Skip to content

chore(deps): upgrade dependencies within seven-day cooldown - #152

Merged
shikhar merged 1 commit into
mainfrom
codex/dep-upgrades-2026-09-25
Sep 26, 2026
Merged

shikhar merged 1 commit into
mainfrom
codex/dep-upgrades-2026-09-25

Conversation

@shikhar

@shikhar shikhar commented Sep 26, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Upgrade direct dependencies and refresh Cargo.lock within the repository's seven-day publication cooldown.
  • Use full major.minor.patch requirements for all 41 direct dependencies, matching the selected lockfile versions. Cargo treats these as compatible-version minimums, not exact pins.
  • Preserve existing features and application code.

Changelog notes

  • aws-config 1.11.0 -> 1.12.0: AWS configuration now resolves with the newer Smithy runtime and SSO/STS clients. The selected release retains the existing Document model after the short-lived 1.7.0 change was reverted; no configuration API migration was needed. AWS SDK September 16 release.
  • aws-smithy-runtime-api 1.15.0 -> 1.16.2: Advances the request/runtime API used by the S3 client. No repository call sites needed changes, and the HTTP 0.2 feature-gating break announced for the later 1.17.0 release is outside this update. Selected AWS SDK release, later release boundary.
  • aws-smithy-types 1.6.2 -> 1.6.4 (dev dependency): 1.6.4 restores the six-variant Document API and HashMap object representation after the 1.7.0 compatibility regression. No test migration was needed. AWS SDK September 16 release.
  • AWS lockfile family: aws-sdk-s3 1.144.0 -> 1.148.0, aws-runtime 1.9.1 -> 1.9.4, aws-sdk-sso 1.108.0 -> 1.111.0, aws-sdk-ssooidc 1.110.0 -> 1.113.0, aws-sdk-sts 1.113.0 -> 1.116.0, aws-sigv4 1.5.1 -> 1.5.3, aws-types 1.5.0 -> 1.6.0, and Smithy HTTP/client/protocol patch releases. S3 adds optional Object Lock variable-retention parameters; STS expands session-token capacity to 4,096 bytes. No S3 read path migration was required. S3 release, STS release, selected versions.
  • foyer family 0.22.4 -> 0.22.6: fixes LRU reinsertion invariants, stale entries after rejected admission, and in-flight may_contains accounting; also updates internal synchronization. Upstream comparison.
  • asyncband 0.6.7 -> 0.7.2: transitive through foyer. The 0.7 line gates primitives by feature and renames/removes some synchronization helpers; foyer incorporates the migration. No formal release notes were found. Upstream comparison.
  • reqwest 0.13.4 -> 0.13.5 (dev dependency): fixes proxy credential selection and timeout classification for decoded response bodies; adds DNS error detection. Release notes.
  • darling 0.23.0 -> 0.24.1 and serde_with 3.22.0 -> 3.23.0: dev-only path through testcontainers. Darling moves to syn 3; serde_with updates its derive support and cfg_attr parsing. These crates require Rust 1.88 or newer, below the tested 1.98.1 toolchain. Darling 0.24.0, 0.24.1, serde_with 3.23.0.
  • tokio-rustls 0.26.4 -> 0.26.5: improves TlsStream::poll_read data return behavior. Upstream comparison.
  • zstd-safe 7.2.4 -> 7.3.0 and zstd-sys 2.0.16 -> 2.1.0: mark experimental block APIs unsafe and adjust platform build configuration; these are transitive through foyer's compression path. Safe wrapper comparison, sys comparison.
  • encoding_rs 0.8.35 -> 0.8.41 (dev-only via reqwest): fixes streaming decode at chunk boundaries and adds SIMD paths. Its MSRV is now 1.88. Upstream comparison.
  • lru 0.18.3 -> 0.18.4 (through AWS S3): adds a retain method; existing cache API use is unchanged. Upstream comparison.
  • rustix 1.1.4 -> 1.1.5: fixes nanosecond-to-microsecond overflow handling and platform build issues in the filesystem/OS dependency tree. Upstream comparison.
  • io-uring 0.7.14 -> 0.7.15: Linux-only foyer storage dependency. No formal release notes or matching repository tag were found for 0.7.15. Crate release.
  • quinn 0.11.11 -> 0.11.12 / quinn-proto 0.11.17 -> 0.11.18: bound datagram buffering and fix transport parameter and flow-control edge cases. These are lockfile-only optional dependencies and are absent from this workspace's active feature graph. Upstream comparison.

Risk notes

  • The main runtime exposure is AWS S3 request/credential handling and foyer cache eviction/storage. Existing downloader, cache, and server integration tests passed with all features enabled.
  • The local run used macOS; Linux-specific io-uring and storage paths rely on CI validation. The seven-day cooldown keeps newer published AWS and other crate versions outside this PR.
  • The selected AWS and foyer crates require Rust 1.94.1 and 1.91 respectively; the local stable toolchain is 1.98.1.
  • Full patch requirements raise the declared minimum for dependencies that previously used broader shorthand; the resolved versions and feature selections are captured in Cargo.lock.
Direct requirement changes

Runtime (33 changed requirements)

async-stream 0.3 -> 0.3.6, aws-config 1.11 -> 1.12.0, aws-sdk-s3 1 -> 1.148.0, aws-smithy-runtime-api 1.15 -> 1.16.2, axum 0.8 -> 0.8.9, axum-server 0.8 -> 0.8.0.
bytes 1.12 -> 1.12.1, bytesize 2.7 -> 2.7.0, clap 4.6 -> 4.6.7, compact_str 0.10 -> 0.10.0, dashmap 6.2 -> 6.2.1, exponential-decay-histogram 0.1 -> 0.1.16.
eyre 0.6 -> 0.6.14, foyer 0.22 -> 0.22.6, futures 0.3 -> 0.3.34, http 1.5 -> 1.5.0, http-body 1.1 -> 1.1.0, http-body-util 0.1 -> 0.1.5.
http-content-range 0.2 -> 0.2.5, httpdate 1.0 -> 1.0.3, itertools 0.15 -> 0.15.0, jemalloc_pprof 0.9 -> 0.9.0, mixtrics 0.2 -> 0.2.5, parking_lot 0.12 -> 0.12.5.
prometheus 0.14 -> 0.14.0, rcgen 0.14 -> 0.14.10, serde 1.0 -> 1.0.229, thiserror 2.0 -> 2.0.20, tikv-jemallocator 0.7 -> 0.7.0, tikv-jemalloc-ctl 0.7 -> 0.7.0.
tokio 1 -> 1.53.1, tracing 0.1 -> 0.1.44, tracing-subscriber 0.3 -> 0.3.23.

Development (7 changed requirements)

aws-smithy-types 1.6.2 -> 1.6.4, hyper 1 -> 1.11.1, hyper-util 0.1 -> 0.1.20, proptest 1.11 -> 1.11.0, reqwest 0.13 -> 0.13.5, serde_json 1.0 -> 1.0.151.
testcontainers 0.28 -> 0.28.0.

http-range-header 0.4.2 already used full patch precision and is unchanged.

Lockfile-only transitive updates

asyncband 0.6.7 -> 0.7.2, aws-runtime 1.9.1 -> 1.9.4, aws-sdk-sso 1.108.0 -> 1.111.0, aws-sdk-ssooidc 1.110.0 -> 1.113.0, aws-sdk-sts 1.113.0 -> 1.116.0, aws-sigv4 1.5.1 -> 1.5.3, aws-smithy-eventstream 0.61.2 -> 0.61.4, aws-smithy-http-client 1.4.0 -> 1.4.2.
aws-smithy-json 0.63.0 -> 0.63.1, aws-smithy-query 0.62.0 -> 0.62.1, aws-smithy-runtime 1.14.0 -> 1.14.2, aws-smithy-schema 0.2.0 -> 0.2.1, aws-smithy-xml 0.62.0 -> 0.62.1, aws-types 1.5.0 -> 1.6.0, bitflags 1.3.2, 2.13.1 -> 1.3.2, 2.13.2, cc 1.4.4 -> 1.4.7.
cfg-if 1.0.4 -> 1.0.5, clap_builder 4.6.6 -> 4.6.7, clap_derive 4.6.4 -> 4.6.7, clap_lex 1.1.0 -> 1.1.1, core_detect none -> 1.0.0, crc32fast 1.5.1 -> 1.5.2, crossbeam-channel 0.5.16 -> 0.5.17, crossbeam-utils 0.8.22 -> 0.8.23.
darling 0.23.0 -> 0.24.1, darling_core 0.23.0 -> 0.24.1, darling_macro 0.23.0 -> 0.24.1, encoding_rs 0.8.35 -> 0.8.41, find-msvc-tools 0.1.11 -> 0.1.13, foyer-common 0.22.4 -> 0.22.6, foyer-memory 0.22.4 -> 0.22.6, foyer-storage 0.22.4 -> 0.22.6.
foyer-tokio 0.22.4 -> 0.22.6, hybrid-array 0.4.14 -> 0.4.15, indexmap 1.9.3, 2.14.1 -> 1.9.3, 2.14.2, io-uring 0.7.14 -> 0.7.15, ipnet 2.12.1 -> 2.12.2, jiff 0.2.35 -> 0.2.37, jiff-core 0.1.0 -> 0.1.1, jiff-static 0.2.35 -> 0.2.37.
js-sys 0.3.104 -> 0.3.105, lru 0.18.3 -> 0.18.4, lru-slab 0.1.2 -> 0.1.3, multiversion none -> 0.9.0, multiversion-macros none -> 0.9.0, multiversion_no_op none -> 1.0.0, portable-atomic-util 0.2.7 -> 0.2.8, quinn 0.11.11 -> 0.11.12.
quinn-proto 0.11.17 -> 0.11.18, rustix 0.38.44, 1.1.4 -> 0.38.44, 1.1.5, serde_with 3.22.0 -> 3.23.0, serde_with_macros 3.22.0 -> 3.23.0, smallvec 1.16.0 -> 1.16.1, syn 2.0.119, 3.0.4 -> 2.0.119, 3.0.6, synstructure 0.13.2 -> 0.13.2, 0.14.0, tinyvec 1.12.0 -> 1.13.3.
tinyvec_macros 0.1.1 -> none, tokio-rustls 0.26.4 -> 0.26.5, unicode-ident 1.0.24 -> 1.0.26, uuid 1.26.0 -> 1.26.1, wasm-bindgen 0.2.127 -> 0.2.128, wasm-bindgen-futures 0.4.77 -> 0.4.78, wasm-bindgen-macro 0.2.127 -> 0.2.128, wasm-bindgen-macro-support 0.2.127 -> 0.2.128.
wasm-bindgen-shared 0.2.127 -> 0.2.128, web-sys 0.3.104 -> 0.3.105, yoke-derive 0.8.2 -> 0.8.3, zerocopy 0.8.56 -> 0.8.57, zerocopy-derive 0.8.56 -> 0.8.57, zerofrom-derive 0.1.7 -> 0.1.8, zlib-rs 0.6.7 -> 0.6.8, zstd-safe 7.2.4 -> 7.3.0.
zstd-sys 2.0.16+zstd.1.5.7 -> 2.1.0+zstd.1.5.7.

Validation

  • cargo metadata --locked --all-features --format-version 1: passed
  • cargo +nightly fmt: passed
  • cargo clippy --locked --all-features --all-targets -- -D warnings --allow deprecated: passed
  • cargo deny check: passed (configured duplicate-version warnings)
  • cargo nextest run --locked --all-features: 109 passed, 1 skipped
  • git diff --check: passed
  • GitHub Actions CI on the latest commit: all seven jobs passed

@greptile-apps

greptile-apps Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

[High risk] Updates Rust dependencies across the codebase.

The PR appears safe to merge, with non-blocking test coverage gaps for AWS default configuration and disk-backed caching.

Findings

  1. P2 AWS defaults lack test coverage ▶
  2. P2 Disk cache lacks test coverage ▶
Fix with agent prompt
### Issue 1
Cargo.toml:12
Production creates its S3 client through `aws_config::load_defaults`, but the S3 tests supply credentials, region, and endpoint explicitly. After this upgrade, a regression in how those defaults are loaded could stop production from fetching objects while the tests still pass. Please add a test that exercises the production configuration path.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

### Issue 2
Cargo.lock:1714
This foyer upgrade affects the optional disk cache, but every cache configuration in the tests sets `disk_cache: None`. The tests therefore cannot catch a storage failure or a problem reading entries written before the upgrade. Please add a disk-backed test that reopens an existing cache.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Summary

This PR raises three direct AWS requirements and refreshes the lockfile, including AWS runtime, foyer storage, and dev-dependency updates.

  • Production AWS default-configuration loading and disk-backed cache behavior remain untested across their respective upgrades.

Reviews (1) · Last reviewed commit: "chore(deps): upgrade dependencies within..."

Comment thread Cargo.toml
[dependencies]
async-stream = "0.3"
aws-config = "1.11"
aws-config = "1.12.0"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 AWS defaults lack test coverage

Production creates its S3 client through aws_config::load_defaults, but the S3 tests supply credentials, region, and endpoint explicitly. After this upgrade, a regression in how those defaults are loaded could stop production from fetching objects while the tests still pass. Please add a test that exercises the production configuration path.

Knowledge Base Used: Object store configuration

Prompt To Fix With AI
This is a comment left during a code review.
Path: Cargo.toml
Line: 12

Comment:
**AWS defaults lack test coverage**

Production creates its S3 client through `aws_config::load_defaults`, but the S3 tests supply credentials, region, and endpoint explicitly. After this upgrade, a regression in how those defaults are loaded could stop production from fetching objects while the tests still pass. Please add a test that exercises the production configuration path.

**Knowledge Base Used:** [Object store configuration](https://app.greptile.com/s2-dev/-/custom-context/knowledge-base/s2-streamstore/cachey/-/docs/object-store-configuration.md)

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

Comment thread Cargo.lock
[[package]]
name = "foyer-storage"
version = "0.22.4"
version = "0.22.6"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Disk cache lacks test coverage

This foyer upgrade affects the optional disk cache, but every cache configuration in the tests sets disk_cache: None. The tests therefore cannot catch a storage failure or a problem reading entries written before the upgrade. Please add a disk-backed test that reopens an existing cache.

Knowledge Base Used: Local cache storage

Prompt To Fix With AI
This is a comment left during a code review.
Path: Cargo.lock
Line: 1714

Comment:
**Disk cache lacks test coverage**

This foyer upgrade affects the optional disk cache, but every cache configuration in the tests sets `disk_cache: None`. The tests therefore cannot catch a storage failure or a problem reading entries written before the upgrade. Please add a disk-backed test that reopens an existing cache.

**Knowledge Base Used:** [Local cache storage](https://app.greptile.com/s2-dev/-/custom-context/knowledge-base/s2-streamstore/cachey/-/docs/cache-storage.md)

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

@shikhar
shikhar force-pushed the codex/dep-upgrades-2026-09-25 branch 2 times, most recently from 02a2f30 to 9bf231d Compare September 26, 2026 03:19
@shikhar
shikhar force-pushed the codex/dep-upgrades-2026-09-25 branch from 88813cf to 08b1e93 Compare September 26, 2026 03:37
@shikhar
shikhar merged commit da66677 into main Sep 26, 2026
7 checks passed
@shikhar
shikhar deleted the codex/dep-upgrades-2026-09-25 branch September 26, 2026 05:14
@github-actions github-actions Bot mentioned this pull request Sep 26, 2026
shikhar pushed a commit that referenced this pull request Sep 26, 2026
## 🤖 New release

* `cachey`: 0.11.1 -> 0.11.2

<details><summary><i><b>Changelog</b></i></summary><p>

<blockquote>

##
[0.11.2](0.11.1...0.11.2)
- 2026-09-26

### Fixed

- *(downloader)* fall back on unsatisfied replica ranges
([#150](#150))

### Other

- *(deps)* upgrade dependencies within seven-day cooldown
([#152](#152))
</blockquote>


</p></details>

---
This PR was generated with
[release-plz](https://github.com/release-plz/release-plz/).

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant