Repository navigation
chore(deps): bump the cargo-major group across 1 directory with 7 updates - #102
dependabot[bot] wants to merge 1 commit into
Conversation
…ates Bumps the cargo-major group with 7 updates in the / directory: | Package | From | To | | --- | --- | --- | | [brotli](https://github.com/dropbox/rust-brotli) | `8.0.4` | `9.0.0` | | [orc-rust](https://github.com/datafusion-contrib/orc-rust) | `0.8.0` | `0.9.0` | | [prost](https://github.com/tokio-rs/prost) | `0.13.5` | `0.14.4` | | [lz4_flex](https://github.com/pseitz/lz4_flex) | `0.13.1` | `0.14.0` | | [apache-avro](https://github.com/apache/avro-rs) | `0.21.0` | `0.22.0` | | [num-bigint](https://github.com/rust-num/num-bigint) | `0.4.8` | `0.5.1` | | [base64](https://github.com/marshallpierce/rust-base64) | `0.22.1` | `0.23.1` | Updates `brotli` from 8.0.4 to 9.0.0 - [Release notes](https://github.com/dropbox/rust-brotli/releases) - [Commits](dropbox/rust-brotli@8.0.4...9.0.0) Updates `orc-rust` from 0.8.0 to 0.9.0 - [Release notes](https://github.com/datafusion-contrib/orc-rust/releases) - [Commits](datafusion-contrib/orc-rust@v0.8.0...v0.9.0) Updates `prost` from 0.13.5 to 0.14.4 - [Release notes](https://github.com/tokio-rs/prost/releases) - [Changelog](https://github.com/tokio-rs/prost/blob/master/CHANGELOG.md) - [Commits](tokio-rs/prost@v0.13.5...v0.14.4) Updates `lz4_flex` from 0.13.1 to 0.14.0 - [Release notes](https://github.com/pseitz/lz4_flex/releases) - [Changelog](https://github.com/PSeitz/lz4_flex/blob/main/CHANGELOG.md) - [Commits](PSeitz/lz4_flex@0.13.1...0.14.0) Updates `apache-avro` from 0.21.0 to 0.22.0 - [Release notes](https://github.com/apache/avro-rs/releases) - [Changelog](https://github.com/apache/avro-rs/blob/main/RELEASE.md) - [Commits](apache/avro-rs@rel/release-0.21.0...rel/release-0.22.0) Updates `num-bigint` from 0.4.8 to 0.5.1 - [Changelog](https://github.com/rust-num/num-bigint/blob/main/RELEASES.md) - [Commits](rust-num/num-bigint@num-bigint-0.4.8...num-bigint-0.5.1) Updates `base64` from 0.22.1 to 0.23.1 - [Changelog](https://github.com/marshallpierce/rust-base64/blob/master/RELEASE-NOTES.md) - [Commits](marshallpierce/rust-base64@v0.22.1...v0.23.1) --- updated-dependencies: - dependency-name: brotli dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: cargo-major - dependency-name: orc-rust dependency-version: 0.9.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: prost dependency-version: 0.14.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: lz4_flex dependency-version: 0.14.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: apache-avro dependency-version: 0.22.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: num-bigint dependency-version: 0.5.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: base64 dependency-version: 0.23.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major ... Signed-off-by: dependabot[bot] <support@github.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
seagrep benchmarksmicromicro did not produce a table e2e S3e2e did not produce a table scalescale did not produce a table proseprose did not produce a table |
| orc-rust = { version = "0.8.0", default-features = false } | ||
| prost = "0.13.5" | ||
| orc-rust = { version = "0.9.0", default-features = false } | ||
| prost = "0.14.4" |
There was a problem hiding this comment.
This upgrade selects Prost 0.14.4, but orc-rust 0.9.0's generated PostScript type implements the Prost 0.13.5 Message trait. The ORC format detection code imports the 0.14 trait and calls PostScript::decode, so the method is unavailable and seagrep-core cannot compile. Align the direct Prost dependency with orc-rust, or upgrade orc-rust to a compatible release.
Artifacts
- Evidence file captured while the check ran.
- The full command output behind this check.
| apache-avro = { version = "0.21.0", features = ["snappy", "zstandard", "bzip", "xz"] } | ||
| num-bigint = "0.4.6" | ||
| apache-avro = { version = "0.22.0", features = ["snappy", "zstandard", "bzip", "xz"] } | ||
| num-bigint = "0.5.1" |
There was a problem hiding this comment.
This upgrade selects num-bigint 0.5.1 while apache-avro 0.22.0 uses num-bigint 0.4.8. The Avro decimal conversion attempts to convert into the direct dependency's distinct BigInt type, for which Apache Avro provides no conversion, so seagrep-core cannot compile. Keep the direct version compatible with Apache Avro or convert through a version-neutral representation.
Artifacts
- The authored executable evidence script runs the narrow locked package compile check, making the reported failure reproducible.
- Running the evidence script compiles both num-bigint 0.4.8 and 0.5.1, then fails at tabular.rs:89 with E0277, confirming the finding.
- The exact Avro decimal test command cannot run because compilation fails first at the same incompatible BigInt conversion, confirming no executable test path until the build defect is fixed.
- The locked Cargo dependency tree records apache-avro's 0.4.8 path and seagrep-core's direct 0.5.1 path, establishing the version split behind the compiler error.
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Bumps the cargo-major group with 7 updates in the / directory:
8.0.49.0.00.8.00.9.00.13.50.14.40.13.10.14.00.21.00.22.00.4.80.5.10.22.10.23.1Updates
brotlifrom 8.0.4 to 9.0.0Commits
a51b65e9.0.0 releasefb3104dAdd non-default portable-float feature for target-independent encoder outputc9af3deFix #25793ea851fix: handle short empty streams in BroCatli5bf2ed8fixed simd (.to_int() renamed to .to_simd())ac02943Revert "fixed simd (.to_int() renamed to .to_simd())"b4ed6acfixed simd (.to_int() renamed to .to_simd())3e7adf2fixed simd (mask.to_int() renamed to mask.to_simd())Updates
orc-rustfrom 0.8.0 to 0.9.0Commits
d21a6e4feat: bump to 0.9 and upgrade arrow to 59 (#89)2060e24feat(writer): add Date32 and timestamp support (#88)d0d723efeat(writer): add ZLIB, Snappy, LZ4, and Zstd compression support (#86)d996ebeFix Cargo Deny license check workflow invocation (#87)c1e4fe4chore: fix clippy warnings surfaced by Rust 1.95 (#83)Updates
prostfrom 0.13.5 to 0.14.4Changelog
Sourced from prost's changelog.
... (truncated)
Commits
13646cdchore: Release version 0.14.4 (#1437)dad79d5fix(prost-derive): return error for invalid enumeration default identifiers (...b0b6c93ci: Updatecargo clippyto 1.91 (#1435)32cfffbstyle: remove explicit.into_iter()(#1434)2710efdci: Updatecargo clippyto 1.89 (#1433)18ea4e4style: use variables directly informat!()(#1432)2821bd1build(deps): bump actions/upload-artifact from 6 to 7 (#1409)3ce3b39test(groups): Actually constructNestedGroup(#1363)8776405docs: Update changelog for version 0.14.3 (#1431)33d3ef1build: Grab binary path from cargo (#1429)Updates
lz4_flexfrom 0.13.1 to 0.14.0Changelog
Sourced from lz4_flex's changelog.
Commits
1bffdcbMerge pull request #229 from PSeitz/release/0.14.0-changeloga5973e4Update CHANGELOG for 0.14.0 release, bump version to 0.14.043cdb22Merge pull request #228 from PSeitz/0.14.x08fd47eadd release skilla6c6135Merge pull request #225 from fbrozovic/alloc-featureca019ecAdd alloc feature to support no_std without an allocator19194f9Merge pull request #223 from PSeitz/0.13.xUpdates
apache-avrofrom 0.21.0 to 0.22.0Release notes
Sourced from apache-avro's releases.
... (truncated)
Commits
ec5721cchore(deps): Bump thiserror from 2.0.18 to 2.0.19 (#604)b946aa3chore(deps): Bump quote from 1.0.46 to 1.0.47 (#605)98fa1f4chore(deps): Bump serde from 1.0.228 to 1.0.229 (#607)49732c4chore(ci): Bump the github-codeql group with 2 updates (#608)73629ebchore(ci): Bump shogo82148/actions-setup-perl from 1.41.1 to 1.42.0 (#609)ed733edchore(ci): Bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 (#610)1c11867chore(ci): Bump actions/setup-java from 5.5.0 to 5.6.0 (#611)6879d53chore(ci): Bump taiki-e/install-action from 2.83.2 to 2.84.0 (#612)e59778bchore(deps): Bump proc-macro2 from 1.0.106 to 1.0.107 (#603)784294dfix: Allow serializing an enum inside a union (#591)Updates
num-bigintfrom 0.4.8 to 0.5.1Changelog
Sourced from num-bigint's changelog.
Commits
33c59baMerge pull request #348 from cuviper/bz-alg2-step3b38b68f6Release 0.5.1f4a43f5Fix the missing part of the Burnikel-Ziegler algorithmebfd89aAdd failing tests for a bug in B-Z division0ab95dfMerge pull request #338 from cuviper/rand-0.1033d6998Release 0.5.084d05b7Clean up manifests of ci cratesf8daf56Allowclippy::duplicate_modwhere intended022310aRearrange therandfeatures to support both 0.9 and 0.10537a036ci: use the fallback resolver for depsUpdates
base64from 0.22.1 to 0.23.1Changelog
Sourced from base64's changelog.
Commits
069bf70v0.23.16ab1fb0Merge pull request #310 from musicinmybrain/test-on-non-simd-arches7cffce6Fix testing on architectures without unsafe SIMD supporte34f9a0Merge pull request #308 from atouchet/come9240c9Remove outdated comment9e9220av0.23.0870326eMerge pull request #306 from marshallpierce/mp/trailing-bits-docsfbec5f1Document no trailing trailing bits0a23549Merge pull request #305 from marshallpierce/mp/edition-2021f10b7e2Update deps & editionDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsGreptile Summary
This dependency update prevents
seagrep-corefrom compiling. The direct Prost upgrade conflicts with ORC's generated protobuf types, and the directnum-bigintupgrade conflicts with Apache Avro's decimal conversion type.Confidence Score: 3/5
Not safe to merge: the core crate fails to compile because two direct dependency upgrades create incompatible Rust types and traits.
Two independently reproduced build failures affect the core crate.
Files Needing Attention: Cargo.toml, crates/core/Cargo.toml, crates/core/src/codec/detect.rs, and crates/core/src/codec/tabular.rs
What T-Rex did
Comments Outside Diff (2)
crates/core/src/codec/detect.rs, line 133 (link)General comment
crates/core/src/codec/tabular.rs:89convertsapache_avro::Decimalintonum_bigint::BigInt, but the direct dependency atcrates/core/Cargo.toml:35is 0.5.1 whereas apache-avro 0.22.0 uses 0.4.8. The locked compile reports E0277:BigInt: From<apache_avro::Decimal>is not satisfied and explicitly identifies multiple num-bigint versions.num-bigintdependency with apache-avro's 0.4.8 version (or avoid the cross-crate conversion through an apache-avro-supported representation), then reruncargo check --locked -p seagrep-core.Reviews (1): Last reviewed commit: "chore(deps): bump the cargo-major group ..." | Re-trigger Greptile