Skip to content

chore(deps): bump the cargo-major group across 1 directory with 13 updates - #105

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-major-a83d7535ed
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-major-a83d7535ed

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the cargo-major group with 13 updates in the / directory:

Package From To
brotli 8.0.4 9.0.0
arrow-ipc 59.1.0 60.0.0
orc-rust 0.8.0 0.9.0
prost 0.13.5 0.14.4
zstd 0.13.3 0.14.0
lz4_flex 0.13.1 0.14.0
parquet 59.1.0 60.0.0
arrow-json 59.1.0 60.0.0
arrow-schema 59.1.0 60.0.0
apache-avro 0.21.0 0.22.0
num-bigint 0.4.8 0.5.1
arrow-array 59.1.0 60.0.0
base64 0.22.1 0.23.1

Updates brotli from 8.0.4 to 9.0.0

Commits
  • a51b65e 9.0.0 release
  • fb3104d Add non-default portable-float feature for target-independent encoder output
  • c9af3de Fix #257
  • 93ea851 fix: handle short empty streams in BroCatli
  • 5bf2ed8 fixed simd (.to_int() renamed to .to_simd())
  • ac02943 Revert "fixed simd (.to_int() renamed to .to_simd())"
  • b4ed6ac fixed simd (.to_int() renamed to .to_simd())
  • 3e7adf2 fixed simd (mask.to_int() renamed to mask.to_simd())
  • See full diff in compare view

Updates arrow-ipc from 59.1.0 to 60.0.0

Release notes

Sourced from arrow-ipc's releases.

arrow 60.0.0

Changelog

60.0.0 - (2026-09-10)

Full Changelog

Breaking changes

... (truncated)

Changelog

Sourced from arrow-ipc's changelog.

60.0.0 - (2026-09-10)

Full Changelog

Breaking changes

Enhancements

... (truncated)

Commits
  • ef1fa15 Update version to 60.0.0 and add CHANGELOG (#11036)
  • f9e02ba perf(variant): resolve borrowed field names without searching the metadata di...
  • a4963a9 minor : batches_to_flight_data() should not require ownership of arguments ...
  • 44141e6 fix(parquet): skip miniblocks wider than 64 values instead of erroring (#11021)
  • 2078680 Prettify RunEndEncoded datatype display (#10840)
  • b7e5977 [Parquet] Populate bloom filters from the dictionary while a column is dictio...
  • 5be0557 [Parquet] Add writer option to skip bloom filters for column chunks whose dat...
  • b06b9c1 fix(arrow-ipc): return an error for a DictionaryBatch without its data (#11020)
  • 8f00fb4 Fix interleave on zero-width FixedSizeListArray (#11026)
  • 2e3a243 chore(deps): bump zstd from 0.13.3 to 0.14.0 (#11024)
  • Additional commits viewable in compare view

Updates orc-rust from 0.8.0 to 0.9.0

Commits
  • d21a6e4 feat: bump to 0.9 and upgrade arrow to 59 (#89)
  • 2060e24 feat(writer): add Date32 and timestamp support (#88)
  • d0d723e feat(writer): add ZLIB, Snappy, LZ4, and Zstd compression support (#86)
  • d996ebe Fix Cargo Deny license check workflow invocation (#87)
  • c1e4fe4 chore: fix clippy warnings surfaced by Rust 1.95 (#83)
  • See full diff in compare view

Updates prost from 0.13.5 to 0.14.4

Changelog

Sourced from prost's changelog.

Prost version 0.14.4

PROST! is a Protocol Buffers implementation for the Rust Language. prost generates simple, idiomatic Rust code from proto2 and proto3 files.

🚀 Features

  • (prost-derive) Make is_valid a constant function (#1401)
  • Increase MSRV to 1.85 (#1428)

🐛 Bug Fixes

  • Use Display instead of Debug for generated enumeration attributes (#1419)
  • (prost-derive) Return error for invalid enumeration default identifiers (#1426)
  • (build) Grab binary path from cargo (#1429)
  • (build) Fix C++ build on GCC 15 (#1395)

📚 Documentation

  • Add example for decode_length_delimiter (#1311)
  • Update protobuf-src example to avoid unsafe set_var

🧪 Testing

  • Test derive Eq behavior (#1422)
  • (groups) Actually construct NestedGroup (#1363)

💼 Dependencies

  • (deps) Update criterion requirement from 0.7 to 0.8 (#1374)
  • (deps) Remove getrandom@0.4.1 from build-dependencies (#1400)
  • (deps) Update rand requirement from 0.9 to 0.10 (#1397)
  • (deps) Bump actions/upload-artifact from 6 to 7 (#1409)
  • (deps) Update cargo clippy to 1.89 (#1433)
  • (deps) Update cargo clippy to 1.91 (#1435)
  • (deps) Update and improve nix devshell (#1393)

🎨 Styling

  • Prevent needless borrow (#1404)
  • Use std::hint::black_box() (#1403)
  • Use variables directly in format!() (#1432)
  • Remove explicit .into_iter() (#1434)
  • Run clippy on benches (#1405)

Prost version 0.14.3

PROST! is a Protocol Buffers implementation for the Rust Language. prost generates simple, idiomatic Rust code from proto2 and proto3 files.

⚠️ Heads-up

... (truncated)

Commits

Updates zstd from 0.13.3 to 0.14.0

Commits
  • 648acb4 Avoid let...else in the seekable callbacks
  • e1152c1 Bump versions for the next release
  • 7caed6e Derive the usual traits on ResetDirective
  • bf7b1f7 Refuse to reuse a context an error may have left undefined
  • 1565618 Check the target, not the host, for MSVC
  • 8315a62 Return Ok(0) from Read::read for an empty buffer
  • a7cfa93 Keep the std gate on the Cursor WriteBuf impl
  • 9bf1692 Say why the Send and Sync impls hold
  • 681bcc3 Don't truncate Cursor positions on 32-bit targets
  • d5a1fdd Don't hand out a &mut Seekable from AdvancedSeekable
  • Additional commits viewable in compare view

Updates lz4_flex from 0.13.1 to 0.14.0

Changelog

Sourced from lz4_flex's changelog.

0.14.0 (2026-07-14)

Features

  • Add alloc feature to allow no_std operation without an allocator. The std feature now implies alloc. Without alloc only the _into variants of the block API are available, e.g. compress_into; the compression hash table is placed on the stack or can be provided via compress_into_with_table.
Note: Users with `default-features = false` need to additionally enable the `alloc`
feature to keep the APIs returning `Vec`, e.g. `compress` and `decompress`.
Commits
  • 1bffdcb Merge pull request #229 from PSeitz/release/0.14.0-changelog
  • a5973e4 Update CHANGELOG for 0.14.0 release, bump version to 0.14.0
  • 43cdb22 Merge pull request #228 from PSeitz/0.14.x
  • 08fd47e add release skill
  • a6c6135 Merge pull request #225 from fbrozovic/alloc-feature
  • ca019ec Add alloc feature to support no_std without an allocator
  • 19194f9 Merge pull request #223 from PSeitz/0.13.x
  • See full diff in compare view

Updates parquet from 59.1.0 to 60.0.0

Release notes

Sourced from parquet's releases.

arrow 60.0.0

Changelog

60.0.0 - (2026-09-10)

Full Changelog

Breaking changes

... (truncated)

Changelog

Sourced from parquet's changelog.

60.0.0 - (2026-09-10)

Full Changelog

Breaking changes

Enhancements

... (truncated)

Commits
  • ef1fa15 Update version to 60.0.0 and add CHANGELOG (#11036)
  • f9e02ba perf(variant): resolve borrowed field names without searching the metadata di...
  • a4963a9 minor : batches_to_flight_data() should not require ownership of arguments ...
  • 44141e6 fix(parquet): skip miniblocks wider than 64 values instead of erroring (#11021)
  • 2078680 Prettify RunEndEncoded datatype display (#10840)
  • b7e5977 [Parquet] Populate bloom filters from the dictionary while a column is dictio...
  • 5be0557 [Parquet] Add writer option to skip bloom filters for column chunks whose dat...
  • b06b9c1 fix(arrow-ipc): return an error for a DictionaryBatch without its data (#11020)
  • 8f00fb4 Fix interleave on zero-width FixedSizeListArray (#11026)
  • 2e3a243 chore(deps): bump zstd from 0.13.3 to 0.14.0 (#11024)
  • Additional commits viewable in compare view

Updates arrow-json from 59.1.0 to 60.0.0

Release notes

Sourced from arrow-json's releases.

arrow 60.0.0

Changelog

60.0.0 - (2026-09-10)

Full Changelog

Breaking changes

... (truncated)

Changelog

Sourced from arrow-json's changelog.

60.0.0 - (2026-09-10)

Full Changelog

Breaking changes

Enhancements

  • Prettify RunEndEncoded datatype display by @​Rich-T-kid in #10840
  • Add ARROW_VERSION const to arrow-array by @​ylw510 in #10957
  • feat(arrow-buffer): add OverflowError and fallible offset constructors by @​emilk in #10736
  • docs + feature : Introduce schemaBuilder::project + make better docs by @​Rich-T-kid in #10924
  • fix(variant): accept Dictionary and RunEndEncoded metadata in VariantArray by @​peterxcli in #10810
  • feat(parquet): support round-trip of Dictionary(_, Utf8View/BinaryView) columns by @​adamreeve in #10831
  • feat: Add row-group-local RowSelection support to the push decoder by @​haohuaijin in RetriggerConfidence Score: 2/5

    Not safe to merge: seagrep-core does not compile.

    Findings

    1. P1 ORC Arrow versions conflict ▶
    2. P1 ORC protobuf trait mismatch ▶
    3. P1 Avro bigint conversion breaks ▶

    Summary

    The dependency upgrades introduce three incompatible types in core. ORC batches cannot be used by the retained Arrow JSON writer, ORC detection imports the wrong prost trait, and Avro decimals cannot convert into core’s BigInt type. Each produces a compiler error. These build failures must be fixed before merging.

    Reviews (1) · Last reviewed commit: "chore(deps): bump the cargo-major group ..."

…dates

Bumps the cargo-major group with 13 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [brotli](https://github.com/dropbox/rust-brotli) | `8.0.4` | `9.0.0` |
| [arrow-ipc](https://github.com/apache/arrow-rs) | `59.1.0` | `60.0.0` |
| [orc-rust](https://github.com/datafusion-contrib/orc-rust) | `0.8.0` | `0.9.0` |
| [prost](https://github.com/tokio-rs/prost) | `0.13.5` | `0.14.4` |
| [zstd](https://github.com/gyscos/zstd-rs) | `0.13.3` | `0.14.0` |
| [lz4_flex](https://github.com/pseitz/lz4_flex) | `0.13.1` | `0.14.0` |
| [parquet](https://github.com/apache/arrow-rs) | `59.1.0` | `60.0.0` |
| [arrow-json](https://github.com/apache/arrow-rs) | `59.1.0` | `60.0.0` |
| [arrow-schema](https://github.com/apache/arrow-rs) | `59.1.0` | `60.0.0` |
| [apache-avro](https://github.com/apache/avro-rs) | `0.21.0` | `0.22.0` |
| [num-bigint](https://github.com/rust-num/num-bigint) | `0.4.8` | `0.5.1` |
| [arrow-array](https://github.com/apache/arrow-rs) | `59.1.0` | `60.0.0` |
| [base64](https://github.com/marshallpierce/rust-base64) | `0.22.1` | `0.23.1` |



Updates `brotli` from 8.0.4 to 9.0.0
- [Release notes](https://github.com/dropbox/rust-brotli/releases)
- [Commits](dropbox/rust-brotli@8.0.4...9.0.0)

Updates `arrow-ipc` from 59.1.0 to 60.0.0
- [Release notes](https://github.com/apache/arrow-rs/releases)
- [Changelog](https://github.com/apache/arrow-rs/blob/main/CHANGELOG.md)
- [Commits](apache/arrow-rs@59.1.0...60.0.0)

Updates `orc-rust` from 0.8.0 to 0.9.0
- [Release notes](https://github.com/datafusion-contrib/orc-rust/releases)
- [Commits](datafusion-contrib/orc-rust@v0.8.0...v0.9.0)

Updates `prost` from 0.13.5 to 0.14.4
- [Release notes](https://github.com/tokio-rs/prost/releases)
- [Changelog](https://github.com/tokio-rs/prost/blob/master/CHANGELOG.md)
- [Commits](tokio-rs/prost@v0.13.5...v0.14.4)

Updates `zstd` from 0.13.3 to 0.14.0
- [Release notes](https://github.com/gyscos/zstd-rs/releases)
- [Commits](gyscos/zstd-rs@v0.13.3...v0.14.0)

Updates `lz4_flex` from 0.13.1 to 0.14.0
- [Release notes](https://github.com/pseitz/lz4_flex/releases)
- [Changelog](https://github.com/PSeitz/lz4_flex/blob/main/CHANGELOG.md)
- [Commits](PSeitz/lz4_flex@0.13.1...0.14.0)

Updates `parquet` from 59.1.0 to 60.0.0
- [Release notes](https://github.com/apache/arrow-rs/releases)
- [Changelog](https://github.com/apache/arrow-rs/blob/main/CHANGELOG.md)
- [Commits](apache/arrow-rs@59.1.0...60.0.0)

Updates `arrow-json` from 59.1.0 to 60.0.0
- [Release notes](https://github.com/apache/arrow-rs/releases)
- [Changelog](https://github.com/apache/arrow-rs/blob/main/CHANGELOG.md)
- [Commits](apache/arrow-rs@59.1.0...60.0.0)

Updates `arrow-schema` from 59.1.0 to 60.0.0
- [Release notes](https://github.com/apache/arrow-rs/releases)
- [Changelog](https://github.com/apache/arrow-rs/blob/main/CHANGELOG.md)
- [Commits](apache/arrow-rs@59.1.0...60.0.0)

Updates `apache-avro` from 0.21.0 to 0.22.0
- [Release notes](https://github.com/apache/avro-rs/releases)
- [Changelog](https://github.com/apache/avro-rs/blob/main/RELEASE.md)
- [Commits](apache/avro-rs@rel/release-0.21.0...rel/release-0.22.0)

Updates `num-bigint` from 0.4.8 to 0.5.1
- [Changelog](https://github.com/rust-num/num-bigint/blob/main/RELEASES.md)
- [Commits](rust-num/num-bigint@num-bigint-0.4.8...num-bigint-0.5.1)

Updates `arrow-array` from 59.1.0 to 60.0.0
- [Release notes](https://github.com/apache/arrow-rs/releases)
- [Changelog](https://github.com/apache/arrow-rs/blob/main/CHANGELOG.md)
- [Commits](apache/arrow-rs@59.1.0...60.0.0)

Updates `base64` from 0.22.1 to 0.23.1
- [Changelog](https://github.com/marshallpierce/rust-base64/blob/master/RELEASE-NOTES.md)
- [Commits](marshallpierce/rust-base64@v0.22.1...v0.23.1)

---
updated-dependencies:
- dependency-name: brotli
  dependency-version: 9.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: cargo-major
- dependency-name: arrow-ipc
  dependency-version: 60.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: cargo-major
- dependency-name: orc-rust
  dependency-version: 0.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
- dependency-name: prost
  dependency-version: 0.14.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
- dependency-name: zstd
  dependency-version: 0.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
- dependency-name: lz4_flex
  dependency-version: 0.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
- dependency-name: parquet
  dependency-version: 60.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: cargo-major
- dependency-name: arrow-json
  dependency-version: 60.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: cargo-major
- dependency-name: arrow-schema
  dependency-version: 60.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: cargo-major
- dependency-name: apache-avro
  dependency-version: 0.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
- dependency-name: num-bigint
  dependency-version: 0.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
- dependency-name: arrow-array
  dependency-version: 60.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: cargo-major
- dependency-name: base64
  dependency-version: 0.23.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 25, 2026
@dependabot
dependabot Bot requested a review from prsabahrami as a code owner September 25, 2026 13:16
@coderabbitai

coderabbitai Bot commented Sep 25, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 04541983-7766-4ba4-949e-1dcc171b61ba

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread Cargo.toml
prost = "0.13.5"
brotli = "9.0.0"
arrow-ipc = { version = "60.0.0", features = ["lz4", "zstd"] }
orc-rust = { version = "0.9.0", default-features = false }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 ORC Arrow versions conflict

Upgrading orc-rust makes its reader return Arrow 59 batches, but the ORC conversion still passes them to an Arrow 58 JSON writer. The ORC test writers also receive Arrow 58 schemas and batches. These incompatible types prevent seagrep-core and its tests from compiling; align the Arrow types before merging.

Artifacts

Executed manifest and ORC source inspection command

  • This is the command run to capture the changed dependency lines, implicated source lines, and resolved Arrow versions; it identifies the version boundary.

Manifest, ORC source, and dependency inspection output

  • Running the inspection command showed ORC resolving Arrow 59.3.0 while the JSON writer resolves Arrow 58.3.0; the versions differ.

Parent-revision core check blocked by missing offline dependency

  • The same locked offline core check against `HEAD^` exited 101 before compilation because `rand_chacha` was absent from the cache; a passing baseline could not be captured.

PR-revision core check fails on ORC and JSON batch types

  • The requested locked offline core check exited 101 and reported the Arrow 58 versus Arrow 59 `RecordBatch` mismatch at `tabular.rs:227`; the library does not compile.

PR-revision test check fails on ORC helper writer types

  • The locked offline test check exited 101 and reported Arrow schema and batch mismatches in both ORC test writers; the tests do not compile.

View artifacts

T-Rex Ran code and verified through T-Rex

Comment thread Cargo.toml
brotli = "9.0.0"
arrow-ipc = { version = "60.0.0", features = ["lz4", "zstd"] }
orc-rust = { version = "0.9.0", default-features = false }
prost = "0.14.4"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 ORC protobuf trait mismatch

Core now imports prost::Message 0.14, while orc-rust uses prost 0.13 for PostScript. The imported trait cannot provide PostScript::decode in ORC detection, so seagrep-core fails to compile. Align the prost versions before merging.

Artifacts

Executed core-check script

  • This is the exact script executed with `sh` to run the locked, offline core check and print its exit code.

Core-check compiler output on the PR checkout

  • Captured the script invocation and compiler output; E0599 identifies the prost trait mismatch and the check exits 101.

Changed manifest line and ORC detection call

  • Captured the manifest diff and numbered source; they locate the prost upgrade at `Cargo.toml:54` and the decode call at `detect.rs:133`.

Dependency paths for both prost versions

  • Captured inverse dependency trees showing prost 0.13.5 through `orc-rust` and prost 0.14.4 directly through core.

Parent-revision check blocked by offline dependency

  • Attempted the same check against the parent revision; offline resolution stopped at uncached `rand_chacha`, so a passing baseline was not established.

View artifacts

T-Rex Ran code and verified through T-Rex

Comment thread crates/core/Cargo.toml
arrow-json = "60.0.0"
arrow-schema = "60.0.0"
apache-avro = { version = "0.22.0", features = ["snappy", "zstandard", "bzip", "xz"] }
num-bigint = "0.5.1"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Avro bigint conversion breaks

Core now uses num-bigint 0.5, but apache-avro 0.22 implements its Decimal conversion for the distinct 0.4 BigInt type. The typed conversion in Avro decoding has no matching implementation, so seagrep-core fails to compile. Use compatible types or an explicit conversion before merging.

Artifacts

Executed Avro core-check validation script

  • This is the exact script executed to inspect the dependency mismatch and run the targeted compiler check.

Observed Avro core-check output

  • Captured the executed script's output with its command, working directory, and exit code, confirming the E0277 compilation failure.

View artifacts

T-Rex Ran code and verified through T-Rex

@greptile-apps

greptile-apps Bot commented Sep 25, 2026

Copy link
Copy Markdown

Comments Outside Diff

These findings sit on lines the diff does not cover, so they could not be posted inline. Each one leaves this list once its file changes.

  • P1 ORC 0.9 uses Arrow 59 types where the ORC path still uses Arrow 58 ▶

    • Bug
      • The ORC reader's batches cannot be passed to the Arrow JSON 58 writer, and ORC test writers cannot accept Arrow 58 schemas or batches. The core library and its tests fail to compile.
    • Cause
      • Cargo.toml:53 upgrades orc-rust to 0.9.0 without aligning the ORC conversion and test code at tabular.rs:217-227, codec.rs:1459-1473, and testutil.rs:195-206 with its Arrow 59 types.
    • Fix
      • Use Arrow-compatible JSON writing and test batches for the upgraded ORC reader and writer, then rerun the core library and test checks.
  • P1 Prost version mismatch prevents core ORC detection from compiling ▶

    • Bug
      • The targeted core check fails at PostScript::decode because the imported Message trait is from a different prost version. Security assessment: no security vulnerability demonstrated.
    • Cause
      • Cargo.toml:54 upgrades workspace prost to 0.14.4 while orc-rust 0.9.0 uses prost 0.13.5 for PostScript.
    • Fix
      • Use a prost 0.13 trait for this call, or adopt an orc-rust version compatible with the imported prost version, then re-run the core check.
  • P1 Avro decimal BigInt conversion prevents core compilation ▶

    • Bug
      • The targeted cargo check reports E0277 because apache_avro::Decimal cannot convert into core's num_bigint::BigInt at crates/core/src/codec/tabular.rs:89.
    • Cause
    • Fix
      • Use a compatible 0.4 direct dependency, or convert the decimal through a version-independent representation.

@github-actions

Copy link
Copy Markdown

seagrep benchmarks

micro

micro did not produce a table

e2e S3

e2e did not produce a table

scale

scale did not produce a table

prose

prose did not produce a table

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants