Repository navigation
chore(deps): bump the cargo-major group across 1 directory with 8 updates - #104
dependabot[bot] wants to merge 1 commit into
Conversation
…ates Bumps the cargo-major group with 8 updates in the / directory: | Package | From | To | | --- | --- | --- | | [brotli](https://github.com/dropbox/rust-brotli) | `8.0.4` | `9.0.0` | | [orc-rust](https://github.com/datafusion-contrib/orc-rust) | `0.8.0` | `0.9.0` | | [prost](https://github.com/tokio-rs/prost) | `0.13.5` | `0.14.4` | | [zstd](https://github.com/gyscos/zstd-rs) | `0.13.3` | `0.14.0` | | [lz4_flex](https://github.com/pseitz/lz4_flex) | `0.13.1` | `0.14.0` | | [apache-avro](https://github.com/apache/avro-rs) | `0.21.0` | `0.22.0` | | [num-bigint](https://github.com/rust-num/num-bigint) | `0.4.8` | `0.5.1` | | [base64](https://github.com/marshallpierce/rust-base64) | `0.22.1` | `0.23.1` | Updates `brotli` from 8.0.4 to 9.0.0 - [Release notes](https://github.com/dropbox/rust-brotli/releases) - [Commits](dropbox/rust-brotli@8.0.4...9.0.0) Updates `orc-rust` from 0.8.0 to 0.9.0 - [Release notes](https://github.com/datafusion-contrib/orc-rust/releases) - [Commits](datafusion-contrib/orc-rust@v0.8.0...v0.9.0) Updates `prost` from 0.13.5 to 0.14.4 - [Release notes](https://github.com/tokio-rs/prost/releases) - [Changelog](https://github.com/tokio-rs/prost/blob/master/CHANGELOG.md) - [Commits](tokio-rs/prost@v0.13.5...v0.14.4) Updates `zstd` from 0.13.3 to 0.14.0 - [Release notes](https://github.com/gyscos/zstd-rs/releases) - [Commits](gyscos/zstd-rs@v0.13.3...v0.14.0) Updates `lz4_flex` from 0.13.1 to 0.14.0 - [Release notes](https://github.com/pseitz/lz4_flex/releases) - [Changelog](https://github.com/PSeitz/lz4_flex/blob/main/CHANGELOG.md) - [Commits](PSeitz/lz4_flex@0.13.1...0.14.0) Updates `apache-avro` from 0.21.0 to 0.22.0 - [Release notes](https://github.com/apache/avro-rs/releases) - [Changelog](https://github.com/apache/avro-rs/blob/main/RELEASE.md) - [Commits](apache/avro-rs@rel/release-0.21.0...rel/release-0.22.0) Updates `num-bigint` from 0.4.8 to 0.5.1 - [Changelog](https://github.com/rust-num/num-bigint/blob/main/RELEASES.md) - [Commits](rust-num/num-bigint@num-bigint-0.4.8...num-bigint-0.5.1) Updates `base64` from 0.22.1 to 0.23.1 - [Changelog](https://github.com/marshallpierce/rust-base64/blob/master/RELEASE-NOTES.md) - [Commits](marshallpierce/rust-base64@v0.22.1...v0.23.1) --- updated-dependencies: - dependency-name: brotli dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: cargo-major - dependency-name: orc-rust dependency-version: 0.9.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: prost dependency-version: 0.14.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: zstd dependency-version: 0.14.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: lz4_flex dependency-version: 0.14.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: apache-avro dependency-version: 0.22.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: num-bigint dependency-version: 0.5.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: base64 dependency-version: 0.23.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major ... Signed-off-by: dependabot[bot] <support@github.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
seagrep benchmarksmicromicro did not produce a table e2e S3e2e did not produce a table scalescale did not produce a table proseprose did not produce a table |
| orc-rust = { version = "0.9.0", default-features = false } | ||
| prost = "0.14.4" |
There was a problem hiding this comment.
The ORC and Prost upgrades leave the core crate using incompatible dependency types: ORC's PostScript requires Prost 0.13's Message trait, while the changed direct dependency imports Prost 0.14's trait. The ORC integration also receives Arrow 59 RecordBatch values where it requires Arrow 58 values. This prevents seagrep-core from compiling, blocking codec functionality and its test suite. Align the ORC-facing Prost and Arrow dependencies and types to compatible versions.
Artifacts
- Contains the complete exact command used for the narrow locked core compilation check, showing the reproducible validation invocation.
- Captured output of the locked core compilation check in the parent worktree; it finishes successfully with exit code 0.
- Captured output of the same locked core compilation check at PR head; it reports the exact Prost and Arrow source-line errors and exits 101.
- Captured git diff for the PR's Cargo manifest change, showing `Cargo.toml:53-54` upgrade ORC and Prost dependencies.
| apache-avro = { version = "0.21.0", features = ["snappy", "zstandard", "bzip", "xz"] } | ||
| num-bigint = "0.4.6" | ||
| apache-avro = { version = "0.22.0", features = ["snappy", "zstandard", "bzip", "xz"] } | ||
| num-bigint = "0.5.1" |
There was a problem hiding this comment.
This dependency selects num-bigint 0.5.1, but apache-avro 0.22.0 implements its decimal conversion for the distinct num-bigint 0.4.8 BigInt type. The decimal conversion in tabular.rs therefore fails to compile, preventing seagrep-core and its tests from building. Keep the direct dependency on the Avro-compatible version line or update the conversion and Avro dependency together.
Artifacts
- The full authored Bash source runs the requested locked Cargo library test and captures its command, directory, output, and exit status; it provides an exact repeatable reproduction.
- Running the narrow reproduction script from `/home/user/repo` produced compiler E0277 at `crates/core/src/codec/tabular.rs:89` and exit code 101; the requested incompatibility is confirmed.
Comments Outside DiffThese findings sit on lines the diff does not cover, so they could not be posted inline. Each one leaves this list once its file changes.
|
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Bumps the cargo-major group with 8 updates in the / directory:
8.0.49.0.00.8.00.9.00.13.50.14.40.13.30.14.00.13.10.14.00.21.00.22.00.4.80.5.10.22.10.23.1Updates
brotlifrom 8.0.4 to 9.0.0Commits
a51b65e9.0.0 releasefb3104dAdd non-default portable-float feature for target-independent encoder outputc9af3deFix #25793ea851fix: handle short empty streams in BroCatli5bf2ed8fixed simd (.to_int() renamed to .to_simd())ac02943Revert "fixed simd (.to_int() renamed to .to_simd())"b4ed6acfixed simd (.to_int() renamed to .to_simd())3e7adf2fixed simd (mask.to_int() renamed to mask.to_simd())Updates
orc-rustfrom 0.8.0 to 0.9.0Commits
d21a6e4feat: bump to 0.9 and upgrade arrow to 59 (#89)2060e24feat(writer): add Date32 and timestamp support (#88)d0d723efeat(writer): add ZLIB, Snappy, LZ4, and Zstd compression support (#86)d996ebeFix Cargo Deny license check workflow invocation (#87)c1e4fe4chore: fix clippy warnings surfaced by Rust 1.95 (#83)Updates
prostfrom 0.13.5 to 0.14.4Changelog
Sourced from prost's changelog.
... (truncated)
Commits
13646cdchore: Release version 0.14.4 (#1437)dad79d5fix(prost-derive): return error for invalid enumeration default identifiers (...b0b6c93ci: Updatecargo clippyto 1.91 (#1435)32cfffbstyle: remove explicit.into_iter()(#1434)2710efdci: Updatecargo clippyto 1.89 (#1433)18ea4e4style: use variables directly informat!()(#1432)2821bd1build(deps): bump actions/upload-artifact from 6 to 7 (#1409)3ce3b39test(groups): Actually constructNestedGroup(#1363)8776405docs: Update changelog for version 0.14.3 (#1431)33d3ef1build: Grab binary path from cargo (#1429)Updates
zstdfrom 0.13.3 to 0.14.0Commits
648acb4Avoid let...else in the seekable callbackse1152c1Bump versions for the next release7caed6eDerive the usual traits on ResetDirectivebf7b1f7Refuse to reuse a context an error may have left undefined1565618Check the target, not the host, for MSVC8315a62Return Ok(0) from Read::read for an empty buffera7cfa93Keep the std gate on the Cursor WriteBuf impl9bf1692Say why the Send and Sync impls hold681bcc3Don't truncate Cursor positions on 32-bit targetsd5a1fddDon't hand out a &mut Seekable from AdvancedSeekableUpdates
lz4_flexfrom 0.13.1 to 0.14.0Changelog
Sourced from lz4_flex's changelog.
Commits
1bffdcbMerge pull request #229 from PSeitz/release/0.14.0-changeloga5973e4Update CHANGELOG for 0.14.0 release, bump version to 0.14.043cdb22Merge pull request #228 from PSeitz/0.14.x08fd47eadd release skilla6c6135Merge pull request #225 from fbrozovic/alloc-featureca019ecAdd alloc feature to support no_std without an allocator19194f9Merge pull request #223 from PSeitz/0.13.xUpdates
apache-avrofrom 0.21.0 to 0.22.0Release notes
Sourced from apache-avro's releases.
... (truncated)
Commits
ec5721cchore(deps): Bump thiserror from 2.0.18 to 2.0.19 (#604)b946aa3chore(deps): Bump quote from 1.0.46 to 1.0.47 (#605)98fa1f4chore(deps): Bump serde from 1.0.228 to 1.0.229 (#607)49732c4chore(ci): Bump the github-codeql group with 2 updates (#608)73629ebchore(ci): Bump shogo82148/actions-setup-perl from 1.41.1 to 1.42.0 (#609)ed733edchore(ci): Bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 (#610)1c11867chore(ci): Bump actions/setup-java from 5.5.0 to 5.6.0 (#611)6879d53chore(ci): Bump taiki-e/install-action from 2.83.2 to 2.84.0 (#612)e59778bchore(deps): Bump proc-macro2 from 1.0.106 to 1.0.107 (#603)784294dfix: Allow serializing an enum inside a union (#591)Updates
num-bigintfrom 0.4.8 to 0.5.1Changelog
Sourced from num-bigint's changelog.
Commits
33c59baMerge pull request #348 from cuviper/bz-alg2-step3b38b68f6Release 0.5.1f4a43f5Fix the missing part of the Burnikel-Ziegler algorithmebfd89aAdd failing tests for a bug in B-Z division0ab95dfMerge pull request #338 from cuviper/rand-0.1033d6998Release 0.5.084d05b7Clean up manifests of ci cratesf8daf56Allowclippy::duplicate_modwhere intended022310aRearrange therandfeatures to support both 0.9 and 0.10537a036ci: use the fallback resolver for depsUpdates
base64from 0.22.1 to 0.23.1Changelog
Sourced from base64's changelog.
Commits
069bf70v0.23.16ab1fb0Merge pull request #310 from musicinmybrain/test-on-non-simd-arches7cffce6Fix testing on architectures without unsafe SIMD supporte34f9a0Merge pull request #308 from atouchet/come9240c9Remove outdated comment9e9220av0.23.0870326eMerge pull request #306 from marshallpierce/mp/trailing-bits-docsfbec5f1Document no trailing trailing bits0a23549Merge pull request #305 from marshallpierce/mp/edition-2021f10b7e2Update deps & editionDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsUnsafe to merge because two independently reproduced dependency mismatches prevent the core crate from compiling.
Findings
Summary
num-bigintupgrade is incompatible with the Avro decimal conversion and independently prevents the core crate from building.Merge safety: unsafe until both dependency version mismatches are resolved and the core crate builds successfully.
Reviews (1) · Last reviewed commit: "chore(deps): bump the cargo-major group ..."