chore(deps): bump the cargo-major group across 1 directory with 4 updates - #95
dependabot[bot] wants to merge 1 commit into
Conversation
…ates Bumps the cargo-major group with 4 updates in the / directory: [prost](https://github.com/tokio-rs/prost), [lz4_flex](https://github.com/pseitz/lz4_flex), [num-bigint](https://github.com/rust-num/num-bigint) and [base64](https://github.com/marshallpierce/rust-base64). Updates `prost` from 0.13.5 to 0.14.4 - [Release notes](https://github.com/tokio-rs/prost/releases) - [Changelog](https://github.com/tokio-rs/prost/blob/master/CHANGELOG.md) - [Commits](tokio-rs/prost@v0.13.5...v0.14.4) Updates `lz4_flex` from 0.13.1 to 0.14.0 - [Release notes](https://github.com/pseitz/lz4_flex/releases) - [Changelog](https://github.com/PSeitz/lz4_flex/blob/main/CHANGELOG.md) - [Commits](PSeitz/lz4_flex@0.13.1...0.14.0) Updates `num-bigint` from 0.4.8 to 0.5.1 - [Changelog](https://github.com/rust-num/num-bigint/blob/main/RELEASES.md) - [Commits](rust-num/num-bigint@num-bigint-0.4.8...num-bigint-0.5.1) Updates `base64` from 0.22.1 to 0.23.0 - [Changelog](https://github.com/marshallpierce/rust-base64/blob/master/RELEASE-NOTES.md) - [Commits](marshallpierce/rust-base64@v0.22.1...v0.23.0) --- updated-dependencies: - dependency-name: prost dependency-version: 0.14.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: lz4_flex dependency-version: 0.14.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: num-bigint dependency-version: 0.5.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: base64 dependency-version: 0.23.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major ... Signed-off-by: dependabot[bot] <support@github.com>
seagrep benchmarksmicromicro did not produce a table e2e S3e2e did not produce a table scalescale did not produce a table proseprose did not produce a table |
| arrow-ipc = { version = "59.1.0", features = ["lz4", "zstd"] } | ||
| orc-rust = { version = "0.8.0", default-features = false } | ||
| prost = "0.13.5" | ||
| prost = "0.14.4" |
There was a problem hiding this comment.
Mismatched prost Message traits
Upgrading the workspace prost dependency to 0.14.4 makes the ORC decoder fail to compile at crates/core/src/codec/detect.rs:133. orc-rust 0.8.0 still generates PostScript against prost 0.13.5, so its Message implementation is a different trait from the 0.14.4 Message imported by seagrep-core. As a result, PostScript::decode is unavailable and the core crate cannot build.
| arrow-schema = "59.1.0" | ||
| apache-avro = { version = "0.21.0", features = ["snappy", "zstandard", "bzip", "xz"] } | ||
| num-bigint = "0.4.6" | ||
| num-bigint = "0.5.1" |
There was a problem hiding this comment.
Incompatible BigInt conversion types
Upgrading seagrep-core to num-bigint 0.5.1 prevents the Avro decimal conversion at crates/core/src/codec/tabular.rs:89 from compiling. apache-avro 0.21.0 provides From<Decimal> for its resolved num-bigint 0.4.8 type, which is distinct from the 0.5.1 BigInt requested here. The decimal.into() conversion therefore fails with E0277, preventing seagrep-core and the workspace from building.
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Bumps the cargo-major group with 4 updates in the / directory: prost, lz4_flex, num-bigint and base64.
Updates
prostfrom 0.13.5 to 0.14.4Changelog
Sourced from prost's changelog.
... (truncated)
Commits
13646cdchore: Release version 0.14.4 (#1437)dad79d5fix(prost-derive): return error for invalid enumeration default identifiers (...b0b6c93ci: Updatecargo clippyto 1.91 (#1435)32cfffbstyle: remove explicit.into_iter()(#1434)2710efdci: Updatecargo clippyto 1.89 (#1433)18ea4e4style: use variables directly informat!()(#1432)2821bd1build(deps): bump actions/upload-artifact from 6 to 7 (#1409)3ce3b39test(groups): Actually constructNestedGroup(#1363)8776405docs: Update changelog for version 0.14.3 (#1431)33d3ef1build: Grab binary path from cargo (#1429)Updates
lz4_flexfrom 0.13.1 to 0.14.0Changelog
Sourced from lz4_flex's changelog.
Commits
1bffdcbMerge pull request #229 from PSeitz/release/0.14.0-changeloga5973e4Update CHANGELOG for 0.14.0 release, bump version to 0.14.043cdb22Merge pull request #228 from PSeitz/0.14.x08fd47eadd release skilla6c6135Merge pull request #225 from fbrozovic/alloc-featureca019ecAdd alloc feature to support no_std without an allocator19194f9Merge pull request #223 from PSeitz/0.13.xUpdates
num-bigintfrom 0.4.8 to 0.5.1Changelog
Sourced from num-bigint's changelog.
Commits
33c59baMerge pull request #348 from cuviper/bz-alg2-step3b38b68f6Release 0.5.1f4a43f5Fix the missing part of the Burnikel-Ziegler algorithmebfd89aAdd failing tests for a bug in B-Z division0ab95dfMerge pull request #338 from cuviper/rand-0.1033d6998Release 0.5.084d05b7Clean up manifests of ci cratesf8daf56Allowclippy::duplicate_modwhere intended022310aRearrange therandfeatures to support both 0.9 and 0.10537a036ci: use the fallback resolver for depsUpdates
base64from 0.22.1 to 0.23.0Changelog
Sourced from base64's changelog.
Commits
9e9220av0.23.0870326eMerge pull request #306 from marshallpierce/mp/trailing-bits-docsfbec5f1Document no trailing trailing bits0a23549Merge pull request #305 from marshallpierce/mp/edition-2021f10b7e2Update deps & edition9d21a59Merge pull request #304 from marshallpierce/mp/custom-padding-rebasef70bad2Support custom padding symbols684d79cMerge pull request #301 from marshallpierce/mp/simd-gardening5bf66f2Merge pull request #284 from AbeZbm/add-testsd3831cfFollowups to SIMD workDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsNote
Medium Risk
Upgrades sit on core decompression/protobuf/big-int decode and CLI base64 JSON encoding; behavior should be unchanged but regressions would affect format handling or output.
Overview
Bumps four direct dependencies and refreshes Cargo.lock, including version-qualified entries where transitive crates still pin older releases.
Workspace /
seagrep-core:prost0.13.5 → 0.14.4 (protobuf handling),lz4_flex0.13.1 → 0.14.0 (LZ4 frame decode in the codec path), andnum-bigint0.4.x → 0.5.1 (numeric types on parquet/Avro-style decode paths).seagrepCLI:base640.22.1 → 0.23.0 for ripgrep-style JSON output when match data is not valid UTF-8.There are no application source edits in this diff—only manifest and lockfile updates.
Reviewed by Cursor Bugbot for commit a7a070c. Bugbot is set up for automated code reviews on this repo. Configure here.
Greptile Summary
This change updates direct Rust dependencies across the workspace, including
prostandnum-bigint. Two independent compatibility regressions preventseagrep-corefrom compiling: the ORC decoder incrates/core/src/codec/detect.rsimports a differentprost::Messagetrait version than ORC's generated types implement, and the Avro decimal conversion incrates/core/src/codec/tabular.rsattempts to convert into a differentnum-bigint::BigIntversion than Apache Avro supports. Both failures were reproduced with locked Cargo checks.Confidence Score: 2/5
What T-Rex did
Comments Outside Diff (4)
crates/core/src/codec/detect.rs, line 133 (link)Artifacts
Focused PR #95 prost and ORC reproduction script
Core library compilation before PR #95
Core library compilation after PR #95
Before and after compilation exit-code comparison
ORC prost 0.13.5 dependency tree
crates/core/src/codec/tabular.rs, line 89 (link)Artifacts
Focused decimal compatibility reproduction script
Compilation output with distinct BigInt versions and Avro decimal conversion error
General comment
cargo check -p seagrep-core --lib --lockedfails atcrates/core/src/codec/detect.rs:133:38:PostScript::decodecannot be resolved because the importedprost::Messageis 0.14.4 whileorc_rust::proto::PostScriptimplements the 0.13.5 trait. This prevents the core library, and therefore the workspace, from compiling.orc-rust v0.8.0dependency graph retains prost 0.13.5; prost traits from distinct major/minor crate versions are incompatible.orc-rust v0.8.0for this call (for example restore the direct dependency to 0.13.5), or upgradeorc-rustto a release generated against/supporting prost 0.14 before retaining prost 0.14.4.General comment
crates/core/src/codec/tabular.rs:89:let unscaled: num_bigint::BigInt = decimal.into();cannot compile after PR chore(deps): bump the cargo-major group across 1 directory with 4 updates #95 upgrades the direct dependency tonum-bigint0.5.1.apache-avro0.21.0 remains resolved againstnum-bigint0.4.8, so itsDecimalconversion targets a distinctBigInttype.From<Decimal>implementation fornum_bigint0.4.8 cannot satisfy conversion intonum_bigint0.5.1.num-bigintversion required byapache-avro0.21.0 (0.4.x), or upgrade Apache Avro to a release that supportsnum-bigint0.5.x and update the lockfile; then reruncargo check -p seagrep-core --lib.Reviews (1): Last reviewed commit: "chore(deps): bump the cargo-major group ..." | Re-trigger Greptile