Skip to content

chore(deps): bump clap from 4.6.6 to 4.6.7 - #6343

Merged
Hmbown merged 2 commits into
mainfrom
dependabot/cargo/clap-4.6.7
Sep 21, 2026
Merged

Hmbown merged 2 commits into
mainfrom
dependabot/cargo/clap-4.6.7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Bumps clap from 4.6.6 to 4.6.7.

Release notes

Sourced from clap's releases.

v4.6.7

[4.6.7] - 2026-09-14

Features

  • (derive) Add #[command(defer = <bool>)] attribute to opt-in to lazy initialisation of subcommands
Changelog

Sourced from clap's changelog.

[4.6.7] - 2026-09-14

Features

  • (derive) Add #[command(defer = <bool>)] attribute to opt-in to lazy initialisation of subcommands
Commits
  • d3e59a9 chore: Release
  • d997f87 docs: Update changelog
  • fb6058c Merge pull request #6409 from heaths/pwsh-support
  • 2310870 test(complete): Add tests for completer_for_path
  • 5967c17 refactor(complete): Move shell detection to Shells
  • 594602b fix(complete): Detect pwsh for PowerShell
  • 3a4f2d0 Merge pull request #6427 from clap-rs/renovate/shlex-2.x
  • 67ebaed Merge pull request #6426 from clap-rs/renovate/actions-checkout-7.x
  • c968b13 chore(deps): Update Rust crate shlex to v2
  • 8f247cb chore(deps): Update actions/checkout action to v7
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 18, 2026
@dependabot
dependabot Bot requested a review from Hmbown as a code owner September 18, 2026 21:14
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 18, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thanks @dependabot[bot] for taking the time to contribute.

This repository is observing a maintainer-managed PR intake gate in dry-run mode, so this pull request is staying open. This note helps maintainers prepare the allowlist before any enforcement is considered.

Please read CONTRIBUTING.md for the expected contribution shape. A maintainer can grant recurring PR access by commenting /lgtm on a pull request.

Bumps [clap](https://github.com/clap-rs/clap) from 4.6.6 to 4.6.7.
- [Release notes](https://github.com/clap-rs/clap/releases)
- [Changelog](https://github.com/clap-rs/clap/blob/main/CHANGELOG.md)
- [Commits](clap-rs/clap@clap_complete-v4.6.6...clap_complete-v4.6.7)

---
updated-dependencies:
- dependency-name: clap
  dependency-version: 4.6.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/cargo/clap-4.6.7 branch from 75c8bad to ddf7bb5 Compare September 20, 2026 01:14

Hmbown commented Sep 21, 2026 •

Copy link
Copy Markdown
Owner

Brought this branch up to date with main (green since ccbef2c) so CI runs against a base that passes; the earlier red lanes were inherited from the red main this PR was opened on. Merging once the re-run is green.


Generated by Claude Code

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 0 potential issues.

Devin Review

@claude

claude Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @Hmbown's task in 50s —— View job


Claude finished reviewing this PR

  • Gather context (dependabot lockfile-only bump: clap 4.6.6 → 4.6.7)
  • Inspect the diff (git diff origin/main...HEAD)
  • Check for correctness/safety/reuse/test concerns
  • Post final review

Summary

This PR only touches Cargo.lock (+23/-23, 1 file) — no source files changed. The diff is:

  • clap 4.6.6 → 4.6.7, clap_derive 4.6.4 → 4.6.7 (patch releases; 4.6.7 adds a derive #[command(defer = <bool>)] opt-in, no breaking changes per the clap changelog).
  • A batch of transitive windows-sys bumps (0.59.0 / 0.60.2 → 0.61.2) and getrandom 0.3.4 → 0.4.3, pulled in incidentally by the resolver run — normal dependabot lockfile churn, not something this PR's diff controls directly.

Workspace manifests pin clap = { version = "4.5.54", features = ["derive"] } (root Cargo.toml:56) and clap_complete = "4.5" (root Cargo.toml:57); 4.6.7 satisfies both caret requirements, so no manifest edits are needed.

Review against the priority list:

  1. Correctness bugs — N/A, no source code changed.
  2. Provider/model/route safety — N/A, unrelated to this diff.
  3. Reuse/simplification — N/A, lockfile-only change.
  4. Tests — N/A, no new behavior; a lockfile bump doesn't warrant new tests.
  5. Security — no CVE noted in clap 4.6.7's release notes; this is a routine feature/patch release, not a security fix.

Note on verification: I was unable to run cargo metadata --locked / cargo check in this sandbox — cargo invocations required approval that wasn't available in this run. If you want automated build verification of the lockfile bump, that would need to run in CI or with cargo allowed in --allowedTools.

No issues found — this looks like a safe, routine dependency bump.

@codewhale-agent

Copy link
Copy Markdown

Codewhale review did not run

codewhale review --pr 6343 (provider: deepseek) could not reach the model: Review pass 1/1 request failed: Responses API request failed: LLM error: HTTP 402: Insufficient Balance; no partial review was accepted or posted; publication: n.
This is a provider funding/config problem, not a finding about this PR. The check stays advisory; a maintainer with secret access needs to fund or rotate the review key (see .github/workflows/codewhale-review.yml). Re-run the workflow after that.

@Hmbown
Hmbown merged commit 20dd337 into main Sep 21, 2026
34 checks passed
@Hmbown
Hmbown deleted the dependabot/cargo/clap-4.6.7 branch September 21, 2026 15:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant