Skip to content

chore(deps): bump the pub-minor-and-patch group across 1 directory with 7 updates - #298

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pub/pub-minor-and-patch-8d284b7c00
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pub/pub-minor-and-patch-8d284b7c00

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the pub-minor-and-patch group with 7 updates in the / directory:

Package From To
archive 4.0.9 4.3.0
dio 5.11.0 5.11.1
flutter_file_dialog 3.3.2 3.3.3
flutter_onnxruntime 1.8.3 1.8.5
html 0.15.6 0.15.7
mime 2.0.0 2.1.0
yaml 3.1.3 3.1.4

Updates archive from 4.0.9 to 4.3.0

Changelog

Sourced from archive's changelog.

4.3.0

  • Added multithreaded decoding to XZDecoder. Passing an XZMultithreadOptions to decodeBytes or decodeStream spreads the work over isolates, one xz block per job, and reports the result through its onDone callback. Both methods behave exactly as before when it is omitted. On a 1.1 GB archive of six blocks: 16.1 s single threaded, 8.0 s on the default three workers, 5.0 s on six.
  • decodeStream reading from an InputFileStream now lets each worker read its own block straight from disk, so the compressed archive never passes through the calling isolate. Decoding a 1.1 GB archive to an OutputFileStream peaks at 1.8 GB, below the 3.0 GB the single threaded path uses, while being twice as fast.
  • Multithreaded decoding falls back to the single threaded path on the web, where there are no isolates, and the isolate machinery is tree-shaken out of web builds entirely.
  • Added InputFileStream.fileBuffer, fileOffset and fileLength.
  • Added --x86 flag support to XZDecoder
  • Improved verify: true speed for XZDecoder
  • Improved overall decode speed for XZDecoder
  • Decreased RAM usage for XZDecoder
  • Added concatenated streams support for XZDecoder
  • Added crc64 wasm support (verify: true)
  • Added uncompressedSize getter for XZDecoder, returning the original file size before compression.
  • Fix: pb=4 flag range error in XZDecoder
  • Fix: padding for _streamStart in XZDecoder
  • Added throwOnError to XZDecoder.decodeBytes and decodeStream. Without it a malformed or truncated archive still returns the partial output with nothing to say it is not the whole file, which was the only decode with no way at all to report a failure. In multithreaded mode the exception is delivered to XZMultithreadOptions.onError, and setting throwOnError without an onError is now refused rather than losing the failure.
  • Fix: a corrupt xz block lost the part of itself that had already decoded when verify: true was used with an output that cannot be read back, such as an OutputFileStream or any multithreaded decode. The output now stops in the same place whichever way the decode was asked for.
  • Added XZDecoder.maxPreallocateSize, capping how large an output buffer is allocated from a size the archive itself declares. Defaults to xzDefaultMaxPreallocateSize, 2 GB natively and 256 MB on the web.
  • Added XZMultithreadOptions.fileReadBufferSize.
  • Fix: an xz --check=none archive with corrupt blocks passed verify: true.
  • Fix: the xz block header reader trusted its own fields, accepting an unterminated multibyte integer, a filter properties length past the end of the header, empty delta or LZMA2 properties, and a bad stream header or footer CRC.
  • Fix: the zip End of Central Directory record was missed when its signature straddled a chunk of the backwards search, or sat within the last 21 bytes of the file, so a valid archive could decode as empty.

... (truncated)

Commits

Updates dio from 5.11.0 to 5.11.1

Release notes

Sourced from dio's releases.

dio 5.11.1

What's new

  • Fix response stream not propagating backpressure to the underlying socket. When a consumer paused the stream, the source subscription was never paused, so the network kept buffering response data into memory, risking OOM on constrained platforms.
  • Make the badCertificateCallback pinning test deterministic by pinning a fingerprint that cannot match the served certificate, instead of relying on badssl.com hosts serving different certificates.
  • Fix NoSuchMethodError when using a class that implements Interceptor instead of extends Interceptor. The interceptor pipeline was calling private dispatch methods that only exist on Interceptor subclasses, breaking any class using interface implementation.
Commits
  • 4684e29 🔖 dio v5.11.1
  • 96b10c7 🔖 web_adapter v2.2.2
  • 6d18c7c 🔖 http2_adapter v2.9.0
  • debe58c ✨ Deprecate misspelled handshakeTimout in favor of handshakeTimeout (#2595)
  • 6c1033e 🐛 Expose supportedProtocols on ConnectionManager to fix fallback for RFC-stri...
  • 6d39187 💚 Fail web test runs on the first failing compiler round (#2594)
  • a3238c3 fix(dio): support classes that implement Interceptor (#2591)
  • fd1cca0 fix(web): classify XHR timeout by connection phase (#2593)
  • 83fd107 💚 Adopt CI to Flutter 3.47 (#2592)
  • a553f46 Update README for clarity and remove star history (#2589)
  • Additional commits viewable in compare view

Updates flutter_file_dialog from 3.3.2 to 3.3.3

Changelog

Sourced from flutter_file_dialog's changelog.

3.3.3

  • [Android] Fix fatal "Reply already submitted" crash on devices without a documents provider (#60): startActivityForResult throwing ActivityNotFoundException left the dialog pending while Android still delivered RESULT_CANCELED, so the result was replied twice; the call now fails with an "activity_not_found" error
  • [Android] Removed the dead Android < 21 "minimum_target" guards from pickDirectory and saveFileToDirectory (minSdk is 24)
Commits
  • 259fca7 Fix fatal "Reply already submitted" crash on devices without a documents prov...
  • c90940d chore: exclude build and platform directories from analysis
  • See full diff in compare view

Updates flutter_onnxruntime from 1.8.3 to 1.8.5

Release notes

Sourced from flutter_onnxruntime's releases.

v1.8.5

What's Changed

Full Changelog: masicai/flutter_onnxruntime@v1.8.4...v1.8.5

v1.8.4

What's Changed

Full Changelog: masicai/flutter_onnxruntime@v1.8.3...v1.8.4

Changelog

Sourced from flutter_onnxruntime's changelog.

1.8.5

  • Support AGP 9 built-in Kotlin (#76)

1.8.4

  • Fix HardSwish and other function-defined ONNX operators returning all zeros on Linux under comma-decimal system locales such as German and French (#73, upstream onnx/onnx#8111)
Commits
  • 8e1c06f release: version 1.8.5
  • 102f426 Merge pull request #76 from masicai/fix/support_agp_9_built_in_kotlin
  • 59c9481 fix: keep the literal KGP apply so Flutter does not re-apply it
  • d100b00 fix: support AGP 9 built-in Kotlin by applying KGP conditionally (#75)
  • 8182e38 release: version 1.8.4
  • 2d6075e Merge pull request #74 from masicai/fix/locale_value_parsing_issue
  • 09e806c fix: extend C-locale guard to session creation
  • eabf64e test: add integration test for HardSwish issue
  • 7373c22 ci: add a regression test for the locale issue in #73
  • b47ff81 fix: create ORT env under thread-local C locale to avoid zero-value parsing i...
  • See full diff in compare view

Updates html from 0.15.6 to 0.15.7

Release notes

Sourced from html's releases.

package:html v0.15.7

  • writeTextNodeAsHtml: Escape text inside <script> and <style>-like tags in foreign namespaces.
  • Fix the tokenizer failing to close CDATA blocks when encountering extra brackets
  • Require Dart 3.6
  • Limit "Noah's Ark" clause to avoid degenerate O(N^2) when parsing deeply nested formatting elements with unique attributes.
  • Added new textContent method to Node class that returns the text content of the node.
  • Fix XSS vulnerability in htmlToCodeMarkup() by escaping DOCTYPE, element, and attribute names.
Commits
  • c7f7a63 Prepare to publish packages (#2562)
  • 3b3b22c [extension_discovery] Fixup review comments (#2557)
  • 441ff29 [unified_analytics]Add an 'is_external' const to indicate external builds (#2...
  • 5f02a37 Fix trailing comma when adding to flow collections in yaml_edit (#2533)
  • 7a3be9a [unified_analytics] Prepare for 8.0.18 release (#2559)
  • 59c163c [unified_analytics] Add hostArch parameter to Event.flutterCommandResult (#2558)
  • 8108a7c [extension_discovery] Prevent config.yaml symlinks from escaping package boun...
  • 3de16a5 fix(coverage): reject file: URIs outside known roots in Resolver (#2534)
  • 1723b1e [html]: add minimal differential testing framework (#2554)
  • 7dc3279 fix: reconcile version mismatches in process and stack_trace (#2546)
  • Additional commits viewable in compare view

Updates mime from 2.0.0 to 2.1.0

Release notes

Sourced from mime's releases.

package:mime v2.1.0

  • Switched to using the Apache httpd mime.conf table as the source of truth for mime types. Mime type additions:
  • application/vnd.geogebra.slides
  • font/collection
  • image/jxl
  • image/vnd.dvb.subtitle
  • video/mp2t Renamed mime types:
  • application/x-font-otf => font/otf
  • application/x-font-ttf => font/ttf
  • application/x-font-woff => font/woff Removed mime types:
  • model/vnd.mts Mime types where the default file extension changed:
  • application/inkml+xml, inkml => ink
  • application/octet-stream, so => bin
  • application/onenote, onetoc2 => onetoc
  • application/pgp-signature, sig => asc
  • application/tei+xml, teicorpus => tei
  • application/vnd.adobe.fxp, fxpl => fxp
  • application/vnd.clonk.c4group, c4u => c4g
  • application/vnd.dece.data, uvvf => uvf
  • application/vnd.dece.ttml+xml, uvvt => uvt
  • application/vnd.eszigno3+xml, et3 => es3
  • application/vnd.framemaker, maker => fm
  • application/vnd.geometry-explorer, gre => gex
  • application/vnd.grafeq, gqs => gqf
  • application/vnd.ibm.modcap, listafp => afp
  • application/vnd.iccprofile, icm => icc
  • application/vnd.intercon.formnet, xpx => xpw
  • application/vnd.kde.kpresenter, kpt => kpr
  • application/vnd.kde.kword, kwt => kwd
  • application/vnd.kinar, knp => kne
  • application/vnd.koan, skt => skp
  • application/vnd.ms-project, mpt => mpp
  • application/vnd.palm, pqa => pdb
  • application/vnd.quark.quarkxpress, qxt => qxd
  • application/vnd.simtech-mindmapper, twds => twd
  • application/vnd.stardivision.writer, vor => sdw
  • application/vnd.sus-calendar, susp => sus
  • application/vnd.symbian.install, sisx => sis
  • application/vnd.ufdl, ufdl => ufd
  • application/vnd.visio, vsw => vsd
  • application/vnd.zul, zirz => zir
  • application/x-authorware-bin, x32 => aab
  • application/x-blorb, blorb => blb
  • application/x-cbr, cbz => cbr
  • application/x-director, w3d => dir

... (truncated)

Commits
  • c7f7a63 Prepare to publish packages (#2562)
  • 3b3b22c [extension_discovery] Fixup review comments (#2557)
  • 441ff29 [unified_analytics]Add an 'is_external' const to indicate external builds (#2...
  • 5f02a37 Fix trailing comma when adding to flow collections in yaml_edit (#2533)
  • 7a3be9a [unified_analytics] Prepare for 8.0.18 release (#2559)
  • 59c163c [unified_analytics] Add hostArch parameter to Event.flutterCommandResult (#2558)
  • 8108a7c [extension_discovery] Prevent config.yaml symlinks from escaping package boun...
  • 3de16a5 fix(coverage): reject file: URIs outside known roots in Resolver (#2534)
  • 1723b1e [html]: add minimal differential testing framework (#2554)
  • 7dc3279 fix: reconcile version mismatches in process and stack_trace (#2546)
  • Additional commits viewable in compare view

Updates yaml from 3.1.3 to 3.1.4

Release notes

Sourced from yaml's releases.

package:yaml v3.1.4

  • Improve recovery for list entries without - prefix. When recovering, provide a more helpful error message suggesting the missing prefix.
  • Fix a bug where block strings terminated by EOF were not given an implicit newline.
  • Fix parsing of plain scalars starting with indicator characters (?, :, and -).
  • Throw a FormatException when parsing self-referential collections instead of a StackOverflow. Yaml definitions with collections nested within themselves are unsupported.
Commits
  • c7f7a63 Prepare to publish packages (#2562)
  • 3b3b22c [extension_discovery] Fixup review comments (#2557)
  • 441ff29 [unified_analytics]Add an 'is_external' const to indicate external builds (#2...
  • 5f02a37 Fix trailing comma when adding to flow collections in yaml_edit (#2533)
  • 7a3be9a [unified_analytics] Prepare for 8.0.18 release (#2559)
  • 59c163c [unified_analytics] Add hostArch parameter to Event.flutterCommandResult (#2558)
  • 8108a7c [extension_discovery] Prevent config.yaml symlinks from escaping package boun...
  • 3de16a5 fix(coverage): reject file: URIs outside known roots in Resolver (#2534)
  • 1723b1e [html]: add minimal differential testing framework (#2554)
  • 7dc3279 fix: reconcile version mismatches in process and stack_trace (#2546)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…th 7 updates

Bumps the pub-minor-and-patch group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [archive](https://github.com/brendan-duncan/archive) | `4.0.9` | `4.3.0` |
| [dio](https://github.com/cfug/dio) | `5.11.0` | `5.11.1` |
| [flutter_file_dialog](https://github.com/kineapps/flutter_file_dialog) | `3.3.2` | `3.3.3` |
| [flutter_onnxruntime](https://github.com/masicai/flutter_onnxruntime) | `1.8.3` | `1.8.5` |
| [html](https://github.com/dart-lang/tools/tree/main/pkgs) | `0.15.6` | `0.15.7` |
| [mime](https://github.com/dart-lang/tools/tree/main/pkgs) | `2.0.0` | `2.1.0` |
| [yaml](https://github.com/dart-lang/tools/tree/main/pkgs) | `3.1.3` | `3.1.4` |



Updates `archive` from 4.0.9 to 4.3.0
- [Changelog](https://github.com/brendan-duncan/archive/blob/main/CHANGELOG.md)
- [Commits](https://github.com/brendan-duncan/archive/commits)

Updates `dio` from 5.11.0 to 5.11.1
- [Release notes](https://github.com/cfug/dio/releases)
- [Commits](cfug/dio@dio_v5.11.0...dio_v5.11.1)

Updates `flutter_file_dialog` from 3.3.2 to 3.3.3
- [Changelog](https://github.com/kineapps/flutter_file_dialog/blob/master/CHANGELOG.md)
- [Commits](kineapps/flutter_file_dialog@3.3.2...3.3.3)

Updates `flutter_onnxruntime` from 1.8.3 to 1.8.5
- [Release notes](https://github.com/masicai/flutter_onnxruntime/releases)
- [Changelog](https://github.com/masicai/flutter_onnxruntime/blob/main/CHANGELOG.md)
- [Commits](masicai/flutter_onnxruntime@v1.8.3...v1.8.5)

Updates `html` from 0.15.6 to 0.15.7
- [Release notes](https://github.com/dart-lang/tools/releases)
- [Commits](https://github.com/dart-lang/tools/commits/html-v0.15.7/pkgs)

Updates `mime` from 2.0.0 to 2.1.0
- [Release notes](https://github.com/dart-lang/tools/releases)
- [Commits](https://github.com/dart-lang/tools/commits/mime-v2.1.0/pkgs)

Updates `yaml` from 3.1.3 to 3.1.4
- [Release notes](https://github.com/dart-lang/tools/releases)
- [Commits](https://github.com/dart-lang/tools/commits/yaml-v3.1.4/pkgs)

---
updated-dependencies:
- dependency-name: archive
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: pub-minor-and-patch
- dependency-name: dio
  dependency-version: 5.11.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pub-minor-and-patch
- dependency-name: flutter_file_dialog
  dependency-version: 3.3.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pub-minor-and-patch
- dependency-name: flutter_onnxruntime
  dependency-version: 1.8.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pub-minor-and-patch
- dependency-name: html
  dependency-version: 0.15.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pub-minor-and-patch
- dependency-name: mime
  dependency-version: 2.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: pub-minor-and-patch
- dependency-name: yaml
  dependency-version: 3.1.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pub-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dart Pull requests that update dart code dependencies Pull requests that update a dependency file labels Sep 28, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 5, 2026
@dependabot
dependabot Bot deleted the dependabot/pub/pub-minor-and-patch-8d284b7c00 branch October 5, 2026 01:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dart Pull requests that update dart code dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants