chore(deps): bump the cargo-major group with 10 updates - #25993
chore(deps): bump the cargo-major group with 10 updates#25993dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the cargo-major group with 10 updates: | Package | From | To | | --- | --- | --- | | [tower-http](https://github.com/tower-rs/tower-http) | `0.4.4` | `0.6.8` | | [metrics-util](https://github.com/metrics-rs/metrics) | `0.18.0` | `0.20.4` | | [prost](https://github.com/tokio-rs/prost) | `0.12.6` | `0.14.3` | | [prost-build](https://github.com/tokio-rs/prost) | `0.12.6` | `0.14.3` | | [prost-reflect](https://github.com/andrewhickman/prost-reflect) | `0.14.7` | `0.16.5` | | [prost-types](https://github.com/tokio-rs/prost) | `0.12.6` | `0.14.3` | | [tokio-tungstenite](https://github.com/snapview/tokio-tungstenite) | `0.20.1` | `0.29.0` | | [tonic-health](https://github.com/hyperium/tonic) | `0.11.0` | `0.14.5` | | [tonic-reflection](https://github.com/hyperium/tonic) | `0.11.0` | `0.14.5` | | [serde_derive_internals](https://github.com/serde-rs/serde) | `0.29.1` | `0.30.0` | Updates `tower-http` from 0.4.4 to 0.6.8 - [Release notes](https://github.com/tower-rs/tower-http/releases) - [Commits](tower-rs/tower-http@tower-http-0.4.4...tower-http-0.6.8) Updates `metrics-util` from 0.18.0 to 0.20.4 - [Changelog](https://github.com/metrics-rs/metrics/blob/main/release.toml) - [Commits](metrics-rs/metrics@metrics-util-v0.18.0...metrics-util-v0.20.4) Updates `prost` from 0.12.6 to 0.14.3 - [Release notes](https://github.com/tokio-rs/prost/releases) - [Changelog](https://github.com/tokio-rs/prost/blob/master/CHANGELOG.md) - [Commits](tokio-rs/prost@v0.12.6...v0.14.3) Updates `prost-build` from 0.12.6 to 0.14.3 - [Release notes](https://github.com/tokio-rs/prost/releases) - [Changelog](https://github.com/tokio-rs/prost/blob/master/CHANGELOG.md) - [Commits](tokio-rs/prost@v0.12.6...v0.14.3) Updates `prost-reflect` from 0.14.7 to 0.16.5 - [Release notes](https://github.com/andrewhickman/prost-reflect/releases) - [Changelog](https://github.com/andrewhickman/prost-reflect/blob/main/CHANGELOG.md) - [Commits](https://github.com/andrewhickman/prost-reflect/commits/prost-reflect-v0.16.5) Updates `prost-types` from 0.12.6 to 0.14.3 - [Release notes](https://github.com/tokio-rs/prost/releases) - [Changelog](https://github.com/tokio-rs/prost/blob/master/CHANGELOG.md) - [Commits](tokio-rs/prost@v0.12.6...v0.14.3) Updates `tokio-tungstenite` from 0.20.1 to 0.29.0 - [Changelog](https://github.com/snapview/tokio-tungstenite/blob/master/CHANGELOG.md) - [Commits](snapview/tokio-tungstenite@v0.20.1...v0.29.0) Updates `tonic-health` from 0.11.0 to 0.14.5 - [Release notes](https://github.com/hyperium/tonic/releases) - [Changelog](https://github.com/grpc/grpc-rust/blob/master/CHANGELOG.md) - [Commits](grpc/grpc-rust@v0.11.0...v0.14.5) Updates `tonic-reflection` from 0.11.0 to 0.14.5 - [Release notes](https://github.com/hyperium/tonic/releases) - [Changelog](https://github.com/grpc/grpc-rust/blob/master/CHANGELOG.md) - [Commits](grpc/grpc-rust@v0.11.0...v0.14.5) Updates `serde_derive_internals` from 0.29.1 to 0.30.0 - [Release notes](https://github.com/serde-rs/serde/releases) - [Commits](https://github.com/serde-rs/serde/commits) --- updated-dependencies: - dependency-name: tower-http dependency-version: 0.6.8 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: metrics-util dependency-version: 0.20.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: prost dependency-version: 0.14.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: prost-build dependency-version: 0.14.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: prost-reflect dependency-version: 0.16.5 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: prost-types dependency-version: 0.14.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: tokio-tungstenite dependency-version: 0.29.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: tonic-health dependency-version: 0.14.5 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: tonic-reflection dependency-version: 0.14.5 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major - dependency-name: serde_derive_internals dependency-version: 0.30.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: cargo-major ... Signed-off-by: dependabot[bot] <support@github.com>
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 906cf7c3f9
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| prost-reflect = { version = "0.14", features = ["serde"], default-features = false } | ||
| prost-types = { version = "0.12", default-features = false } | ||
| prost = { version = "0.14", default-features = false, features = ["std"] } | ||
| prost-build = { version = "0.14", default-features = false } |
There was a problem hiding this comment.
Keep prost-build matched with tonic-build
When the protobuf-build feature or the vector-api-client build script runs, this direct prost-build dependency is now a different crate version than the one exposed by tonic-build 0.11: the lockfile still has tonic-build 0.11.0 depending on prost-build 0.12.6, while build.rs and lib/vector-api-client/build.rs create a direct prost_build::Config and pass it to tonic_build::configure().compile_with_config(...). That makes those build scripts fail before protobuf codegen; either bump tonic-build in lockstep or keep prost-build on 0.12.
Useful? React with 👍 / 👎.
| tonic = { version = "0.11", default-features = false, features = ["transport", "codegen", "prost", "tls", "tls-roots", "gzip", "zstd"] } | ||
| tonic-build = { version = "0.11", default-features = false, features = ["transport", "prost"] } | ||
| tonic-health = { version = "0.11", default-features = false } | ||
| tonic-reflection = { version = "0.11", default-features = false, features = ["server"] } | ||
| tonic-health = { version = "0.14", default-features = false } | ||
| tonic-reflection = { version = "0.14", default-features = false, features = ["server"] } |
There was a problem hiding this comment.
Keep tonic companions on the same major version
With the API or sources-vector features enabled, this now mixes workspace tonic 0.11 with tonic-health/tonic-reflection 0.14; Cargo.lock resolves those companion crates through tonic 0.14.5, but Vector wires their health/reflection services into tonic 0.11 servers/clients (TonicServer, RoutesBuilder, and Channel). Those service/client types come from different tonic/http stacks and cannot be composed with the existing gRPC code, so the API and vector source builds break unless tonic/tonic-build are upgraded together or the companions stay on 0.11.
Useful? React with 👍 / 👎.
| prost-types = { version = "0.12", default-features = false } | ||
| prost = { version = "0.14", default-features = false, features = ["std"] } | ||
| prost-build = { version = "0.14", default-features = false } | ||
| prost-reflect = { version = "0.16", features = ["serde"], default-features = false } |
There was a problem hiding this comment.
Keep prost-reflect aligned with VRL
When the protobuf codec or opentelemetry e2e code is built, this resolves two incompatible prost-reflect versions: Vector imports prost_reflect::MessageDescriptor from 0.16, while vrl::protobuf::{descriptor,encode,parse} still exposes and accepts the 0.14.7 types from the VRL dependency. Calls such as let message_descriptor = get_message_descriptor(...) followed by storing it in Vector's direct MessageDescriptor, or passing it back to encode_message/proto_to_value, no longer type-check; keep prost-reflect on the same major as VRL or update VRL at the same time.
Useful? React with 👍 / 👎.
| prost = { version = "0.14", default-features = false, features = ["std"] } | ||
| prost-build = { version = "0.14", default-features = false } | ||
| prost-reflect = { version = "0.16", features = ["serde"], default-features = false } | ||
| prost-types = { version = "0.14", default-features = false } |
There was a problem hiding this comment.
Keep generated prost types aligned with tonic
With any generated gRPC feature enabled, this upgrades the crate used by generated messages to prost 0.14 while tonic/tonic-build remain at 0.11 and Cargo.lock still has tonic 0.11.0 depending on prost 0.12.6. The generated clients and servers use tonic's ProstCodec, whose public bounds are on tonic's 0.12 prost::Message, so messages deriving the direct 0.14 prost::Message won't satisfy those bounds; bump tonic/tonic-build together with prost or keep prost/prost-types at 0.12.
Useful? React with 👍 / 👎.
| tokio-stream = { version = "0.1.18", default-features = false } | ||
| tokio-test = "0.4.5" | ||
| tokio-tungstenite = { version = "0.20.1", default-features = false } | ||
| tokio-tungstenite = { version = "0.29.0", default-features = false } |
There was a problem hiding this comment.
Update websocket code for tungstenite 0.29 payloads
Enabling any websocket source or sink feature now pulls tungstenite 0.29, whose Message tuple variants use Bytes/Utf8Bytes payloads and an owned close frame API, but the repo still constructs variants directly with String and Vec<u8> in places like Message::Text(initial_message.clone()), Message::Ping(vec![]), and the sink ping path. Those features no longer type-check until the websocket code is migrated to the new payload types or helper constructors, so this dependency needs either code changes or to stay on the old version.
Useful? React with 👍 / 👎.
| proc-macro2 = { version = "1.0", default-features = false } | ||
| quote = { version = "1.0", default-features = false } | ||
| serde_derive_internals = "0.29" | ||
| serde_derive_internals = "0.30" |
There was a problem hiding this comment.
Keep serde internals on the same syn major
This pulls serde_derive_internals 0.30, which resolves through syn 3.0.3, but vector-config-macros still depends on syn 2 and passes its &syn::DeriveInput into serde_ast::Container::from_ast. Because those public AST types now come from different syn majors, every Configurable derive that uses this path fails to compile unless the macro crate is migrated to syn 3 (and compatible darling usage) or serde_derive_internals remains on 0.29.
Useful? React with 👍 / 👎.
| name = "rand_xoshiro" | ||
| version = "0.7.0" |
There was a problem hiding this comment.
Regenerate third-party license metadata
This dependency update adds a new transitive crate, rand_xoshiro, but LICENSE-3rdparty.csv still has no entry for it (rg '^rand_xoshiro,' LICENSE-3rdparty.csv returns nothing). Vector's dependency updates are expected to refresh the generated license inventory, so make check-licenses/license validation will fail until the license file is rebuilt.
Useful? React with 👍 / 👎.
Bumps the cargo-major group with 10 updates:
0.4.40.6.80.18.00.20.40.12.60.14.30.12.60.14.30.14.70.16.50.12.60.14.30.20.10.29.00.11.00.14.50.11.00.14.50.29.10.30.0Updates
tower-httpfrom 0.4.4 to 0.6.8Release notes
Sourced from tower-http's releases.
... (truncated)
Commits
33166c8v0.6.86680160Fix deprecated lints (#608)81b8231ci: Switch cargo-public-api-crates to cargo-check-external-types (#613)1fb0144ci: pin tracing in msrv job (#622)1fe4c09fix(decompression): disablemultiple_membersoption for gzip decoder (#621)3bf1ba7v0.6.7723ca9afix(decompression): Suppress EOF errors caused by decompressing empty body (#...8ab9f82chore(ci): use newer cargo-public-api-crates job (#619)7cfdf76doc: Replace doc_auto_cfg with doc_cfg (#609)50beeafAdd support for custom status code in TimeoutLayer (#599)Updates
metrics-utilfrom 0.18.0 to 0.20.4Commits
8893711chore: Release23cc597chore: Release78ebfc3revert: defer version bumps to cargo-release8d7f5eaupdate CHANGELOG for metricscd5b9a3chore(metrics): update doc comments for macros for consistency9cf1f73fix(metrics): resolve hash mismatch between pre-computed and on-demand key ha...2bfe3baenhancement(metrics): allow specifying description and unit in registration m...dae3a67chore: Release6dddb64update CHANGELOG for metrics-exporter-dogstatsd9e387a4chore: ReleaseUpdates
prostfrom 0.12.6 to 0.14.3Changelog
Sourced from prost's changelog.
... (truncated)
Commits
fafa97fchore: remove protobuf submodule and leverage cmake for it (#1389)e0643e2release 0.14.35595b61fix: Add backDecodeError::new(#1382)e42dcadBufix: Name::full_name() is correct for empty packages (#1386)107153fbuild(deps): update pulldown-cmark-to-cmark requirement from 21 to 22 (#1384)3fc7003build(deps): bump actions/upload-artifact from 5 to 6 (#1381)33f8721fix some forgotten prost import paths (#1385)efb0755chore: Release version 0.14.2 (#1372)91a093ftest(derive_copy): Allow dead code (#1362)2c22c59build(deps): bump actions/checkout from 5 to 6 (#1370)Updates
prost-buildfrom 0.12.6 to 0.14.3Changelog
Sourced from prost-build's changelog.
... (truncated)
Commits
fafa97fchore: remove protobuf submodule and leverage cmake for it (#1389)e0643e2release 0.14.35595b61fix: Add backDecodeError::new(#1382)e42dcadBufix: Name::full_name() is correct for empty packages (#1386)107153fbuild(deps): update pulldown-cmark-to-cmark requirement from 21 to 22 (#1384)3fc7003build(deps): bump actions/upload-artifact from 5 to 6 (#1381)33f8721fix some forgotten prost import paths (#1385)efb0755chore: Release version 0.14.2 (#1372)91a093ftest(derive_copy): Allow dead code (#1362)2c22c59build(deps): bump actions/checkout from 5 to 6 (#1370)Updates
prost-reflectfrom 0.14.7 to 0.16.5Release notes
Sourced from prost-reflect's releases.
... (truncated)
Changelog
Sourced from prost-reflect's changelog.
... (truncated)
Commits
Updates
prost-typesfrom 0.12.6 to 0.14.3Changelog
Sourced from prost-types's changelog.
... (truncated)
Commits
fafa97fchore: remove protobuf submodule and leverage cmake for it (#1389)e0643e2release 0.14.35595b61fix: Add backDecodeError::new(#1382)e42dcadBufix: Name::full_name() is correct for empty packages (#1386)107153fbuild(deps): update pulldown-cmark-to-cmark requirement from 21 to 22 (#1384)3fc7003build(deps): bump actions/upload-artifact from 5 to 6 (#1381)33f8721fix some forgotten prost import paths (#1385)efb0755chore: Release version 0.14.2 (#1372)91a093ftest(derive_copy): Allow dead code (#1362)2c22c59build(deps): bump actions/checkout from 5 to 6 (#1370)Updates
tokio-tungstenitefrom 0.20.1 to 0.29.0Changelog
Sourced from tokio-tungstenite's changelog.
... (truncated)
Commits
7930ff2Bump version38d0465Update Readme (#369)35d110cImplement into_inner to get the underlying stream (#367)f3ae75dUpdatetungsteniteversion and fix bugs25b544eAllow getting a reference to the shared inner stream (#363)e855f9eFix errors in the examples caused byUtf8Error21c5d19Bump versionfbd1471Update performance notes in READMEa8d9f19Bump versionaafb2f9Bump versionUpdates
tonic-healthfrom 0.11.0 to 0.14.5Changelog
Sourced from tonic-health's changelog.
... (truncated)
Commits
3f7caf3chore: prepare v0.14.5 release (#2516)3f56644grpc(chore): add missing copyright notices (#2513)1769c91feat(xds): implement xDS subscription worker (#2478)56f8c6dfeat(grpc): Add TCP listener API in the Runtime trait + tests for server cred...149f366feat(grpc) Add channel credentials API + Insecure credentials (#2495)cd5b32fchore: prepare 0.14.4 release (#2504)27640d2fix(web): allow space after:ingrpc-status(#2506)0c26ee1Fix permission of a series of files (#2502)c25daa6fix(ci): remove comment from manifest to unblock version parsing (#2501)3efc5f9chore(doc): Replace doc_auto_cfg config with doc_cfg (#2428)Updates
tonic-reflectionfrom 0.11.0 to 0.14.5Changelog
Sourced from tonic-reflection's changelog.
... (truncated)
Commits
3f7caf3chore: prepare v0.14.5 release (#2516)3f56644grpc(chore): add missing copyright notices (#2513)1769c91feat(xds): implement xDS subscription worker (#2478)56f8c6dfeat(grpc): Add TCP listener API in the Runtime trait + tests for server cred...149f366feat(grpc) Add channel credentials API + Insecure credentials (#2495)cd5b32fchore: prepare 0.14.4 release (#2504)27640d2fix(web): allow space after:ingrpc-status(#2506)0c26ee1Fix permission of a series of files (#2502)c25daa6fix(ci): remove comment from manifest to unblock version parsing (#2501)3efc5f9chore(doc): Replace doc_auto_cfg config with doc_cfg (#2428)Updates
serde_derive_internalsfrom 0.29.1 to 0.30.0Commits
Most Recent Ignore Conditions Applied to This Pull Request
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions