Skip to content

chore(deps): bump the cargo-major group across 1 directory with 4 updates - #95

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-major-9d53c7780e
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/cargo-major-9d53c7780e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 31, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the cargo-major group with 4 updates in the / directory: prost, lz4_flex, num-bigint and base64.

Updates prost from 0.13.5 to 0.14.4

Changelog

Sourced from prost's changelog.

Prost version 0.14.4

PROST! is a Protocol Buffers implementation for the Rust Language. prost generates simple, idiomatic Rust code from proto2 and proto3 files.

🚀 Features

  • (prost-derive) Make is_valid a constant function (#1401)
  • Increase MSRV to 1.85 (#1428)

🐛 Bug Fixes

  • Use Display instead of Debug for generated enumeration attributes (#1419)
  • (prost-derive) Return error for invalid enumeration default identifiers (#1426)
  • (build) Grab binary path from cargo (#1429)
  • (build) Fix C++ build on GCC 15 (#1395)

📚 Documentation

  • Add example for decode_length_delimiter (#1311)
  • Update protobuf-src example to avoid unsafe set_var

🧪 Testing

  • Test derive Eq behavior (#1422)
  • (groups) Actually construct NestedGroup (#1363)

💼 Dependencies

  • (deps) Update criterion requirement from 0.7 to 0.8 (#1374)
  • (deps) Remove getrandom@0.4.1 from build-dependencies (#1400)
  • (deps) Update rand requirement from 0.9 to 0.10 (#1397)
  • (deps) Bump actions/upload-artifact from 6 to 7 (#1409)
  • (deps) Update cargo clippy to 1.89 (#1433)
  • (deps) Update cargo clippy to 1.91 (#1435)
  • (deps) Update and improve nix devshell (#1393)

🎨 Styling

  • Prevent needless borrow (#1404)
  • Use std::hint::black_box() (#1403)
  • Use variables directly in format!() (#1432)
  • Remove explicit .into_iter() (#1434)
  • Run clippy on benches (#1405)

Prost version 0.14.3

PROST! is a Protocol Buffers implementation for the Rust Language. prost generates simple, idiomatic Rust code from proto2 and proto3 files.

⚠️ Heads-up

... (truncated)

Commits

Updates lz4_flex from 0.13.1 to 0.14.0

Changelog

Sourced from lz4_flex's changelog.

0.14.0 (2026-07-14)

Features

  • Add alloc feature to allow no_std operation without an allocator. The std feature now implies alloc. Without alloc only the _into variants of the block API are available, e.g. compress_into; the compression hash table is placed on the stack or can be provided via compress_into_with_table.
Note: Users with `default-features = false` need to additionally enable the `alloc`
feature to keep the APIs returning `Vec`, e.g. `compress` and `decompress`.
Commits
  • 1bffdcb Merge pull request #229 from PSeitz/release/0.14.0-changelog
  • a5973e4 Update CHANGELOG for 0.14.0 release, bump version to 0.14.0
  • 43cdb22 Merge pull request #228 from PSeitz/0.14.x
  • 08fd47e add release skill
  • a6c6135 Merge pull request #225 from fbrozovic/alloc-feature
  • ca019ec Add alloc feature to support no_std without an allocator
  • 19194f9 Merge pull request #223 from PSeitz/0.13.x
  • See full diff in compare view

Updates num-bigint from 0.4.8 to 0.5.1

Changelog

Sourced from num-bigint's changelog.

Release 0.5.1 (2026-07-04)

Contributors: @​cuviper

Release 0.5.0 (2026-07-02)

  • Upgrade to rand v0.10 and/or v0.9, and split rand_core.
    • The former rand feature is now split into multiple features, rand_0_9, rand_core_0_9, rand_0_10, and rand_core_0_10, depending on the version and feature set you need.
    • The RandBigInt extension trait is now split into BigRng09 and BigRng010 for each version.
    • The gen_* methods are deprecated in favor of new random_* methods.
    • This is also a value-breaking release, as rand defines it.

Contributors: @​bionicles, @​cuviper, @​divergentdave

Commits
  • 33c59ba Merge pull request #348 from cuviper/bz-alg2-step3b
  • 38b68f6 Release 0.5.1
  • f4a43f5 Fix the missing part of the Burnikel-Ziegler algorithm
  • ebfd89a Add failing tests for a bug in B-Z division
  • 0ab95df Merge pull request #338 from cuviper/rand-0.10
  • 33d6998 Release 0.5.0
  • 84d05b7 Clean up manifests of ci crates
  • f8daf56 Allow clippy::duplicate_mod where intended
  • 022310a Rearrange the rand features to support both 0.9 and 0.10
  • 537a036 ci: use the fallback resolver for deps
  • Additional commits viewable in compare view

Updates base64 from 0.22.1 to 0.23.0

Changelog

Sourced from base64's changelog.

0.23.0

  • Added more consts for preconfigured configs and engines
  • Make DecodeError::InvalidLastSymbol more clear by including the decoded value
  • Added SIMD-accelerated engines behind the default-on simd-unsafe feature: Simd picks the best instruction set at runtime (AVX2 on x86_64, NEON on aarch64) and falls back to the scalar GeneralPurpose engine, while Avx2 and Neon target one instruction set with no runtime detection and work in no_std. The engines support the standard and URL-safe alphabets.
  • Update MSRV to 1.71.0
  • Add support for custom padding symbols
Commits
  • 9e9220a v0.23.0
  • 870326e Merge pull request #306 from marshallpierce/mp/trailing-bits-docs
  • fbec5f1 Document no trailing trailing bits
  • 0a23549 Merge pull request #305 from marshallpierce/mp/edition-2021
  • f10b7e2 Update deps & edition
  • 9d21a59 Merge pull request #304 from marshallpierce/mp/custom-padding-rebase
  • f70bad2 Support custom padding symbols
  • 684d79c Merge pull request #301 from marshallpierce/mp/simd-gardening
  • 5bf66f2 Merge pull request #284 from AbeZbm/add-tests
  • d3831cf Followups to SIMD work
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Note

Medium Risk
Upgrades sit on core decompression/protobuf/big-int decode and CLI base64 JSON encoding; behavior should be unchanged but regressions would affect format handling or output.

Overview
Bumps four direct dependencies and refreshes Cargo.lock, including version-qualified entries where transitive crates still pin older releases.

Workspace / seagrep-core: prost 0.13.5 → 0.14.4 (protobuf handling), lz4_flex 0.13.1 → 0.14.0 (LZ4 frame decode in the codec path), and num-bigint 0.4.x → 0.5.1 (numeric types on parquet/Avro-style decode paths).

seagrep CLI: base64 0.22.1 → 0.23.0 for ripgrep-style JSON output when match data is not valid UTF-8.

There are no application source edits in this diff—only manifest and lockfile updates.

Reviewed by Cursor Bugbot for commit a7a070c. Bugbot is set up for automated code reviews on this repo. Configure here.

Greptile Summary

This change updates direct Rust dependencies across the workspace, including prost and num-bigint. Two independent compatibility regressions prevent seagrep-core from compiling: the ORC decoder in crates/core/src/codec/detect.rs imports a different prost::Message trait version than ORC's generated types implement, and the Avro decimal conversion in crates/core/src/codec/tabular.rs attempts to convert into a different num-bigint::BigInt version than Apache Avro supports. Both failures were reproduced with locked Cargo checks.

Confidence Score: 2/5

T-Rex T-Rex Logs

What T-Rex did

  • T-Rex ran a focused prost-ORC reproduction workflow and captured before/after compilation results and the dependency tree.
  • T-Rex executed the decimal compatibility reproduction and captured distinct BigInt versions and an Avro decimal conversion error, including an after-run log.
  • A separate P1 finding was produced with no artifacts.
  • Another P1 finding was produced with no artifacts.

View all artifacts

T-Rex Ran code and verified through T-Rex

Comments Outside Diff (4)

  1. crates/core/src/codec/detect.rs, line 133 (link)

    P1 Ran cargo check -p seagrep-core --lib --locked against the parent commit and this change.

    • Bug
      • Ran cargo check -p seagrep-core --lib --locked against the parent commit and this change. The parent compilation exited successfully; the changed dependency graph exited 101 with E0599 at crates/core/src/codec/detect.rs:133, reporting that PostScript implements the prost 0.13.5 Message trait while the imported trait is prost 0.14.4. The dependency tree confirms orc-rust 0.8.0 retains prost 0.13.5, confirming that the dependency update breaks ORC codec compilation.
    • Cause
      • T-Rex reproduced this while running the changed behavior, but it did not return a separate root-cause sentence.
    • Fix
      • Update the changed code so this failing path is handled, then rerun the same T-Rex check to confirm it passes.
    Artifacts

    Focused PR #95 prost and ORC reproduction script

    • Runs the identical locked core-library compilation in the detached parent worktree and the PR checkout, saving both command outputs; it provides the executable reproduction.

    Core library compilation before PR #95

    • The parent commit executes `cargo check -p seagrep-core --lib --locked` successfully with exit code 0; the pre-upgrade baseline compiles.

    Core library compilation after PR #95

    • The PR checkout executes the same locked compile and exits 101 with E0599 at `detect.rs:133`, identifying prost 0.13.5 versus 0.14.4 Message traits; the upgrade breaks compilation.

    Before and after compilation exit-code comparison

    • Records the parent commit `4873722` exiting 0 and PR commit `a7a070c` exiting 101 from the focused reproduction; the regression is confirmed.

    ORC prost 0.13.5 dependency tree

    • Shows `orc-rust v0.8.0` reaches `seagrep-core` through prost 0.13.5; ORC retains the incompatible trait version.

    View artifacts

    T-Rex Ran code and verified through T-Rex

  2. crates/core/src/codec/tabular.rs, line 89 (link)

    P1 Ran the focused reproduction script to inspect the resolved num-bigint dependencies and...

    • Bug
      • Ran the focused reproduction script to inspect the resolved num-bigint dependencies and compile seagrep-core with cargo check. The run exited 101 with E0277 at crates/core/src/codec/tabular.rs:89: Apache Avro's Decimal conversion is implemented for num-bigint 0.4.8, while seagrep-core requests num-bigint 0.5.1. The observed distinct crate versions and failing conversion confirm that the update breaks Avro decimal compilation.
    • Cause
      • T-Rex reproduced this while running the changed behavior, but it did not return a separate root-cause sentence.
    • Fix
      • Update the changed code so this failing path is handled, then rerun the same T-Rex check to confirm it passes.
    Artifacts

    Focused decimal compatibility reproduction script

    • Runs the dependency-tree inspection and core library compilation used to reproduce the Avro decimal conversion failure, establishing the exact test procedure.

    Compilation output with distinct BigInt versions and Avro decimal conversion error

    • Captures the executed command, working directory, exit code 101, resolved 0.4.8/0.5.1 dependency split, and the verified `tabular.rs:89` E0277 failure, proving the candidate bug.

    View artifacts

    T-Rex Ran code and verified through T-Rex

  3. General comment

    P1 PR 95 breaks ORC codec compilation through incompatible prost Message traits

    • Bug
      • cargo check -p seagrep-core --lib --locked fails at crates/core/src/codec/detect.rs:133:38: PostScript::decode cannot be resolved because the imported prost::Message is 0.14.4 while orc_rust::proto::PostScript implements the 0.13.5 trait. This prevents the core library, and therefore the workspace, from compiling.
    • Cause
      • The root workspace direct dependency was upgraded to prost 0.14.4, while the pinned orc-rust v0.8.0 dependency graph retains prost 0.13.5; prost traits from distinct major/minor crate versions are incompatible.
    • Fix
      • Use a prost version compatible with orc-rust v0.8.0 for this call (for example restore the direct dependency to 0.13.5), or upgrade orc-rust to a release generated against/supporting prost 0.14 before retaining prost 0.14.4.

    T-Rex Ran code and verified through T-Rex

  4. General comment

    P1 Restore the BigInt version compatible with Apache Avro decimal conversion

    • Bug
    • Cause
      • Cargo resolves semver-incompatible 0.4.8 and 0.5.1 as distinct crates. Trait implementations are type-version-specific, therefore Apache Avro's From<Decimal> implementation for num_bigint 0.4.8 cannot satisfy conversion into num_bigint 0.5.1.
    • Fix
      • Use the num-bigint version required by apache-avro 0.21.0 (0.4.x), or upgrade Apache Avro to a release that supports num-bigint 0.5.x and update the lockfile; then rerun cargo check -p seagrep-core --lib.

    T-Rex Ran code and verified through T-Rex

Reviews (1): Last reviewed commit: "chore(deps): bump the cargo-major group ..." | Re-trigger Greptile

Greptile also left 2 inline comments on this PR.

…ates

Bumps the cargo-major group with 4 updates in the / directory: [prost](https://github.com/tokio-rs/prost), [lz4_flex](https://github.com/pseitz/lz4_flex), [num-bigint](https://github.com/rust-num/num-bigint) and [base64](https://github.com/marshallpierce/rust-base64).


Updates `prost` from 0.13.5 to 0.14.4
- [Release notes](https://github.com/tokio-rs/prost/releases)
- [Changelog](https://github.com/tokio-rs/prost/blob/master/CHANGELOG.md)
- [Commits](tokio-rs/prost@v0.13.5...v0.14.4)

Updates `lz4_flex` from 0.13.1 to 0.14.0
- [Release notes](https://github.com/pseitz/lz4_flex/releases)
- [Changelog](https://github.com/PSeitz/lz4_flex/blob/main/CHANGELOG.md)
- [Commits](PSeitz/lz4_flex@0.13.1...0.14.0)

Updates `num-bigint` from 0.4.8 to 0.5.1
- [Changelog](https://github.com/rust-num/num-bigint/blob/main/RELEASES.md)
- [Commits](rust-num/num-bigint@num-bigint-0.4.8...num-bigint-0.5.1)

Updates `base64` from 0.22.1 to 0.23.0
- [Changelog](https://github.com/marshallpierce/rust-base64/blob/master/RELEASE-NOTES.md)
- [Commits](marshallpierce/rust-base64@v0.22.1...v0.23.0)

---
updated-dependencies:
- dependency-name: prost
  dependency-version: 0.14.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
- dependency-name: lz4_flex
  dependency-version: 0.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
- dependency-name: num-bigint
  dependency-version: 0.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
- dependency-name: base64
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Jul 31, 2026
@dependabot
dependabot Bot requested a review from prsabahrami as a code owner July 31, 2026 13:16
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Jul 31, 2026
@github-actions

Copy link
Copy Markdown

seagrep benchmarks

micro

micro did not produce a table

e2e S3

e2e did not produce a table

scale

scale did not produce a table

prose

prose did not produce a table

Comment thread Cargo.toml
arrow-ipc = { version = "59.1.0", features = ["lz4", "zstd"] }
orc-rust = { version = "0.8.0", default-features = false }
prost = "0.13.5"
prost = "0.14.4"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Mismatched prost Message traits

Upgrading the workspace prost dependency to 0.14.4 makes the ORC decoder fail to compile at crates/core/src/codec/detect.rs:133. orc-rust 0.8.0 still generates PostScript against prost 0.13.5, so its Message implementation is a different trait from the 0.14.4 Message imported by seagrep-core. As a result, PostScript::decode is unavailable and the core crate cannot build.

Comment thread crates/core/Cargo.toml
arrow-schema = "59.1.0"
apache-avro = { version = "0.21.0", features = ["snappy", "zstandard", "bzip", "xz"] }
num-bigint = "0.4.6"
num-bigint = "0.5.1"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Incompatible BigInt conversion types

Upgrading seagrep-core to num-bigint 0.5.1 prevents the Avro decimal conversion at crates/core/src/codec/tabular.rs:89 from compiling. apache-avro 0.21.0 provides From<Decimal> for its resolved num-bigint 0.4.8 type, which is distinct from the 0.5.1 BigInt requested here. The decimal.into() conversion therefore fails with E0277, preventing seagrep-core and the workspace from building.

@dependabot @github

dependabot Bot commented on behalf of github Aug 21, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Aug 21, 2026
@dependabot
dependabot Bot deleted the dependabot/cargo/cargo-major-9d53c7780e branch August 21, 2026 13:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants