Skip to content

chore(deps): bump the cargo-major group across 1 directory with 8 updates - #104

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-major-ac014f21cc
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-major-ac014f21cc

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the cargo-major group with 8 updates in the / directory:

Package From To
brotli 8.0.4 9.0.0
orc-rust 0.8.0 0.9.0
prost 0.13.5 0.14.4
zstd 0.13.3 0.14.0
lz4_flex 0.13.1 0.14.0
apache-avro 0.21.0 0.22.0
num-bigint 0.4.8 0.5.1
base64 0.22.1 0.23.1

Updates brotli from 8.0.4 to 9.0.0

Commits
  • a51b65e 9.0.0 release
  • fb3104d Add non-default portable-float feature for target-independent encoder output
  • c9af3de Fix #257
  • 93ea851 fix: handle short empty streams in BroCatli
  • 5bf2ed8 fixed simd (.to_int() renamed to .to_simd())
  • ac02943 Revert "fixed simd (.to_int() renamed to .to_simd())"
  • b4ed6ac fixed simd (.to_int() renamed to .to_simd())
  • 3e7adf2 fixed simd (mask.to_int() renamed to mask.to_simd())
  • See full diff in compare view

Updates orc-rust from 0.8.0 to 0.9.0

Commits
  • d21a6e4 feat: bump to 0.9 and upgrade arrow to 59 (#89)
  • 2060e24 feat(writer): add Date32 and timestamp support (#88)
  • d0d723e feat(writer): add ZLIB, Snappy, LZ4, and Zstd compression support (#86)
  • d996ebe Fix Cargo Deny license check workflow invocation (#87)
  • c1e4fe4 chore: fix clippy warnings surfaced by Rust 1.95 (#83)
  • See full diff in compare view

Updates prost from 0.13.5 to 0.14.4

Changelog

Sourced from prost's changelog.

Prost version 0.14.4

PROST! is a Protocol Buffers implementation for the Rust Language. prost generates simple, idiomatic Rust code from proto2 and proto3 files.

🚀 Features

  • (prost-derive) Make is_valid a constant function (#1401)
  • Increase MSRV to 1.85 (#1428)

🐛 Bug Fixes

  • Use Display instead of Debug for generated enumeration attributes (#1419)
  • (prost-derive) Return error for invalid enumeration default identifiers (#1426)
  • (build) Grab binary path from cargo (#1429)
  • (build) Fix C++ build on GCC 15 (#1395)

📚 Documentation

  • Add example for decode_length_delimiter (#1311)
  • Update protobuf-src example to avoid unsafe set_var

🧪 Testing

  • Test derive Eq behavior (#1422)
  • (groups) Actually construct NestedGroup (#1363)

💼 Dependencies

  • (deps) Update criterion requirement from 0.7 to 0.8 (#1374)
  • (deps) Remove getrandom@0.4.1 from build-dependencies (#1400)
  • (deps) Update rand requirement from 0.9 to 0.10 (#1397)
  • (deps) Bump actions/upload-artifact from 6 to 7 (#1409)
  • (deps) Update cargo clippy to 1.89 (#1433)
  • (deps) Update cargo clippy to 1.91 (#1435)
  • (deps) Update and improve nix devshell (#1393)

🎨 Styling

  • Prevent needless borrow (#1404)
  • Use std::hint::black_box() (#1403)
  • Use variables directly in format!() (#1432)
  • Remove explicit .into_iter() (#1434)
  • Run clippy on benches (#1405)

Prost version 0.14.3

PROST! is a Protocol Buffers implementation for the Rust Language. prost generates simple, idiomatic Rust code from proto2 and proto3 files.

⚠️ Heads-up

... (truncated)

Commits

Updates zstd from 0.13.3 to 0.14.0

Commits
  • 648acb4 Avoid let...else in the seekable callbacks
  • e1152c1 Bump versions for the next release
  • 7caed6e Derive the usual traits on ResetDirective
  • bf7b1f7 Refuse to reuse a context an error may have left undefined
  • 1565618 Check the target, not the host, for MSVC
  • 8315a62 Return Ok(0) from Read::read for an empty buffer
  • a7cfa93 Keep the std gate on the Cursor WriteBuf impl
  • 9bf1692 Say why the Send and Sync impls hold
  • 681bcc3 Don't truncate Cursor positions on 32-bit targets
  • d5a1fdd Don't hand out a &mut Seekable from AdvancedSeekable
  • Additional commits viewable in compare view

Updates lz4_flex from 0.13.1 to 0.14.0

Changelog

Sourced from lz4_flex's changelog.

0.14.0 (2026-07-14)

Features

  • Add alloc feature to allow no_std operation without an allocator. The std feature now implies alloc. Without alloc only the _into variants of the block API are available, e.g. compress_into; the compression hash table is placed on the stack or can be provided via compress_into_with_table.
Note: Users with `default-features = false` need to additionally enable the `alloc`
feature to keep the APIs returning `Vec`, e.g. `compress` and `decompress`.
Commits
  • 1bffdcb Merge pull request #229 from PSeitz/release/0.14.0-changelog
  • a5973e4 Update CHANGELOG for 0.14.0 release, bump version to 0.14.0
  • 43cdb22 Merge pull request #228 from PSeitz/0.14.x
  • 08fd47e add release skill
  • a6c6135 Merge pull request #225 from fbrozovic/alloc-feature
  • ca019ec Add alloc feature to support no_std without an allocator
  • 19194f9 Merge pull request #223 from PSeitz/0.13.x
  • See full diff in compare view

Updates apache-avro from 0.21.0 to 0.22.0

Release notes

Sourced from apache-avro's releases.

Apache Avro Rust SDK 0.22.0 release

The Apache Avro Rust SDK 0.22.0 release is a large release with lots of features, fixes and breaking changes. It is strongly recommended to read the Breaking changes and New features sections of the changelog.

What's changed

Breaking changes

  • Resolve schema(ta) in the builder of Writer by @​Kriskras99 in #328
    • The builder now returns an AvroResult
  • Rework schema compatibility by @​Kriskras99 in #342
    • SchemaCompatiblity::can_read and SchemaCompatiblity::mutual_read now return a Compatiblity type
  • Bump MSRV from 1.85 to 1.88 by @​Kriskras99 in #342, #348
  • Schema::Duration now has a FixedSchema allowing access to attributes and Serialize and Deserialize is implemented for apache_avro::Duration by @​jdarais in #382
  • AvroSchema and AvroSchemaComponent are no longer behind the derive feature and have moved from apache_avro::schema::derive to apache_avro::serde by @​martin-g in #394 and @​Kriskras99 in #433
  • Change the implementation of AvroSchemaComponent for Uuid from Schema::Uuid(String) to Schema::Uuid(Fixed(name: "org.apache.avro.rust.Uuid", size: 16)) and allow overwriting a field's schema with the with attribute when using #[derive(AvroSchema)] by @​Kriskras99 in #397, #558
    • When #[avro(with)] is specified without an argument, it will call the get_schema_in_ctxt(&mut HashSet<Name>, NamespaceRef<'_>) -> Schema in the same module as specified by #[serde(with)]
    • When #[avro(with = path::to::some_fn)] is specified with a path, the function it's pointing to will be called with two parameters &mut HashSet<Name>, NamespaceRef<'_>
    • When #[avro(with = || {})] is specified with a closure, that closure is invoked
    • The name of the schema for uuid::Uuid is org.apache.avro.rust.uuid
    • The schema for Uuid can be changed back to a Schema::Uuid(String) using #[avro(with = || Schema::Uuid(UuidSchema::String))] on a field with a Uuid and setting human_readable to true
  • Replace the From<&str> implementations for Name and Alias with TryFrom<&str>, TryFrom<String>, and FromStr as the conversion is not fallible by @​Kriskras99 in #423
  • Rework SpecificSingleObjectWriter removing ::with_capacity and changing write_avro_datum_ref to also take a &NamesRef parameter by @​Kriskras99 in #445
  • Remove the default field from FixedSchema as it is not in the specification by @​Kriskras99 in #460
  • AvroSchemaComponent::get_schema_in_ctxt now takes a &mut HashSet<Name> parameter for the named_schemas parameter by @​Kriskras99 in #471
  • Replace the Schema::map{,_with_attributes} and Schema::array{,_with_attributes} with builders allowing the user to set more fields by @​martin-g in #472
    • This also adds Schema::r#enum, Schema::fixed and Schema::record
  • Stricter schema parsing by @​Kriskras99 in #479
    • This now rejects schemas that were previously accepted by this library, they were already rejected by parsers in different languages
  • Alias::name and Alias::namespace now return references by @​Kriskras99 in #486
  • Remove unused order and position fields in RecordField by @​Kriskras99 in #491
  • Rework Name to be more performant which requires changing the SchemaNameValidator trait by @​Kriskras99 in #493
    • The regex returned by SchemaNameValidator::regex must have a capture group named name which captures the unqualified name when not overriding the SchemaNameValidator::validate function
    • The SchemaNameValidator::validate must now return the start byte of the unqualified name
  • Support enums and tuples in SchemaAwareSerializer, implement SchemaAwareDeserializer and document the mapping between the Serde and Avro data models by @​Kriskras99 in #512, #558
    • The SchemaAware* now have specific requirements for what input they accept, so type definitions might need to be modified to make them work with the new code (especially for enums and tuples)
    • This also makes human_readable configurable per reader and writer instance
    • Array and Map serialisation will not write the block size in bytes unless configured to do so, allowing unbuffered serialisation
    • The AvroSchemaComponent implementation for std::time::Duration has changed to match the (de)serialisation implementation as defined by Serde
      • It is now a Schema::Record(name: "org.apache.avro.rust.Duration", fields: ["secs": "org.apache.avro.rust.u64", "nanos": "long"])
    • The AvroSchemaComponent implementation for BigDecimal is now a Schema::String matching the (de)serialisation implementation as defined by bigdecimal
      • It can be changed back to a Schema::String using #[serde(with = "apache_avro::serde::bigdecimal"), avro(with)] on a field with a BigDecimal
    • The SchemaAwareDeserializer does not support schema resolution, for that use the old from_value implementation (see #575)

New features

  • Make DeflateSettings::compression_level public by @​EmilyMatt in #335
  • Support fixed as a type for uuid by @​Kriskras99 in #339
  • Don't depend on Serde to provide fields in the right order by @​Kriskras99 in #351
    • It is still recommended to match the field order between the type and the schema as out-of-order serialisation incurs a performance penalty
  • Support the #[serde(flatten)] attribute by @​Kriskras99 in #359, #448
    • This attribute is not supported when using apache_avro::serde::to_value
  • Use the Serde attributes and check for conflict with the Avro attributes by @​Kriskras99 in #377
    • This deprecates the Avro attributes for which the value must always match the Serde attribute:

... (truncated)

Commits
  • ec5721c chore(deps): Bump thiserror from 2.0.18 to 2.0.19 (#604)
  • b946aa3 chore(deps): Bump quote from 1.0.46 to 1.0.47 (#605)
  • 98fa1f4 chore(deps): Bump serde from 1.0.228 to 1.0.229 (#607)
  • 49732c4 chore(ci): Bump the github-codeql group with 2 updates (#608)
  • 73629eb chore(ci): Bump shogo82148/actions-setup-perl from 1.41.1 to 1.42.0 (#609)
  • ed733ed chore(ci): Bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 (#610)
  • 1c11867 chore(ci): Bump actions/setup-java from 5.5.0 to 5.6.0 (#611)
  • 6879d53 chore(ci): Bump taiki-e/install-action from 2.83.2 to 2.84.0 (#612)
  • e59778b chore(deps): Bump proc-macro2 from 1.0.106 to 1.0.107 (#603)
  • 784294d fix: Allow serializing an enum inside a union (#591)
  • Additional commits viewable in compare view

Updates num-bigint from 0.4.8 to 0.5.1

Changelog

Sourced from num-bigint's changelog.

Release 0.5.1 (2026-07-04)

Contributors: @​cuviper

Release 0.5.0 (2026-07-02)

  • Upgrade to rand v0.10 and/or v0.9, and split rand_core.
    • The former rand feature is now split into multiple features, rand_0_9, rand_core_0_9, rand_0_10, and rand_core_0_10, depending on the version and feature set you need.
    • The RandBigInt extension trait is now split into BigRng09 and BigRng010 for each version.
    • The gen_* methods are deprecated in favor of new random_* methods.
    • This is also a value-breaking release, as rand defines it.

Contributors: @​bionicles, @​cuviper, @​divergentdave

Commits
  • 33c59ba Merge pull request #348 from cuviper/bz-alg2-step3b
  • 38b68f6 Release 0.5.1
  • f4a43f5 Fix the missing part of the Burnikel-Ziegler algorithm
  • ebfd89a Add failing tests for a bug in B-Z division
  • 0ab95df Merge pull request #338 from cuviper/rand-0.10
  • 33d6998 Release 0.5.0
  • 84d05b7 Clean up manifests of ci crates
  • f8daf56 Allow clippy::duplicate_mod where intended
  • 022310a Rearrange the rand features to support both 0.9 and 0.10
  • 537a036 ci: use the fallback resolver for deps
  • Additional commits viewable in compare view

Updates base64 from 0.22.1 to 0.23.1

Changelog

Sourced from base64's changelog.

0.23.1

  • Make the tests build again on non-SIMD architectures

0.23.0

  • Added more consts for preconfigured configs and engines
  • Make DecodeError::InvalidLastSymbol more clear by including the decoded value
  • Added SIMD-accelerated engines behind the default-on simd-unsafe feature: Simd picks the best instruction set at runtime (AVX2 on x86_64, NEON on aarch64) and falls back to the scalar GeneralPurpose engine, while Avx2 and Neon target one instruction set with no runtime detection and work in no_std. The engines support the standard and URL-safe alphabets.
  • Update MSRV to 1.71.0
  • Add support for custom padding symbols
Commits
  • 069bf70 v0.23.1
  • 6ab1fb0 Merge pull request #310 from musicinmybrain/test-on-non-simd-arches
  • 7cffce6 Fix testing on architectures without unsafe SIMD support
  • e34f9a0 Merge pull request #308 from atouchet/com
  • e9240c9 Remove outdated comment
  • 9e9220a v0.23.0
  • 870326e Merge pull request #306 from marshallpierce/mp/trailing-bits-docs
  • fbec5f1 Document no trailing trailing bits
  • 0a23549 Merge pull request #305 from marshallpierce/mp/edition-2021
  • f10b7e2 Update deps & edition
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

RetriggerConfidence Score: 3/5

Unsafe to merge because two independently reproduced dependency mismatches prevent the core crate from compiling.

Findings

  1. P1 Align ORC dependency versions ▶
  2. P1 Use Avro-compatible BigInt ▶

Summary

  • The ORC dependency changes introduce incompatible Prost and Arrow types, so the core crate no longer builds.
  • The num-bigint upgrade is incompatible with the Avro decimal conversion and independently prevents the core crate from building.

Merge safety: unsafe until both dependency version mismatches are resolved and the core crate builds successfully.

Reviews (1) · Last reviewed commit: "chore(deps): bump the cargo-major group ..."

…ates

Bumps the cargo-major group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [brotli](https://github.com/dropbox/rust-brotli) | `8.0.4` | `9.0.0` |
| [orc-rust](https://github.com/datafusion-contrib/orc-rust) | `0.8.0` | `0.9.0` |
| [prost](https://github.com/tokio-rs/prost) | `0.13.5` | `0.14.4` |
| [zstd](https://github.com/gyscos/zstd-rs) | `0.13.3` | `0.14.0` |
| [lz4_flex](https://github.com/pseitz/lz4_flex) | `0.13.1` | `0.14.0` |
| [apache-avro](https://github.com/apache/avro-rs) | `0.21.0` | `0.22.0` |
| [num-bigint](https://github.com/rust-num/num-bigint) | `0.4.8` | `0.5.1` |
| [base64](https://github.com/marshallpierce/rust-base64) | `0.22.1` | `0.23.1` |



Updates `brotli` from 8.0.4 to 9.0.0
- [Release notes](https://github.com/dropbox/rust-brotli/releases)
- [Commits](dropbox/rust-brotli@8.0.4...9.0.0)

Updates `orc-rust` from 0.8.0 to 0.9.0
- [Release notes](https://github.com/datafusion-contrib/orc-rust/releases)
- [Commits](datafusion-contrib/orc-rust@v0.8.0...v0.9.0)

Updates `prost` from 0.13.5 to 0.14.4
- [Release notes](https://github.com/tokio-rs/prost/releases)
- [Changelog](https://github.com/tokio-rs/prost/blob/master/CHANGELOG.md)
- [Commits](tokio-rs/prost@v0.13.5...v0.14.4)

Updates `zstd` from 0.13.3 to 0.14.0
- [Release notes](https://github.com/gyscos/zstd-rs/releases)
- [Commits](gyscos/zstd-rs@v0.13.3...v0.14.0)

Updates `lz4_flex` from 0.13.1 to 0.14.0
- [Release notes](https://github.com/pseitz/lz4_flex/releases)
- [Changelog](https://github.com/PSeitz/lz4_flex/blob/main/CHANGELOG.md)
- [Commits](PSeitz/lz4_flex@0.13.1...0.14.0)

Updates `apache-avro` from 0.21.0 to 0.22.0
- [Release notes](https://github.com/apache/avro-rs/releases)
- [Changelog](https://github.com/apache/avro-rs/blob/main/RELEASE.md)
- [Commits](apache/avro-rs@rel/release-0.21.0...rel/release-0.22.0)

Updates `num-bigint` from 0.4.8 to 0.5.1
- [Changelog](https://github.com/rust-num/num-bigint/blob/main/RELEASES.md)
- [Commits](rust-num/num-bigint@num-bigint-0.4.8...num-bigint-0.5.1)

Updates `base64` from 0.22.1 to 0.23.1
- [Changelog](https://github.com/marshallpierce/rust-base64/blob/master/RELEASE-NOTES.md)
- [Commits](marshallpierce/rust-base64@v0.22.1...v0.23.1)

---
updated-dependencies:
- dependency-name: brotli
  dependency-version: 9.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: cargo-major
- dependency-name: orc-rust
  dependency-version: 0.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
- dependency-name: prost
  dependency-version: 0.14.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
- dependency-name: zstd
  dependency-version: 0.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
- dependency-name: lz4_flex
  dependency-version: 0.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
- dependency-name: apache-avro
  dependency-version: 0.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
- dependency-name: num-bigint
  dependency-version: 0.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
- dependency-name: base64
  dependency-version: 0.23.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 18, 2026
@dependabot
dependabot Bot requested a review from prsabahrami as a code owner September 18, 2026 13:15
@coderabbitai

coderabbitai Bot commented Sep 18, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: cb410d92-27cd-493a-9b11-e6e03bfc5ca1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown

seagrep benchmarks

micro

micro did not produce a table

e2e S3

e2e did not produce a table

scale

scale did not produce a table

prose

prose did not produce a table

Comment thread Cargo.toml
Comment on lines +53 to +54
orc-rust = { version = "0.9.0", default-features = false }
prost = "0.14.4"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Align ORC dependency versions

The ORC and Prost upgrades leave the core crate using incompatible dependency types: ORC's PostScript requires Prost 0.13's Message trait, while the changed direct dependency imports Prost 0.14's trait. The ORC integration also receives Arrow 59 RecordBatch values where it requires Arrow 58 values. This prevents seagrep-core from compiling, blocking codec functionality and its test suite. Align the ORC-facing Prost and Arrow dependencies and types to compatible versions.

Artifacts

Evidence from the check

  • Contains the complete exact command used for the narrow locked core compilation check, showing the reproducible validation invocation.

Command output from the check

  • Captured output of the locked core compilation check in the parent worktree; it finishes successfully with exit code 0.

Command output from the check

  • Captured output of the same locked core compilation check at PR head; it reports the exact Prost and Arrow source-line errors and exits 101.

Evidence from the check

  • Captured git diff for the PR's Cargo manifest change, showing `Cargo.toml:53-54` upgrade ORC and Prost dependencies.

View artifacts

T-Rex Ran code and verified through T-Rex

Comment thread crates/core/Cargo.toml
apache-avro = { version = "0.21.0", features = ["snappy", "zstandard", "bzip", "xz"] }
num-bigint = "0.4.6"
apache-avro = { version = "0.22.0", features = ["snappy", "zstandard", "bzip", "xz"] }
num-bigint = "0.5.1"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Use Avro-compatible BigInt

This dependency selects num-bigint 0.5.1, but apache-avro 0.22.0 implements its decimal conversion for the distinct num-bigint 0.4.8 BigInt type. The decimal conversion in tabular.rs therefore fails to compile, preventing seagrep-core and its tests from building. Keep the direct dependency on the Avro-compatible version line or update the conversion and Avro dependency together.

Artifacts

Evidence from the check

  • The full authored Bash source runs the requested locked Cargo library test and captures its command, directory, output, and exit status; it provides an exact repeatable reproduction.

Command output from the check

  • Running the narrow reproduction script from `/home/user/repo` produced compiler E0277 at `crates/core/src/codec/tabular.rs:89` and exit code 101; the requested incompatibility is confirmed.

View artifacts

T-Rex Ran code and verified through T-Rex

@greptile-apps

greptile-apps Bot commented Sep 18, 2026

Copy link
Copy Markdown

Comments Outside Diff

These findings sit on lines the diff does not cover, so they could not be posted inline. Each one leaves this list once its file changes.

  • P1 ORC dependency upgrade leaves seagrep-core uncompilable ▶

    • Bug
      • cargo check --locked -p seagrep-core succeeds on the parent revision but fails on PR chore(deps): bump the cargo-major group across 1 directory with 8 updates #104 with compiler errors in ORC handling. The decisive errors are E0599 at crates/core/src/codec/detect.rs:133 (Prost 0.13.5 versus 0.14.4 Message trait mismatch) and E0308 at crates/core/src/codec/tabular.rs:227 (Arrow Array 58.3.0 versus 59.1.0 RecordBatch mismatch).
    • Cause
      • Cargo.toml:53-54 upgrades orc-rust from 0.8.0 to 0.9.0 and the direct prost dependency from 0.13.5 to 0.14.4, while core still bridges ORC's Arrow/Prost types with Arrow 59 and Prost 0.14 imports. These identically named types and traits are version-specific and incompatible.
    • Fix
      • Align the ORC integration with one compatible Prost and Arrow version set: either retain dependency versions compatible with the current core code, or update the ORC-facing imports/types and dependency constraints together so PostScript uses its matching Message trait and all ORC writer/reader RecordBatch values use the same Arrow major version.
  • P1 Avro decimal conversion uses an incompatible num-bigint major version ▶

    • Bug
      • cargo test --locked -p seagrep-core --lib fails with E0277 at crates/core/src/codec/tabular.rs:89:56: BigInt: From<apache_avro::Decimal> is not satisfied. This prevents seagrep-core from compiling.
    • Cause
      • crates/core/Cargo.toml:35 directly selects num-bigint 0.5.1, whereas the locked dependency graph resolves apache-avro 0.22.0 through num-bigint 0.4.8. Rust treats the two BigInt types as distinct, so apache_avro::Decimal cannot implement Into for the directly imported 0.5 type used at tabular.rs:89.
    • Fix
      • Align the direct num-bigint dependency with apache-avro's compatible 0.4 line (or change the decimal conversion to use a type/API compatible with the apache-avro version), then rerun the locked core library tests.

@dependabot @github

dependabot Bot commented on behalf of github Sep 25, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 25, 2026
@dependabot
dependabot Bot deleted the dependabot/cargo/cargo-major-ac014f21cc branch September 25, 2026 13:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants