Skip to content

chore(deps): Bump the cargo-pcai-core group across 1 directory with 17 updates - #83

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/Native/pcai_core/cargo-pcai-core-380642b2b0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/Native/pcai_core/cargo-pcai-core-380642b2b0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the cargo-pcai-core group with 17 updates in the /Native/pcai_core directory:

Package From To
libc 0.2.183 0.2.189
rayon 1.11.0 1.12.0
ignore 0.4.25 0.4.32
globset 0.4.18 0.4.20
regex 1.12.2 1.12.4
serde 1.0.228 1.0.229
serde_json 1.0.149 1.0.151
anyhow 1.0.102 1.0.104
thiserror 2.0.18 2.0.20
chrono 0.4.44 0.4.45
env_logger 0.11.8 0.11.11
async-trait 0.1.89 0.1.92
futures 0.3.31 0.3.34
uuid 1.23.1 1.26.0
ollama-rs 0.3.4 0.3.6
ort 2.0.0-rc.11 2.0.0-rc.13
clap 4.5.56 4.5.60

Updates libc from 0.2.183 to 0.2.189

Release notes

Sourced from libc's releases.

0.2.189

Added

  • Emscripten: Add pthread_sigmask, sigwait, sigwaitinfo, sigtimedwait, faccessat, and pthread_kill (#5270)
  • Linux SPARC: Enable the clone3 syscall (#4980)
  • Solarish: Add CLOCK_PROCESS_CPUTIME_ID and CLOCK_THREAD_CPUTIME_ID (#5274)

Deprecated

  • Deprecate CLONE_INTO_CGROUP and CLONE_CLEAR_SIGHAND. These overflow their types and will be changed to a larger size in the future. (8c6e6710458d)

Fixed

  • Musl riscv32: Rename padding fields to avoid a conflict and fix the build (2499ff0ad993)
  • NuttX: Fix wchar_t definition under Arm (#5245)
  • Windows: Add back link names for time-related symbols (#5300)

0.2.188

Changed

These were removed in 0.2.187 because libc does not actually make Send and Sync guarantees about DIR (or other extern types), but this caused some crates to break. The traits are added back for now to allow time to migrate, but will be removed again in the future; please make sure your crates are not relying on libc::DIR: Send or libc::DIR: Sync.

0.2.187

This release contains a number of improvements related to 64-bit time_t configuration. Of note the existing RUST_LIBC_UNSTABLE_* environment variables have been replaced with configuration options. The new way to use these is:

RUSTFLAGS='--cfg=libc_unstable_musl_v1_2_3' cargo ...
RUSTFLAGS='--cfg=libc_unstable_gnu_time_bits="64"' cargo ...

Being able to set this via RUSTFLAGS makes it easier to only apply configuration to specific targets (and notably, not the host if build scripts are used).

There are two other notable changes:

  • The 32-bit windows-gnu targets now respect libc_unstable_gnu_time_bits

  • uClibc now supports a similar configuration option:

    RUSTFLAGS='--cfg=libc_unstable_uclibc_time64'

... (truncated)

Changelog

Sourced from libc's changelog.

0.2.189 - 2026-07-21

Added

  • Emscripten: Add pthread_sigmask, sigwait, sigwaitinfo, sigtimedwait, faccessat, and pthread_kill (#5270)
  • Linux SPARC: Enable the clone3 syscall (#4980)
  • Solarish: Add CLOCK_PROCESS_CPUTIME_ID and CLOCK_THREAD_CPUTIME_ID (#5274)

Deprecated

  • Deprecate CLONE_INTO_CGROUP and CLONE_CLEAR_SIGHAND. These overflow their types and will be changed to a larger size in the future. (8c6e6710458d)

Fixed

  • Musl riscv32: Rename padding fields to avoid a conflict and fix the build (2499ff0ad993)
  • NuttX: Fix wchar_t definition under Arm (#5245)
  • Windows: Add back link names for time-related symbols (#5300)

0.2.188 - 2026-07-21

Changed

These were removed in 0.2.187 because libc does not actually make Send and Sync guarantees about DIR (or other extern types), but this caused some crates to break. The traits are added back for now to allow time to migrate, but will be removed again in the future; please make sure your crates are not relying on libc::DIR: Send or libc::DIR: Sync.

0.2.187 - 2026-07-20

This release contains a number of improvements related to 64-bit time_t configuration. Of note the existing RUST_LIBC_UNSTABLE_* environment variables have been replaced with configuration options. The new way to use these is:

RUSTFLAGS='--cfg=libc_unstable_musl_v1_2_3' cargo ...
RUSTFLAGS='--cfg=libc_unstable_gnu_time_bits="64"' cargo ...

Being able to set this via RUSTFLAGS makes it easier to only apply configuration to specific targets (and notably, not the host if build scripts are used).

There are two other notable changes:

  • The 32-bit windows-gnu targets now respect libc_unstable_gnu_time_bits
  • uClibc now supports a similar configuration option:

... (truncated)

Commits
  • ef0906e libc: Release 0.2.189
  • 5a79f76 riscv32-musl: Rename padding fields to avoid a conflict
  • 3e51062 psp: Fix overflowing_literals warnings
  • e352fdd emscripten: add pthread_sigmask, sigwait, sigwaitinfo, sigtimedwait, faccessa...
  • 63221b3 macros: Require safe in safe_f! invocations
  • 707ab52 macros: Require unsafe in f! invocations
  • 8e40c94 Enable clone3() syscall on sparc-linux and sparc64-linux
  • 8427909 windows: Add back link names for time-related symbols
  • b4863fa nuttx: fix wchar_t definition under arm
  • 41c683d nuttx: mirror type definitions
  • Additional commits viewable in compare view

Updates rayon from 1.11.0 to 1.12.0

Changelog

Sourced from rayon's changelog.

Release rayon 1.12.0 (2026-04-13)

  • Fixed a bug in parallel Range<char> when the end is 0xE000, just past the surrogate boundary, which was unsafely producing invalid char values.
  • The new method ParallelSlice::par_array_windows works like par_windows but with a constant length, producing &[T; N] items.
Commits
  • 7449d7d Merge #1093
  • b3d9e3f Release rayon 1.8.0 and rayon-core 1.12.0
  • 3fe51e5 Fix clippy::let_and_return
  • 082f215 Merge #1087
  • ea0c06d core: registry: Factor out "wait till out of work" part of the main loop.
  • 75524e2 Merge #1063
  • 01d2800 Ignore the multi-threaded test on emscripten/wasm
  • 40b59c0 core: Make use_current_thread error rather than panic when already in the pool.
  • f4db4d7 core: tests: Add some basic tests for ThreadPoolBuilder::use_current_thread.
  • 87274ad core: registry: Add some more documentation for ThreadPoolBuilder::use_curren...
  • Additional commits viewable in compare view

Updates ignore from 0.4.25 to 0.4.32

Commits
  • 5ed408e ignore-0.4.32
  • 435f59f ignore: skip loading unreachable ignore files
  • f9c05a9 index: remove incorrect README
  • 8372866 index: add some initial indexing scaffolding
  • d99ac34 core: add index module
  • 2ed0c00 flags: disable many flags when indexing is enabled
  • 59e318f ignore-0.4.31
  • a9dc222 cargo: set rust-version on all crates
  • be739c7 index: add grep-index crate
  • d958105 cargo: add new build-time unstable-index feature
  • Additional commits viewable in compare view

Updates globset from 0.4.18 to 0.4.20

Commits
  • 5055264 globset-0.4.20
  • 020687a ignore,globset: increase pool capacity
  • 5ed408e ignore-0.4.32
  • 435f59f ignore: skip loading unreachable ignore files
  • f9c05a9 index: remove incorrect README
  • 8372866 index: add some initial indexing scaffolding
  • d99ac34 core: add index module
  • 2ed0c00 flags: disable many flags when indexing is enabled
  • 59e318f ignore-0.4.31
  • a9dc222 cargo: set rust-version on all crates
  • Additional commits viewable in compare view

Updates regex from 1.12.2 to 1.12.4

Changelog

Sourced from regex's changelog.

1.12.4 (2026-06-09)

This release includes a performance optimization for compilation of regexes with very large character classes.

Improvements:

  • #1308: Avoid re-canonicalizing the entire interval set when pushing new class ranges.

1.12.3 (2026-02-03)

This release excludes some unnecessary things from the archive published to crates.io. Specifically, fuzzing data and various shell scripts are now excluded. If you run into problems, please file an issue.

Improvements:

  • #1319: Switch from a Cargo exclude list to an include list, and exclude some unnecessary stuff.
Commits
  • 7b96fdc 1.12.4
  • 7b89cf0 deps: update to regex-syntax 0.8.11
  • 1401679 regex-syntax-0.8.11
  • d709000 changelog: 1.12.4
  • 9825c74 syntax: avoid re-canonicalizing the entire IntervalSet on push (#1308)
  • a7f2ff6 docs: clarify regex-lite word boundaries
  • 2c7b172 docs: clarify unsupported Anchored::Pattern searches
  • 839d16b regex-syntax-0.8.10
  • c4865a0 syntax: fix negation handling in HIR translation
  • d8761c0 cargo: also include benches
  • Additional commits viewable in compare view

Updates serde from 1.0.228 to 1.0.229

Release notes

Sourced from serde's releases.

v1.0.229

  • Update to syn 3
Commits
  • 7fc3b4c Release 1.0.229
  • 6d6e9a1 Merge pull request #3085 from dtolnay/syn3
  • 6dec3b7 Update to syn 3
  • cfe6692 Resolve mut_mut pedantic clippy lint
  • 1023d07 Update actions/upload-artifact@v6 -> v7
  • dd682c2 Update actions/checkout@v6 -> v7
  • 5f0f18b Update ui test suite to nightly-2026-06-01
  • 63a1498 Regenerate stderr with trybuild normalization fixes
  • fa7da4a Fix unused_features warning
  • 6b1a178 Unpin CI miri toolchain
  • Additional commits viewable in compare view

Updates serde_json from 1.0.149 to 1.0.151

Release notes

Sourced from serde_json's releases.

v1.0.151

v1.0.150

Commits
  • de85007 Release 1.0.151
  • 3b2b3c5 Merge pull request #1331 from WonderLawrence/rawvalue-from-string-unchecked
  • 0406d96 Debug-assert well-formedness and no-whitespace in from_string_unchecked
  • cf16f75 Add RawValue::from_string_unchecked
  • 827a315 Update actions/upload-artifact@v6 -> v7
  • cea36a5 Update actions/checkout@v6 -> v7
  • a1ae73a Release 1.0.150
  • 1a360b0 Merge pull request #1324 from puneetdixit200/reject-non-string-enum-keys
  • 2037b63 Reject non-string enum object keys
  • 5d30df6 Resolve manual_assert_eq pedantic clippy lint
  • Additional commits viewable in compare view

Updates anyhow from 1.0.102 to 1.0.104

Release notes

Sourced from anyhow's releases.

1.0.104

  • Update syn dev-dependency to version 3

1.0.103

  • Fix Stacked Borrows violation (UB) in Error::downcast_mut (#451, #452)
Commits
  • 1dbe186 Release 1.0.104
  • f6479f8 Update to syn 3
  • 5bdb0e2 Release 1.0.103
  • e621bd3 Merge pull request #452 from dtolnay/downcast
  • 6e8c000 Eliminate pointer->reference->pointer during downcast
  • 67c4abd Add regression test for issue 451
  • 917a169 Update actions/upload-artifact@v6 -> v7
  • d9dc3fa Update actions/checkout@v6 -> v7
  • 841522b Raise minimum tested compiler to rust 1.85
  • See full diff in compare view

Updates thiserror from 2.0.18 to 2.0.20

Release notes

Sourced from thiserror's releases.

2.0.20

  • Suppress redundant_field_names clippy lint in generated code (#454)

2.0.19

  • Update to syn 3
Commits
  • b1d5db5 Release 2.0.20
  • c4c3ebd Merge pull request #454 from dtolnay/clippy
  • 2266152 Suppress redundant_field_names clippy lint
  • 2901cfd Raise minimum tested compiler to rust 1.88
  • aa9d91f Update ui tests for version 2.0.19
  • e13a785 Release 2.0.19
  • 0a0e76c Update to syn 3
  • ec42ea7 Update actions/upload-artifact@v6 -> v7
  • 4178c4a Update actions/checkout@v6 -> v7
  • 7214e0e Ignore items_after_statements pedantic clippy lint in test
  • Additional commits viewable in compare view

Updates chrono from 0.4.44 to 0.4.45

Release notes

Sourced from chrono's releases.

0.4.45

What's Changed

Commits
  • 1703382 Prepare 0.4.45 release
  • 881f9ab tz_data: fix tzdata locations on Android
  • f14ead4 fix(tz): reject TZ offset hour of 24 to avoid FixedOffset overflow
  • c6063e6 Update similar-asserts requirement from 1.6.1 to 2.0.0
  • 120686c Bump codecov/codecov-action from 5 to 6
  • See full diff in compare view

Updates env_logger from 0.11.8 to 0.11.11

Release notes

Sourced from env_logger's releases.

v0.11.11

[0.11.11] - 2026-06-25

Internal

  • Updated env_filter

v0.11.10

[0.11.10] - 2026-03-23

Internal

  • Update dependencies

v0.11.9

[0.11.9] - 2026-02-11

Changelog

Sourced from env_logger's changelog.

[0.11.11] - 2026-06-25

Internal

  • Updated env_filter

[0.11.10] - 2026-03-23

Internal

  • Update dependencies

[0.11.9] - 2026-02-11

Commits
  • b4d3f2b chore: Release
  • cc2b2ef chore: Release
  • 69e27d1 docs: Update changelog
  • 166880d Merge pull request #411 from epage/parse
  • 0a580d0 fix(filter): Remove 'parse' on no_std
  • 78d8ef1 Merge pull request #404 from cagatay-y/feature/filter-no_std
  • 132fe86 feat(filter): Add support for no_std environments
  • 4feafa4 refactor(env_filter): Fix unreachable pub warning
  • 92f8d8d Merge pull request #410 from rust-cli/renovate/crate-ci-typos-1.x
  • 4e57784 chore(deps): Update pre-commit hook crate-ci/typos to v1.47.0
  • Additional commits viewable in compare view

Updates async-trait from 0.1.89 to 0.1.92

Release notes

Sourced from async-trait's releases.

0.1.92

  • Resolve double_must_use clippy lint in generated code (#303)

0.1.91

  • Update to syn 3 (#299)
  • Fix mutability for by-reference receivers (#301)

0.1.90

(yanked)

Commits
  • 82e7e9e Release 0.1.92
  • 9a35cb8 Merge pull request #303 from dtolnay/mustuse
  • 875ceec Resolve double_must_use clippy lint
  • 62993a5 Raise minimum tested compiler to rust 1.88
  • d049ee0 Release 0.1.91
  • 7a0961f Merge pull request #301 from dtolnay/mutability
  • 740f86f Ignore mut_mut pedantic clippy lint in test
  • 4699cd3 Fix mutability for by-reference receivers
  • 6dd3573 Add regression test for issue 300
  • 2371797 Release 0.1.90
  • Additional commits viewable in compare view

Updates futures from 0.3.31 to 0.3.34

Release notes

Sourced from futures's releases.

0.3.34

  • Preserve cloned waker identity. (#3032)
  • Updato syn to 3. (#3028)

0.3.33

  • Fix ReadLine's soundness issue regarding to exception safety. (#3020)
  • Fix unsound Send impl for IterPinRef and Iter. (#3003)
  • Fix stacked borrows violation in compat01as03 implementation. (#3012)
  • Fix memory leak in FuturesUnordered::IntoIter. (#3005)
  • Add portable-atomic-alloc feature and use it in FuturesUnordered. (#3007)
  • Re-export alloc::task::Wake. (#3010)
  • Update spin to 0.12. (#3014)

0.3.32

  • Bump MSRV of utility crates to 1.71. (#2989)
  • Soft-deprecate ready! macro in favor of std::task::ready! added in Rust 1.64 (#2925)
  • Soft-deprecate pin_mut! macro in favor of std::pin::pin! added in Rust 1.68 (#2929)
  • Add FuturesOrdered::clear (#2927)
  • Add mpsc::*Receiver::recv (#2947)
  • Add mpsc::*Receiver::try_recv and deprecate mpsc::*Receiver::::try_next (#2944)
  • Implement FusedStream for sink::With (#2948)
  • Add no_std support for shared (#2868)
  • Make Mutex::new() const (#2956)
  • Add #[clippy::has_significant_drop] to guards (#2967)
  • Remove dependency to pin-utils (#2929)
  • Remove dependency on num_cpus (#2946)
  • Performance improvements (#2983)
  • Documentation improvements (#2925, #2926, #2940, #2971)
Changelog

Sourced from futures's changelog.

0.3.34 - 2026-08-11

  • Preserve cloned waker identity. (#3032)
  • Updato syn to 3. (#3028)

0.3.33 - 2026-07-18

  • Fix ReadLine's soundness issue regarding to exception safety. (#3020)
  • Fix unsound Send impl for IterPinRef and Iter. (#3003)
  • Fix stacked borrows violation in compat01as03 implementation. (#3012)
  • Fix memory leak in FuturesUnordered::IntoIter. (#3005)
  • Add portable-atomic-alloc feature and use it in FuturesUnordered. (#3007)
  • Re-export alloc::task::Wake. (#3010)
  • Update spin to 0.12. (#3014)

0.3.32 - 2026-02-15

  • Bump MSRV of utility crates to 1.71. (#2989)
  • Soft-deprecate ready! macro in favor of std::task::ready! added in Rust 1.64 (#2925)
  • Soft-deprecate pin_mut! macro in favor of std::pin::pin! added in Rust 1.68 (#2929)
  • Add FuturesOrdered::clear (#2927)
  • Add mpsc::*Receiver::recv (#2947)
  • Add mpsc::*Receiver::try_recv and deprecate mpsc::*Receiver::::try_next (#2944)
  • Implement FusedStream for sink::With (#2948)
  • Add no_std support for shared (#2868)
  • Make Mutex::new() const (#2956)
  • Add #[clippy::has_significant_drop] to guards (#2967)
  • Remove dependency to pin-utils (#2929)
  • Remove dependency on num_cpus (#2946)
  • Performance improvements (#2983)
  • Documentation improvements (#2925, #2926, #2940, #2971)
Commits

Updates uuid from 1.23.1 to 1.26.0

Release notes

Sourced from uuid's releases.

v1.26.0

What's Changed

Full Changelog: uuid-rs/uuid@1.25.0...v1.26.0

1.25.0

What's Changed

New Contributors

Full Changelog: uuid-rs/uuid@v1.24.1...1.25.0

v1.24.1

What's Changed

New Contributors

Full Changelog: uuid-rs/uuid@v1.24.0...v1.24.1

v1.24.0

What's Changed

New Contributors

Full Changelog: uuid-rs/uuid@v1.23.5...v1.24.0

v1.23.5

What's Changed

New Contributors

Full Changelog: uuid-rs/uuid@v1.23.4...v1.23.5

v1.23.4

... (truncated)

Commits
  • cdc96a8 Merge pull request #905 from uuid-rs/cargo/v1.26.0
  • 34e4f49 don't test macros under miri
  • d9e7242 update nightly used for miri
  • ec16819 prepare for 1.26.0 release
  • 162cd20 Merge pull request #904 from ChrisJr404/v7-additional-precision-bits
  • 97eceff Add ContextV7::with_additional_precision_bits for microsecond clocks
  • 302e0bf Merge pull request #903 from uuid-rs/cargo/1.25.0
  • b7ccde8 prepare for 1.25.0 release
  • c62dffb Merge pull request #902 from ChrisJr404/serde-bytes-module
  • 8c198b2 Add a serde::bytes module that encodes as a byte string
  • Additional commits viewable in compare view

Updates ollama-rs from 0.3.4 to 0.3.6

Release notes

Sourced from ollama-rs's releases.

v0.3.6

What's Changed

Full Changelog: pepperoni21/ollama-rs@v0.3.5...v0.3.6

v0.3.5

What's Changed

New Contributors

Full Changelog: pepperoni21/ollama-rs@v0.3.4...v0.3.5

Commits
  • b3ffdda 0.3.6 update
  • fc2efda Merge pull request #358 from wez/tooltypefix
  • 0ccd9f7 Fix ToolType serializing as "Function" instead of "function"
  • 5253b0e Merge pull request #355 from pepperoni21/dependabot/cargo/quote-1.0.46
  • b213b9f Merge pull request #354 from pepperoni21/dependabot/cargo/syn-2.0.118
  • 97082b5 Bump syn from 2.0.117 to 2.0.118
  • 71f228f Merge pull request #353 from pepperoni21/dependabot/cargo/regex-1.12.4
  • f4fc25d Merge pull request #352 from pepperoni21/dependabot/cargo/log-0.4.33
  • fa98426 Merge pull request #351 from pepperoni21/dependabot/cargo/text-splitter-0.32.0
  • 01f655c Bump quote from 1.0.45 to 1.0.46
  • Additional commits viewable in compare view

Updates ort from 2.0.0-rc.11 to 2.0.0-rc.13

Release notes

Sourced from ort's releases.

v2.0.0-rc.13

2.0.0-rc.13

💖 If you find ort useful, please consider sponsoring us on Open Collective 💖

🤔 Need help upgrading? Ask questions in GitHub Discussions or in the pyke.io Discord server!


...

Description has been truncated

@dependabot @github

dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, rust. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from David-Martel as a code owner September 8, 2026 14:38
David-Martel added a commit that referenced this pull request Sep 8, 2026
Review on #87 caught that `update-types: ["version-update:semver-major"]`
does not match the bump it was written to block. Dependabot classifies an
update by which SemVer *component* changed, and 0.10.9 -> 0.11.0 changes the
minor component -- the major component stays 0.

The consequence is worse than the ignore simply not firing. cargo-pcai-core
groups minor and patch updates, so a bump classified as minor is eligible for
the group: the next run could fold a known-broken sha2 0.11 into the grouped
PR and block an otherwise good batch of updates behind it.

`versions: [">=0.11.0"]` cannot be misclassified. It also covers the eventual
1.0 without another edit.

Note the empirical picture is not clean either way. In the 2026-09 batch,
genuine semver-minor bumps were grouped -- uuid 1.23.1 -> 1.26.0 and rayon
1.11.0 -> 1.12.0 both landed inside #83 -- while sha2 0.10.9 -> 0.11.0 alone
was raised as its own PR (#84), which is what a major classification would
produce. So Dependabot's Cargo handling may well already treat a 0.x minor as
breaking. The range makes that question moot rather than betting on it.

Verified: .github/dependabot.yml parses with all 8 update blocks intact and
the cargo-pcai-core group unchanged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Mu7jB5ysKe4DN5ovjVtX1t
David-Martel added a commit that referenced this pull request Sep 8, 2026
* chore(deps): hold sha2 on the 0.10 line

Dependabot raised sha2 0.10.9 -> 0.11.0 as #84. It does not build.

RustCrypto 0.11 moves digest output from generic-array::GenericArray to
hybrid-array::Array, and Array does not implement LowerHex, so every
`format!("{:x}", hasher.finalize())` stops compiling:

    error[E0277]: the trait `LowerHex` is not implemented for
                  `Array<u8, UInt<UInt<UInt<UInt<UInt<...>>>>>>`
    error: could not compile `pcai_core_lib` (lib) due to 3 previous errors

sha2 is a direct dependency with three hex-formatting call sites:
pcai_core_lib/src/hash.rs, pcai_core_lib/src/search/duplicates.rs, and
pcai_perf_cli/src/main.rs.

The bump would also not consolidate anything. cudaforge and openai-harmony
still require the 0.10 line, so taking 0.11 directly means compiling two
SHA-2 implementations rather than replacing one:

    cudaforge        -> sha2 0.10.9
    openai-harmony   -> sha2 0.10.9
    pcai_core_lib    -> sha2 0.11.0
    pcai-perf        -> sha2 0.11.0

0.10.9 carries no advisory and cargo audit is clean on it, so the cost is
three rewritten call sites and a duplicated hash implementation for no gain.

Scoped to semver-major only, so minor and patch updates to sha2 keep arriving
through the normal cargo-pcai-core group. This is the same reasoning as the
candle pin in the /Deploy block: a stack that has to move as one coordinated
piece, not one crate at a time.

Verified: cargo check -p pcai_core_lib -p pcai-perf --all-targets against the
#84 lockfile fails with the three errors above; the dependabot config parses
with all 8 update blocks intact.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Mu7jB5ysKe4DN5ovjVtX1t

* fix(deps): express the sha2 hold as a version range, not an update-type

Review on #87 caught that `update-types: ["version-update:semver-major"]`
does not match the bump it was written to block. Dependabot classifies an
update by which SemVer *component* changed, and 0.10.9 -> 0.11.0 changes the
minor component -- the major component stays 0.

The consequence is worse than the ignore simply not firing. cargo-pcai-core
groups minor and patch updates, so a bump classified as minor is eligible for
the group: the next run could fold a known-broken sha2 0.11 into the grouped
PR and block an otherwise good batch of updates behind it.

`versions: [">=0.11.0"]` cannot be misclassified. It also covers the eventual
1.0 without another edit.

Note the empirical picture is not clean either way. In the 2026-09 batch,
genuine semver-minor bumps were grouped -- uuid 1.23.1 -> 1.26.0 and rayon
1.11.0 -> 1.12.0 both landed inside #83 -- while sha2 0.10.9 -> 0.11.0 alone
was raised as its own PR (#84), which is what a major classification would
produce. So Dependabot's Cargo handling may well already treat a 0.x minor as
breaking. The range makes that question moot rather than betting on it.

Verified: .github/dependabot.yml parses with all 8 update blocks intact and
the cargo-pcai-core group unchanged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Mu7jB5ysKe4DN5ovjVtX1t

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
…7 updates

Bumps the cargo-pcai-core group with 17 updates in the /Native/pcai_core directory:

| Package | From | To |
| --- | --- | --- |
| [libc](https://github.com/rust-lang/libc) | `0.2.183` | `0.2.189` |
| [rayon](https://github.com/rayon-rs/rayon) | `1.11.0` | `1.12.0` |
| [ignore](https://github.com/BurntSushi/ripgrep) | `0.4.25` | `0.4.32` |
| [globset](https://github.com/BurntSushi/ripgrep) | `0.4.18` | `0.4.20` |
| [regex](https://github.com/rust-lang/regex) | `1.12.2` | `1.12.4` |
| [serde](https://github.com/serde-rs/serde) | `1.0.228` | `1.0.229` |
| [serde_json](https://github.com/serde-rs/json) | `1.0.149` | `1.0.151` |
| [anyhow](https://github.com/dtolnay/anyhow) | `1.0.102` | `1.0.104` |
| [thiserror](https://github.com/dtolnay/thiserror) | `2.0.18` | `2.0.20` |
| [chrono](https://github.com/chronotope/chrono) | `0.4.44` | `0.4.45` |
| [env_logger](https://github.com/rust-cli/env_logger) | `0.11.8` | `0.11.11` |
| [async-trait](https://github.com/dtolnay/async-trait) | `0.1.89` | `0.1.92` |
| [futures](https://github.com/rust-lang/futures-rs) | `0.3.31` | `0.3.34` |
| [uuid](https://github.com/uuid-rs/uuid) | `1.23.1` | `1.26.0` |
| [ollama-rs](https://github.com/pepperoni21/ollama-rs) | `0.3.4` | `0.3.6` |
| [ort](https://github.com/pykeio/ort) | `2.0.0-rc.11` | `2.0.0-rc.13` |
| [clap](https://github.com/clap-rs/clap) | `4.5.56` | `4.5.60` |



Updates `libc` from 0.2.183 to 0.2.189
- [Release notes](https://github.com/rust-lang/libc/releases)
- [Changelog](https://github.com/rust-lang/libc/blob/0.2.189/CHANGELOG.md)
- [Commits](rust-lang/libc@0.2.183...0.2.189)

Updates `rayon` from 1.11.0 to 1.12.0
- [Changelog](https://github.com/rayon-rs/rayon/blob/main/RELEASES.md)
- [Commits](rayon-rs/rayon@rayon-core-v1.11.0...rayon-core-v1.12.0)

Updates `ignore` from 0.4.25 to 0.4.32
- [Release notes](https://github.com/BurntSushi/ripgrep/releases)
- [Changelog](https://github.com/BurntSushi/ripgrep/blob/master/CHANGELOG.md)
- [Commits](BurntSushi/ripgrep@ignore-0.4.25...ignore-0.4.32)

Updates `globset` from 0.4.18 to 0.4.20
- [Release notes](https://github.com/BurntSushi/ripgrep/releases)
- [Changelog](https://github.com/BurntSushi/ripgrep/blob/master/CHANGELOG.md)
- [Commits](BurntSushi/ripgrep@globset-0.4.18...globset-0.4.20)

Updates `regex` from 1.12.2 to 1.12.4
- [Release notes](https://github.com/rust-lang/regex/releases)
- [Changelog](https://github.com/rust-lang/regex/blob/master/CHANGELOG.md)
- [Commits](rust-lang/regex@1.12.2...1.12.4)

Updates `serde` from 1.0.228 to 1.0.229
- [Release notes](https://github.com/serde-rs/serde/releases)
- [Commits](serde-rs/serde@v1.0.228...v1.0.229)

Updates `serde_json` from 1.0.149 to 1.0.151
- [Release notes](https://github.com/serde-rs/json/releases)
- [Commits](serde-rs/json@v1.0.149...v1.0.151)

Updates `anyhow` from 1.0.102 to 1.0.104
- [Release notes](https://github.com/dtolnay/anyhow/releases)
- [Commits](dtolnay/anyhow@1.0.102...1.0.104)

Updates `thiserror` from 2.0.18 to 2.0.20
- [Release notes](https://github.com/dtolnay/thiserror/releases)
- [Commits](dtolnay/thiserror@2.0.18...2.0.20)

Updates `chrono` from 0.4.44 to 0.4.45
- [Release notes](https://github.com/chronotope/chrono/releases)
- [Changelog](https://github.com/chronotope/chrono/blob/main/CHANGELOG.md)
- [Commits](chronotope/chrono@v0.4.44...v0.4.45)

Updates `env_logger` from 0.11.8 to 0.11.11
- [Release notes](https://github.com/rust-cli/env_logger/releases)
- [Changelog](https://github.com/rust-cli/env_logger/blob/main/CHANGELOG.md)
- [Commits](rust-cli/env_logger@v0.11.8...v0.11.11)

Updates `async-trait` from 0.1.89 to 0.1.92
- [Release notes](https://github.com/dtolnay/async-trait/releases)
- [Commits](dtolnay/async-trait@0.1.89...0.1.92)

Updates `futures` from 0.3.31 to 0.3.34
- [Release notes](https://github.com/rust-lang/futures-rs/releases)
- [Changelog](https://github.com/rust-lang/futures-rs/blob/main/CHANGELOG.md)
- [Commits](rust-lang/futures-rs@0.3.31...0.3.34)

Updates `uuid` from 1.23.1 to 1.26.0
- [Release notes](https://github.com/uuid-rs/uuid/releases)
- [Commits](uuid-rs/uuid@v1.23.1...v1.26.0)

Updates `ollama-rs` from 0.3.4 to 0.3.6
- [Release notes](https://github.com/pepperoni21/ollama-rs/releases)
- [Commits](pepperoni21/ollama-rs@v0.3.4...v0.3.6)

Updates `ort` from 2.0.0-rc.11 to 2.0.0-rc.13
- [Release notes](https://github.com/pykeio/ort/releases)
- [Commits](pykeio/ort@v2.0.0-rc.11...v2.0.0-rc.13)

Updates `clap` from 4.5.56 to 4.5.60
- [Release notes](https://github.com/clap-rs/clap/releases)
- [Changelog](https://github.com/clap-rs/clap/blob/master/CHANGELOG.md)
- [Commits](clap-rs/clap@clap_complete-v4.5.56...clap_complete-v4.5.60)

---
updated-dependencies:
- dependency-name: anyhow
  dependency-version: 1.0.104
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-pcai-core
- dependency-name: async-trait
  dependency-version: 0.1.92
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-pcai-core
- dependency-name: chrono
  dependency-version: 0.4.45
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-pcai-core
- dependency-name: clap
  dependency-version: 4.5.60
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-pcai-core
- dependency-name: env_logger
  dependency-version: 0.11.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-pcai-core
- dependency-name: futures
  dependency-version: 0.3.34
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-pcai-core
- dependency-name: globset
  dependency-version: 0.4.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-pcai-core
- dependency-name: ignore
  dependency-version: 0.4.32
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-pcai-core
- dependency-name: libc
  dependency-version: 0.2.189
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-pcai-core
- dependency-name: ollama-rs
  dependency-version: 0.3.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-pcai-core
- dependency-name: ort
  dependency-version: 2.0.0-rc.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-pcai-core
- dependency-name: rayon
  dependency-version: 1.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-pcai-core
- dependency-name: regex
  dependency-version: 1.12.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-pcai-core
- dependency-name: serde
  dependency-version: 1.0.229
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-pcai-core
- dependency-name: serde_json
  dependency-version: 1.0.151
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-pcai-core
- dependency-name: thiserror
  dependency-version: 2.0.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cargo-pcai-core
- dependency-name: uuid
  dependency-version: 1.26.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: cargo-pcai-core
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): Bump the cargo-pcai-core group in /Native/pcai_core with 17 updates chore(deps): Bump the cargo-pcai-core group across 1 directory with 17 updates Sep 8, 2026
@dependabot
dependabot Bot force-pushed the dependabot/cargo/Native/pcai_core/cargo-pcai-core-380642b2b0 branch from 8668f47 to 5abe91d Compare September 8, 2026 16:17
David-Martel added a commit that referenced this pull request Sep 8, 2026
…precation (#85)

* chore(deps): land the 17-update grouped bump, fixing the ollama-rs deprecation

Takes the lockfile from dependabot's grouped PR #83 -- the first PR produced by
the grouping added in #71, and exactly what that change was for: one PR with 17
minor/patch updates instead of 17 separate ones.

#83 could not merge on its own. `ollama-rs` 0.3.4 -> 0.3.6 deprecated
`Ollama::new` in favour of `Ollama::builder().host(host).port(port).build()`,
and the workspace builds with `-D warnings`, so the deprecation is a hard error:

    error: use of deprecated associated function `ollama_rs::Ollama::new`
      --> pcai_ollama_rs\src\main.rs:382:16
      = note: `-D deprecated` implied by `-D warnings`

That is the gate working. A grouped lockfile bump reached a real API change and
the build refused it, which is the whole point of running clippy with
`-D warnings` across the workspace rather than only on pcai_inference.

`build_client` now uses the builder. Note `build()` returns `Ollama` directly,
not a `Result` -- the first attempt applied `?` to it and failed to compile,
which the local build caught before this was pushed.

Verified against the grouped lockfile:

  cargo clippy --workspace --all-targets -D warnings   exit 0
  cargo test  --workspace --features server,ffi --lib  229 passed, 0 failed

The one remaining warning is `linker_messages` from the pcai-inference build
script, which the compiler itself notes "ignores -D warnings"; it is
pre-existing and not introduced here.

* fix(ollama): parse the endpoint forms Ollama actually emits

Addresses the IPv6 review finding on this PR, plus two further defects the
test for it uncovered. All three predate this branch -- `build_client` derived
host and port the same way before the builder migration -- but they live in
the function under review, so they are fixed here rather than deferred.

Host derivation moves into `split_base_url`, a pure function, so the cases are
testable at all; `build_client` now just calls it.

1. IPv6 literals lost their brackets

`Url::host_str()` returns a bare `::1` for `http://[::1]:11434`, so
`format!("{}://{}", scheme, host)` produced `http://::1` -- not a valid URL.
`Url::host()` is used instead, whose `Display` re-adds the brackets.

2. The scheme-less form failed outright

`OLLAMA_HOST` is conventionally written the way Ollama documents it, with no
scheme -- this workstation sets `0.0.0.0:11434`. `Url::parse` rejects that, and
the fallback path parses `default_ollama_url()`, which returns `OLLAMA_HOST`
verbatim, so it failed too. `build_client` returned Err in that configuration.

`parse_ollama_url` retries with an `http://` prefix. The `has_host` guard
covers the opposite trap: `localhost:11434` *does* parse, as scheme `localhost`
with path `11434` and no host, so accepting it unchecked would have produced a
client pointed at nothing.

3. The unspecified address was used as a destination

`OLLAMA_HOST` does double duty -- it tells the server what to bind and clients
where to connect. `0.0.0.0` means "bind every interface"; as a destination it
relies on the OS to reinterpret it. `client_host` resolves the unspecified
address to loopback, v4 and v6. Routable addresses are left alone.

Nine unit tests cover IPv4, IPv6, scheme-less, `localhost:port`, unspecified v4
and v6, a routable address, a non-default scheme and port, port defaulting, and
the fallback branch. This is the first test module in this crate.

Scope of the ast-grep change: `flag-hardcoded-endpoints-rs` already exempts
`**/tests/**`, but that path is unreachable for a *binary* crate -- an
integration test cannot call a private fn, so a URL-parsing unit test has to
live in an inline `mod tests`, where literal endpoints are the fixture rather
than a hardcoded default. The rule now exempts that module and nothing else.
Confirmed in both directions: the test module scans clean, and a planted
`"http://127.0.0.1:8080"` inside `build_client` in the same file still raises
the error. Narrowed, not disabled.

Verified:

  sg scan (changed file)                                          0 errors
  cargo clippy --workspace --all-targets --no-deps -- -D warnings exit 0
  cargo test -p pcai-ollama-rs --bins                             9 passed

Not verified: no Ollama daemon was running on this host, so this proves the
endpoint is derived correctly and `build_client` no longer returns Err -- not
that a live connection succeeds.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Mu7jB5ysKe4DN5ovjVtX1t

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
@David-Martel

Copy link
Copy Markdown
Owner

Superseded by #85, merged as 510cbd27, which takes this lockfile verbatim.

This PR could not merge on its own. ollama-rs 0.3.4 → 0.3.6 deprecated Ollama::new in favour of the builder, and the workspace builds with -D warnings, so the deprecation was a hard error:

error: use of deprecated associated function `ollama_rs::Ollama::new`
  --> pcai_ollama_rs\src\main.rs:382:16
  = note: `-D deprecated` implied by `-D warnings`

That is the gate working as designed. A lockfile-only bump reached a real API change and the build refused it — which is exactly why workspace-wide clippy matters rather than checking pcai_inference alone.

#85 migrates build_client to the builder, and — after review flagged an IPv6 bug in the surrounding code — fixes three endpoint-parsing defects that predated this branch, with nine new unit tests.

Worth recording what this PR demonstrated: it was the first grouped PR produced by the grouping added in #71, and it did the job — one PR with 17 minor/patch updates instead of 17 separate ones, resolved against a single current lockfile and gated once.

Branch note: #85 branched from main and took this lockfile via git checkout <branch> -- Cargo.lock rather than checking out this branch directly, because another writer had uncommitted work in Tools/ in that tree and this branch predates those files. Their work was left untouched.

@dependabot @github

dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/cargo/Native/pcai_core/cargo-pcai-core-380642b2b0 branch September 8, 2026 16:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant