0a5e21a6b5ae7b22ecb230bc21c7063eca" [[package]] name = "sdl3-mixer-sys" -version = "0.6.3+SDL-mixer-3.2.4" +version = "0.7.0+SDL-mixer-3.2.4" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "2b5a157588924cf886bdc3a7c9d0e478cdad35d315740f26af00609a61e7c327" +checksum = "6150136321198ec95cccfb6168d838f114273a7615d21b513e5277c86f7d3aa1" dependencies = [ "cmake", "pkg-config", @@ -602,15 +602,15 @@ dependencies = [ [[package]] name = "sdl3-src" -version = "3.4.14" +version = "3.4.18" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "e75661ac9dbedc58da5ce739e9688be6bf9d5542a282d89e7e29fdb7dcb43936" +checksum = "400d0fb006a4485fde477cfc56a250c99d7bfb183fefd145c15fe7607db7fc49" [[package]] name = "sdl3-sys" -version = "0.6.8+SDL-3.4.14" +version = "0.7.2+SDL-3.4.18" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "b97e3d18c4994224aec3fb2d3d189f5fc88af0958fb8ed7b569272fde558f033" +checksum = "82b6a7f3cad40c5b318b3539bb4624389f4a03504cd5f4c65030787b962505ac" dependencies = [ "cc", "cmake", @@ -622,15 +622,15 @@ dependencies = [ [[package]] name = "sdl3-ttf-src" -version = "3.2.2" +version = "3.2.3" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "e8deaa09c46d6aa8e8a81a601eb4685b2a57f2ce8a4ea3c59e8b623b526d1125" +checksum = "f28923d2ce72ff317d8eb7cec97ddfb8f351c330d7bcbf8c76e91332122c93b3" [[package]] name = "sdl3-ttf-sys" -version = "0.6.1+SDL-ttf-3.2.2" +version = "0.7.1+SDL-ttf-3.2.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "8137096072109d6c834d4cb30b8a617ded4f150c7766757eddc834108bbcefd2" +checksum = "d254e537d2d96b3e2d6e8a3dd4850a1361b8689c3d95c6c1dfdc02b091307eef" dependencies = [ "cmake", "pkg-config", @@ -744,9 +744,9 @@ checksum = "8ecb6da28b8a351d773b68d5825ac39017e680750f980f3a1a85cd8dd28a47c1" [[package]] name = "ureq" -version = "3.4.0" +version = "3.4.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "972d7902c8735f2695410b8aed7df6ed12a47394aa1c8d7af49f0497b731a94d" +checksum = "9a7ac20be9b7726e0bbdbf974c059676d9acb1cd414961f570a4e8231cacd7fc" dependencies = [ "base64", "flate2", @@ -761,9 +761,9 @@ dependencies = [ [[package]] name = "ureq-proto" -version = "0.6.1" +version = "0.6.4" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "da5f78b09e6941e1a0f2e30e695e4b120377b54d5e0aec11b594bb57b3971613" +checksum = "f86fd172ccca569e458f61b6bdd6220965a9ef36e672a6852953b51a0e1583be" dependencies = [ "base64", "http", diff --git a/Cargo.toml b/Cargo.toml index 2792148..6cbca66 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -32,7 +32,7 @@ atrinik-session = { path = "crates/atrinik-session", version = "=0.1.0" } atrinik-testkit = { path = "crates/atrinik-testkit", version = "=0.1.0" } atrinik-ui-model = { path = "crates/atrinik-ui-model", version = "=0.1.0" } httpdate = "1.0.3" -sdl3 = { version = "0.18.4", default-features = false, features = ["build-from-source-static"] } +sdl3 = { version = "0.20.0", default-features = false, features = ["build-from-source-static"] } sha2 = "0.11.0" ureq = { version = "3.4.0", default-features = false, features = ["gzip", "rustls"] } From 4e8daef6ebd9c059a862ff89246a1dd6500da236 Mon Sep 17 00:00:00 2001 From: Zoey Rose Date: Sat, 3 Oct 2026 14:13:32 -0500 Subject: [PATCH 2/2] fix(deps): align SDL 3.4.18 metadata --- README.md | 6 +++--- THIRD_PARTY_NOTICES.md | 2 +- docs/PLATFORM.md | 2 +- policy/dependencies.json | 2 +- tools/package-linux.sh | 2 +- tools/package-windows.ps1 | 2 +- 6 files changed, 8 insertions(+), 8 deletions(-) diff --git a/README.md b/README.md index 308bd19..780f615 100644 --- a/README.md +++ b/README.md @@ -57,7 +57,7 @@ configured direct connections. See the [directory contract](docs/DIRECTORY.md). ## Build and test -Rust 1.97.1 is pinned. SDL 3.4.14 is acquired reproducibly from the checksummed +Rust 1.97.1 is pinned. SDL 3.4.18 is acquired reproducibly from the checksummed `sdl3-src` crate and linked statically; no ambient system SDL is selected. Linux builders need the desktop, audio, input, and GPU development headers listed in `tools/install-linux-native-deps.sh`; CI installs them from the @@ -86,8 +86,8 @@ existing tagged release without rebuilding from another revision. | Target | SDL3 | Window validation | Renderer backend | | --- | --- | --- | --- | -| Linux x86-64 | 3.4.14 static source build | headless dummy plus optional desktop window | Vulkan contract recorded; exercised when released renderer lands | -| Windows x86-64 MSVC | 3.4.14 static source build | compile/tests in CI; interactive smoke on release host | D3D12 contract recorded; exercised when released renderer lands | +| Linux x86-64 | 3.4.18 static source build | headless dummy plus optional desktop window | Vulkan contract recorded; exercised when released renderer lands | +| Windows x86-64 MSVC | 3.4.18 static source build | compile/tests in CI; interactive smoke on release host | D3D12 contract recorded; exercised when released renderer lands | Logical UI coordinates are integer-independent from physical pixels; SDL display scale is represented as bounded thousandths. Focus, suspend, full-screen, diff --git a/THIRD_PARTY_NOTICES.md b/THIRD_PARTY_NOTICES.md index 2c20fc3..2822019 100644 --- a/THIRD_PARTY_NOTICES.md +++ b/THIRD_PARTY_NOTICES.md @@ -7,7 +7,7 @@ Resolved versions are recorded only in `Cargo.lock`. | --- | --- | --- | --- | | `atrinik-protocol` | none | `MIT` | https://crates.io/crates/atrinik-protocol | | `httpdate` | none | `MIT OR Apache-2.0` | https://crates.io/crates/httpdate | -| `sdl3` | SDL 3.4.14 | `MIT AND Zlib` | https://crates.io/crates/sdl3 | +| `sdl3` | SDL 3.4.18 | `MIT AND Zlib` | https://crates.io/crates/sdl3 | | `sha2` | none | `MIT OR Apache-2.0` | https://crates.io/crates/sha2 | | `ureq` | none | `MIT OR Apache-2.0` | https://crates.io/crates/ureq | diff --git a/docs/PLATFORM.md b/docs/PLATFORM.md index 9ce7e97..be42cb1 100644 --- a/docs/PLATFORM.md +++ b/docs/PLATFORM.md @@ -1,6 +1,6 @@ # SDL3 platform contract -SDL 3.4.14 comes from `sdl3-src` through the Cargo-locked `sdl3` 0.18.4. +SDL 3.4.18 comes from `sdl3-src` through the Cargo-locked `sdl3` 0.20.0. Linux and Windows use static source builds so clean clones do not depend on an unversioned system SDL. Packages record the SDL license/notice and native graph. diff --git a/policy/dependencies.json b/policy/dependencies.json index 6be5b5b..257ea38 100644 --- a/policy/dependencies.json +++ b/policy/dependencies.json @@ -8,7 +8,7 @@ "direct_dependencies": [ {"name":"atrinik-protocol","native":null,"license":"MIT","source":"https://crates.io/crates/atrinik-protocol","purpose":"released Game Protocol 1 static-directory parser and bounds","validation":"Cargo.lock, protocol fixtures, cargo-deny, unit tests, SBOM"}, {"name":"httpdate","native":null,"license":"MIT OR Apache-2.0","source":"https://crates.io/crates/httpdate","purpose":"strict static-directory Last-Modified and Retry-After handling","validation":"Cargo.lock, cargo-deny, metadata boundary tests, SBOM"}, - {"name":"sdl3","native":"SDL 3.4.14","license":"MIT AND Zlib","source":"https://crates.io/crates/sdl3","purpose":"isolated platform/window/input/audio boundary","validation":"Cargo.lock, cargo-deny, source-static build, Linux/Windows checks"}, + {"name":"sdl3","native":"SDL 3.4.18","license":"MIT AND Zlib","source":"https://crates.io/crates/sdl3","purpose":"isolated platform/window/input/audio boundary","validation":"Cargo.lock, cargo-deny, source-static build, Linux/Windows checks"}, {"name":"sha2","native":null,"license":"MIT OR Apache-2.0","source":"https://crates.io/crates/sha2","purpose":"authenticated resource and static-directory body/cache identity digest verification","validation":"Cargo.lock, cargo-deny, unit tests, SBOM"}, {"name":"ureq","native":null,"license":"MIT OR Apache-2.0","source":"https://crates.io/crates/ureq","purpose":"bounded blocking HTTPS retrieval of the fixed static directory origin","validation":"Cargo.lock, cargo-deny, fixed-request transport tests, Linux/Windows builds, SBOM"} ], diff --git a/tools/package-linux.sh b/tools/package-linux.sh index d554667..b3df730 100755 --- a/tools/package-linux.sh +++ b/tools/package-linux.sh @@ -20,7 +20,7 @@ git archive --format=tar --prefix="atrinik-client-${version}/" HEAD | gzip -n >" SYFT_CHECK_FOR_APP_UPDATE=false syft dir:"${stage}" --source-name atrinik-client --source-version "${version}" --output "cyclonedx-json=${output}/atrinik-client-${version}-linux-amd64.sbom.cdx.json" if grep -Eiq 'AGPL-[123]|GPL-[123]' "${output}/atrinik-client-${version}-linux-amd64.sbom.cdx.json"; then echo "forbidden reciprocal license in SBOM" >&2; exit 1; fi if [[ $(jq '.components | length' "${output}/atrinik-client-${version}-linux-amd64.sbom.cdx.json") -lt 10 ]]; then echo "release SBOM is missing the effective Rust graph" >&2; exit 1; fi -jq -n --arg version "${version}" --arg revision "${revision}" --arg rust "$(rustc --version)" '{schema_version:1,version:$version,revision:$revision,target:"x86_64-unknown-linux-gnu",rust:$rust,sdl:"3.4.14 static",protocol:"game-protocol-1",renderer:"scene-snapshot-1",symbols:"stripped; private symbol packages begin in M6"}' >"${output}/atrinik-client-${version}-linux-amd64.provenance.json" +jq -n --arg version "${version}" --arg revision "${revision}" --arg rust "$(rustc --version)" '{schema_version:1,version:$version,revision:$revision,target:"x86_64-unknown-linux-gnu",rust:$rust,sdl:"3.4.18 static",protocol:"game-protocol-1",renderer:"scene-snapshot-1",symbols:"stripped; private symbol packages begin in M6"}' >"${output}/atrinik-client-${version}-linux-amd64.provenance.json" ( cd "${output}" sha256sum "atrinik-client-${version}-linux-amd64.tar.gz" "atrinik-client-${version}-linux-amd64.sbom.cdx.json" "atrinik-client-${version}-linux-amd64.provenance.json" "atrinik-client-${version}-source.tar.gz" >"atrinik-client-${version}-linux-amd64.SHA256SUMS" diff --git a/tools/package-windows.ps1 b/tools/package-windows.ps1 index f03a1fd..9633298 100644 --- a/tools/package-windows.ps1 +++ b/tools/package-windows.ps1 @@ -17,6 +17,6 @@ Compress-Archive -Path "$stage/*" -DestinationPath $archive -CompressionLevel Op syft "dir:$stage" --source-name atrinik-client --source-version $Version --output "cyclonedx-json=$(Join-Path $Output "atrinik-client-$Version-windows-amd64.sbom.cdx.json")" $sbom = Get-Content (Join-Path $Output "atrinik-client-$Version-windows-amd64.sbom.cdx.json") | ConvertFrom-Json if ($sbom.components.Count -lt 10) { throw "release SBOM is missing the effective Rust graph" } -[ordered]@{schema_version=1;version=$Version;revision=$revision;target="x86_64-pc-windows-msvc";rust=(rustc --version);sdl="3.4.14 static";protocol="game-protocol-1";renderer="scene-snapshot-1";symbols="stripped public package; private symbol packages begin in M6"} | ConvertTo-Json -Compress | Set-Content -Encoding utf8 (Join-Path $Output "atrinik-client-$Version-windows-amd64.provenance.json") +[ordered]@{schema_version=1;version=$Version;revision=$revision;target="x86_64-pc-windows-msvc";rust=(rustc --version);sdl="3.4.18 static";protocol="game-protocol-1";renderer="scene-snapshot-1";symbols="stripped public package; private symbol packages begin in M6"} | ConvertTo-Json -Compress | Set-Content -Encoding utf8 (Join-Path $Output "atrinik-client-$Version-windows-amd64.provenance.json") Get-ChildItem $Output -File | Sort-Object Name | ForEach-Object { "{0} {1}" -f (Get-FileHash -Algorithm SHA256 $_.FullName).Hash.ToLowerInvariant(), $_.Name } | Set-Content -Encoding ascii (Join-Path $Output "atrinik-client-$Version-windows-amd64.SHA256SUMS") Remove-Item -Recurse -Force $stage