Skip to content

chore(deps): bump the cargo-major group across 1 directory with 7 updates - #102

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-major-f3fba03980
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-major-f3fba03980

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the cargo-major group with 7 updates in the / directory:

Package From To
brotli 8.0.4 9.0.0
orc-rust 0.8.0 0.9.0
prost 0.13.5 0.14.4
lz4_flex 0.13.1 0.14.0
apache-avro 0.21.0 0.22.0
num-bigint 0.4.8 0.5.1
base64 0.22.1 0.23.1

Updates brotli from 8.0.4 to 9.0.0

Commits
  • a51b65e 9.0.0 release
  • fb3104d Add non-default portable-float feature for target-independent encoder output
  • c9af3de Fix #257
  • 93ea851 fix: handle short empty streams in BroCatli
  • 5bf2ed8 fixed simd (.to_int() renamed to .to_simd())
  • ac02943 Revert "fixed simd (.to_int() renamed to .to_simd())"
  • b4ed6ac fixed simd (.to_int() renamed to .to_simd())
  • 3e7adf2 fixed simd (mask.to_int() renamed to mask.to_simd())
  • See full diff in compare view

Updates orc-rust from 0.8.0 to 0.9.0

Commits
  • d21a6e4 feat: bump to 0.9 and upgrade arrow to 59 (#89)
  • 2060e24 feat(writer): add Date32 and timestamp support (#88)
  • d0d723e feat(writer): add ZLIB, Snappy, LZ4, and Zstd compression support (#86)
  • d996ebe Fix Cargo Deny license check workflow invocation (#87)
  • c1e4fe4 chore: fix clippy warnings surfaced by Rust 1.95 (#83)
  • See full diff in compare view

Updates prost from 0.13.5 to 0.14.4

Changelog

Sourced from prost's changelog.

Prost version 0.14.4

PROST! is a Protocol Buffers implementation for the Rust Language. prost generates simple, idiomatic Rust code from proto2 and proto3 files.

🚀 Features

  • (prost-derive) Make is_valid a constant function (#1401)
  • Increase MSRV to 1.85 (#1428)

🐛 Bug Fixes

  • Use Display instead of Debug for generated enumeration attributes (#1419)
  • (prost-derive) Return error for invalid enumeration default identifiers (#1426)
  • (build) Grab binary path from cargo (#1429)
  • (build) Fix C++ build on GCC 15 (#1395)

📚 Documentation

  • Add example for decode_length_delimiter (#1311)
  • Update protobuf-src example to avoid unsafe set_var

🧪 Testing

  • Test derive Eq behavior (#1422)
  • (groups) Actually construct NestedGroup (#1363)

💼 Dependencies

  • (deps) Update criterion requirement from 0.7 to 0.8 (#1374)
  • (deps) Remove getrandom@0.4.1 from build-dependencies (#1400)
  • (deps) Update rand requirement from 0.9 to 0.10 (#1397)
  • (deps) Bump actions/upload-artifact from 6 to 7 (#1409)
  • (deps) Update cargo clippy to 1.89 (#1433)
  • (deps) Update cargo clippy to 1.91 (#1435)
  • (deps) Update and improve nix devshell (#1393)

🎨 Styling

  • Prevent needless borrow (#1404)
  • Use std::hint::black_box() (#1403)
  • Use variables directly in format!() (#1432)
  • Remove explicit .into_iter() (#1434)
  • Run clippy on benches (#1405)

Prost version 0.14.3

PROST! is a Protocol Buffers implementation for the Rust Language. prost generates simple, idiomatic Rust code from proto2 and proto3 files.

⚠️ Heads-up

... (truncated)

Commits

Updates lz4_flex from 0.13.1 to 0.14.0

Changelog

Sourced from lz4_flex's changelog.

0.14.0 (2026-07-14)

Features

  • Add alloc feature to allow no_std operation without an allocator. The std feature now implies alloc. Without alloc only the _into variants of the block API are available, e.g. compress_into; the compression hash table is placed on the stack or can be provided via compress_into_with_table.
Note: Users with `default-features = false` need to additionally enable the `alloc`
feature to keep the APIs returning `Vec`, e.g. `compress` and `decompress`.
Commits
  • 1bffdcb Merge pull request #229 from PSeitz/release/0.14.0-changelog
  • a5973e4 Update CHANGELOG for 0.14.0 release, bump version to 0.14.0
  • 43cdb22 Merge pull request #228 from PSeitz/0.14.x
  • 08fd47e add release skill
  • a6c6135 Merge pull request #225 from fbrozovic/alloc-feature
  • ca019ec Add alloc feature to support no_std without an allocator
  • 19194f9 Merge pull request #223 from PSeitz/0.13.x
  • See full diff in compare view

Updates apache-avro from 0.21.0 to 0.22.0

Release notes

Sourced from apache-avro's releases.

Apache Avro Rust SDK 0.22.0 release

The Apache Avro Rust SDK 0.22.0 release is a large release with lots of features, fixes and breaking changes. It is strongly recommended to read the Breaking changes and New features sections of the changelog.

What's changed

Breaking changes

  • Resolve schema(ta) in the builder of Writer by @​Kriskras99 in #328
    • The builder now returns an AvroResult
  • Rework schema compatibility by @​Kriskras99 in #342
    • SchemaCompatiblity::can_read and SchemaCompatiblity::mutual_read now return a Compatiblity type
  • Bump MSRV from 1.85 to 1.88 by @​Kriskras99 in #342, #348
  • Schema::Duration now has a FixedSchema allowing access to attributes and Serialize and Deserialize is implemented for apache_avro::Duration by @​jdarais in #382
  • AvroSchema and AvroSchemaComponent are no longer behind the derive feature and have moved from apache_avro::schema::derive to apache_avro::serde by @​martin-g in #394 and @​Kriskras99 in #433
  • Change the implementation of AvroSchemaComponent for Uuid from Schema::Uuid(String) to Schema::Uuid(Fixed(name: "org.apache.avro.rust.Uuid", size: 16)) and allow overwriting a field's schema with the with attribute when using #[derive(AvroSchema)] by @​Kriskras99 in #397, #558
    • When #[avro(with)] is specified without an argument, it will call the get_schema_in_ctxt(&mut HashSet<Name>, NamespaceRef<'_>) -> Schema in the same module as specified by #[serde(with)]
    • When #[avro(with = path::to::some_fn)] is specified with a path, the function it's pointing to will be called with two parameters &mut HashSet<Name>, NamespaceRef<'_>
    • When #[avro(with = || {})] is specified with a closure, that closure is invoked
    • The name of the schema for uuid::Uuid is org.apache.avro.rust.uuid
    • The schema for Uuid can be changed back to a Schema::Uuid(String) using #[avro(with = || Schema::Uuid(UuidSchema::String))] on a field with a Uuid and setting human_readable to true
  • Replace the From<&str> implementations for Name and Alias with TryFrom<&str>, TryFrom<String>, and FromStr as the conversion is not fallible by @​Kriskras99 in #423
  • Rework SpecificSingleObjectWriter removing ::with_capacity and changing write_avro_datum_ref to also take a &NamesRef parameter by @​Kriskras99 in #445
  • Remove the default field from FixedSchema as it is not in the specification by @​Kriskras99 in #460
  • AvroSchemaComponent::get_schema_in_ctxt now takes a &mut HashSet<Name> parameter for the named_schemas parameter by @​Kriskras99 in #471
  • Replace the Schema::map{,_with_attributes} and Schema::array{,_with_attributes} with builders allowing the user to set more fields by @​martin-g in #472
    • This also adds Schema::r#enum, Schema::fixed and Schema::record
  • Stricter schema parsing by @​Kriskras99 in #479
    • This now rejects schemas that were previously accepted by this library, they were already rejected by parsers in different languages
  • Alias::name and Alias::namespace now return references by @​Kriskras99 in #486
  • Remove unused order and position fields in RecordField by @​Kriskras99 in #491
  • Rework Name to be more performant which requires changing the SchemaNameValidator trait by @​Kriskras99 in #493
    • The regex returned by SchemaNameValidator::regex must have a capture group named name which captures the unqualified name when not overriding the SchemaNameValidator::validate function
    • The SchemaNameValidator::validate must now return the start byte of the unqualified name
  • Support enums and tuples in SchemaAwareSerializer, implement SchemaAwareDeserializer and document the mapping between the Serde and Avro data models by @​Kriskras99 in #512, #558
    • The SchemaAware* now have specific requirements for what input they accept, so type definitions might need to be modified to make them work with the new code (especially for enums and tuples)
    • This also makes human_readable configurable per reader and writer instance
    • Array and Map serialisation will not write the block size in bytes unless configured to do so, allowing unbuffered serialisation
    • The AvroSchemaComponent implementation for std::time::Duration has changed to match the (de)serialisation implementation as defined by Serde
      • It is now a Schema::Record(name: "org.apache.avro.rust.Duration", fields: ["secs": "org.apache.avro.rust.u64", "nanos": "long"])
    • The AvroSchemaComponent implementation for BigDecimal is now a Schema::String matching the (de)serialisation implementation as defined by bigdecimal
      • It can be changed back to a Schema::String using #[serde(with = "apache_avro::serde::bigdecimal"), avro(with)] on a field with a BigDecimal
    • The SchemaAwareDeserializer does not support schema resolution, for that use the old from_value implementation (see #575)

New features

  • Make DeflateSettings::compression_level public by @​EmilyMatt in #335
  • Support fixed as a type for uuid by @​Kriskras99 in #339
  • Don't depend on Serde to provide fields in the right order by @​Kriskras99 in #351
    • It is still recommended to match the field order between the type and the schema as out-of-order serialisation incurs a performance penalty
  • Support the #[serde(flatten)] attribute by @​Kriskras99 in #359, #448
    • This attribute is not supported when using apache_avro::serde::to_value
  • Use the Serde attributes and check for conflict with the Avro attributes by @​Kriskras99 in #377
    • This deprecates the Avro attributes for which the value must always match the Serde attribute:

... (truncated)

Commits
  • ec5721c chore(deps): Bump thiserror from 2.0.18 to 2.0.19 (#604)
  • b946aa3 chore(deps): Bump quote from 1.0.46 to 1.0.47 (#605)
  • 98fa1f4 chore(deps): Bump serde from 1.0.228 to 1.0.229 (#607)
  • 49732c4 chore(ci): Bump the github-codeql group with 2 updates (#608)
  • 73629eb chore(ci): Bump shogo82148/actions-setup-perl from 1.41.1 to 1.42.0 (#609)
  • ed733ed chore(ci): Bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 (#610)
  • 1c11867 chore(ci): Bump actions/setup-java from 5.5.0 to 5.6.0 (#611)
  • 6879d53 chore(ci): Bump taiki-e/install-action from 2.83.2 to 2.84.0 (#612)
  • e59778b chore(deps): Bump proc-macro2 from 1.0.106 to 1.0.107 (#603)
  • 784294d fix: Allow serializing an enum inside a union (#591)
  • Additional commits viewable in compare view

Updates num-bigint from 0.4.8 to 0.5.1

Changelog

Sourced from num-bigint's changelog.

Release 0.5.1 (2026-07-04)

Contributors: @​cuviper

Release 0.5.0 (2026-07-02)

  • Upgrade to rand v0.10 and/or v0.9, and split rand_core.
    • The former rand feature is now split into multiple features, rand_0_9, rand_core_0_9, rand_0_10, and rand_core_0_10, depending on the version and feature set you need.
    • The RandBigInt extension trait is now split into BigRng09 and BigRng010 for each version.
    • The gen_* methods are deprecated in favor of new random_* methods.
    • This is also a value-breaking release, as rand defines it.

Contributors: @​bionicles, @​cuviper, @​divergentdave

Commits
  • 33c59ba Merge pull request #348 from cuviper/bz-alg2-step3b
  • 38b68f6 Release 0.5.1
  • f4a43f5 Fix the missing part of the Burnikel-Ziegler algorithm
  • ebfd89a Add failing tests for a bug in B-Z division
  • 0ab95df Merge pull request #338 from cuviper/rand-0.10
  • 33d6998 Release 0.5.0
  • 84d05b7 Clean up manifests of ci crates
  • f8daf56 Allow clippy::duplicate_mod where intended
  • 022310a Rearrange the rand features to support both 0.9 and 0.10
  • 537a036 ci: use the fallback resolver for deps
  • Additional commits viewable in compare view

Updates base64 from 0.22.1 to 0.23.1

Changelog

Sourced from base64's changelog.

0.23.1

  • Make the tests build again on non-SIMD architectures

0.23.0

  • Added more consts for preconfigured configs and engines
  • Make DecodeError::InvalidLastSymbol more clear by including the decoded value
  • Added SIMD-accelerated engines behind the default-on simd-unsafe feature: Simd picks the best instruction set at runtime (AVX2 on x86_64, NEON on aarch64) and falls back to the scalar GeneralPurpose engine, while Avx2 and Neon target one instruction set with no runtime detection and work in no_std. The engines support the standard and URL-safe alphabets.
  • Update MSRV to 1.71.0
  • Add support for custom padding symbols
Commits
  • 069bf70 v0.23.1
  • 6ab1fb0 Merge pull request #310 from musicinmybrain/test-on-non-simd-arches
  • 7cffce6 Fix testing on architectures without unsafe SIMD support
  • e34f9a0 Merge pull request #308 from atouchet/com
  • e9240c9 Remove outdated comment
  • 9e9220a v0.23.0
  • 870326e Merge pull request #306 from marshallpierce/mp/trailing-bits-docs
  • fbec5f1 Document no trailing trailing bits
  • 0a23549 Merge pull request #305 from marshallpierce/mp/edition-2021
  • f10b7e2 Update deps & edition
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Greptile Summary

This dependency update prevents seagrep-core from compiling. The direct Prost upgrade conflicts with ORC's generated protobuf types, and the direct num-bigint upgrade conflicts with Apache Avro's decimal conversion type.

Confidence Score: 3/5

Not safe to merge: the core crate fails to compile because two direct dependency upgrades create incompatible Rust types and traits.

Two independently reproduced build failures affect the core crate.

Files Needing Attention: Cargo.toml, crates/core/Cargo.toml, crates/core/src/codec/detect.rs, and crates/core/src/codec/tabular.rs

T-Rex T-Rex Logs

What T-Rex did

  • T-Rex produced a finding-proof for a posted P1 finding and attached a shell script and a log artifact to enable review.
  • T-Rex added a second finding-proof for another P1 finding, including a shell script and three log artifacts to support validation.
  • T-Rex executed a general contract validation script to check for Prost-mismatch during compile across git refs and captured the observed errors.
  • T-Rex ran an avro-bigint compile-check flow and documented the before/after context and dependency provenance, noting a build-blocking correctness issue with mixed Prost versions.

View all artifacts

T-Rex Ran code and verified through T-Rex

Comments Outside Diff (2)

  1. crates/core/src/codec/detect.rs, line 133 (link)

    P1 Prost trait version mismatch

    • Bug
      • Cargo.toml selects prost 0.14.4 for seagrep-core, but orc-rust 0.9.0 resolves prost 0.13.5. The changed code imports the 0.14 Message trait, so PostScript::decode is unavailable on the ORC-generated type and seagrep-core cannot compile. Align prost with the version used by orc-rust, or upgrade orc-rust to a compatible release before merging.
    • Cause
      • Two incompatible prost Message traits are present in the resolved dependency graph.
    • Fix
      • Use prost 0.13.5 with orc-rust 0.9.0, or upgrade orc-rust to a release generated against prost 0.14 and revalidate the dependency graph.

    T-Rex Ran code and verified through T-Rex

  2. General comment

    P1 Avro decimal conversion uses an incompatible num-bigint version

    • Bug
      • crates/core/src/codec/tabular.rs:89 converts apache_avro::Decimal into num_bigint::BigInt, but the direct dependency at crates/core/Cargo.toml:35 is 0.5.1 whereas apache-avro 0.22.0 uses 0.4.8. The locked compile reports E0277: BigInt: From<apache_avro::Decimal> is not satisfied and explicitly identifies multiple num-bigint versions.
    • Cause
      • Rust treats types from distinct major/minor crate versions as distinct. apache-avro implements the Decimal conversion for its num-bigint 0.4.8 BigInt, not the package's 0.5.1 BigInt.
    • Fix
      • Align the direct num-bigint dependency with apache-avro's 0.4.8 version (or avoid the cross-crate conversion through an apache-avro-supported representation), then rerun cargo check --locked -p seagrep-core.

    T-Rex Ran code and verified through T-Rex

Reviews (1): Last reviewed commit: "chore(deps): bump the cargo-major group ..." | Re-trigger Greptile

Greptile also left 2 inline comments on this PR.

…ates

Bumps the cargo-major group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [brotli](https://github.com/dropbox/rust-brotli) | `8.0.4` | `9.0.0` |
| [orc-rust](https://github.com/datafusion-contrib/orc-rust) | `0.8.0` | `0.9.0` |
| [prost](https://github.com/tokio-rs/prost) | `0.13.5` | `0.14.4` |
| [lz4_flex](https://github.com/pseitz/lz4_flex) | `0.13.1` | `0.14.0` |
| [apache-avro](https://github.com/apache/avro-rs) | `0.21.0` | `0.22.0` |
| [num-bigint](https://github.com/rust-num/num-bigint) | `0.4.8` | `0.5.1` |
| [base64](https://github.com/marshallpierce/rust-base64) | `0.22.1` | `0.23.1` |



Updates `brotli` from 8.0.4 to 9.0.0
- [Release notes](https://github.com/dropbox/rust-brotli/releases)
- [Commits](dropbox/rust-brotli@8.0.4...9.0.0)

Updates `orc-rust` from 0.8.0 to 0.9.0
- [Release notes](https://github.com/datafusion-contrib/orc-rust/releases)
- [Commits](datafusion-contrib/orc-rust@v0.8.0...v0.9.0)

Updates `prost` from 0.13.5 to 0.14.4
- [Release notes](https://github.com/tokio-rs/prost/releases)
- [Changelog](https://github.com/tokio-rs/prost/blob/master/CHANGELOG.md)
- [Commits](tokio-rs/prost@v0.13.5...v0.14.4)

Updates `lz4_flex` from 0.13.1 to 0.14.0
- [Release notes](https://github.com/pseitz/lz4_flex/releases)
- [Changelog](https://github.com/PSeitz/lz4_flex/blob/main/CHANGELOG.md)
- [Commits](PSeitz/lz4_flex@0.13.1...0.14.0)

Updates `apache-avro` from 0.21.0 to 0.22.0
- [Release notes](https://github.com/apache/avro-rs/releases)
- [Changelog](https://github.com/apache/avro-rs/blob/main/RELEASE.md)
- [Commits](apache/avro-rs@rel/release-0.21.0...rel/release-0.22.0)

Updates `num-bigint` from 0.4.8 to 0.5.1
- [Changelog](https://github.com/rust-num/num-bigint/blob/main/RELEASES.md)
- [Commits](rust-num/num-bigint@num-bigint-0.4.8...num-bigint-0.5.1)

Updates `base64` from 0.22.1 to 0.23.1
- [Changelog](https://github.com/marshallpierce/rust-base64/blob/master/RELEASE-NOTES.md)
- [Commits](marshallpierce/rust-base64@v0.22.1...v0.23.1)

---
updated-dependencies:
- dependency-name: brotli
  dependency-version: 9.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: cargo-major
- dependency-name: orc-rust
  dependency-version: 0.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
- dependency-name: prost
  dependency-version: 0.14.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
- dependency-name: lz4_flex
  dependency-version: 0.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
- dependency-name: apache-avro
  dependency-version: 0.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
- dependency-name: num-bigint
  dependency-version: 0.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
- dependency-name: base64
  dependency-version: 0.23.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 11, 2026
@dependabot
dependabot Bot requested a review from prsabahrami as a code owner September 11, 2026 13:17
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 11, 2026
@coderabbitai

coderabbitai Bot commented Sep 11, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 82e1a996-d027-491c-9015-ad0a211e0ac8

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown

seagrep benchmarks

micro

micro did not produce a table

e2e S3

e2e did not produce a table

scale

scale did not produce a table

prose

prose did not produce a table

Comment thread Cargo.toml
orc-rust = { version = "0.8.0", default-features = false }
prost = "0.13.5"
orc-rust = { version = "0.9.0", default-features = false }
prost = "0.14.4"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Prost versions break ORC

This upgrade selects Prost 0.14.4, but orc-rust 0.9.0's generated PostScript type implements the Prost 0.13.5 Message trait. The ORC format detection code imports the 0.14 trait and calls PostScript::decode, so the method is unavailable and seagrep-core cannot compile. Align the direct Prost dependency with orc-rust, or upgrade orc-rust to a compatible release.

Artifacts

Evidence from the check

  • Evidence file captured while the check ran.

Command output from the check

  • The full command output behind this check.

View artifacts

T-Rex Ran code and verified through T-Rex

Comment thread crates/core/Cargo.toml
apache-avro = { version = "0.21.0", features = ["snappy", "zstandard", "bzip", "xz"] }
num-bigint = "0.4.6"
apache-avro = { version = "0.22.0", features = ["snappy", "zstandard", "bzip", "xz"] }
num-bigint = "0.5.1"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 BigInt versions break Avro

This upgrade selects num-bigint 0.5.1 while apache-avro 0.22.0 uses num-bigint 0.4.8. The Avro decimal conversion attempts to convert into the direct dependency's distinct BigInt type, for which Apache Avro provides no conversion, so seagrep-core cannot compile. Keep the direct version compatible with Apache Avro or convert through a version-neutral representation.

Artifacts

Evidence from the check

  • The authored executable evidence script runs the narrow locked package compile check, making the reported failure reproducible.

Command output from the check

  • Running the evidence script compiles both num-bigint 0.4.8 and 0.5.1, then fails at tabular.rs:89 with E0277, confirming the finding.

Command output from the check

  • The exact Avro decimal test command cannot run because compilation fails first at the same incompatible BigInt conversion, confirming no executable test path until the build defect is fixed.

Command output from the check

  • The locked Cargo dependency tree records apache-avro's 0.4.8 path and seagrep-core's direct 0.5.1 path, establishing the version split behind the compiler error.

View artifacts

T-Rex Ran code and verified through T-Rex

@dependabot @github

dependabot Bot commented on behalf of github Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 18, 2026
@dependabot
dependabot Bot deleted the dependabot/cargo/cargo-major-f3fba03980 branch September 18, 2026 13:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants