Conversation
Run `cargo update` at the repo root. Eight transitive lockfile entries moved; no Cargo.toml requirement changed. hyper-util 0.1.20 -> 0.1.21 rustls-platform-verifier 0.7.0 -> 0.7.1 rustls-platform-verifier-android 0.1.1 -> 0.2.0 smallvec 1.16.1 -> 1.16.2 thiserror 2.0.20 -> 2.0.21 thiserror-impl 2.0.20 -> 2.0.21 zerocopy 0.8.57 -> 0.8.58 zerocopy-derive 0.8.57 -> 0.8.58 The four Cargo.lock files under tools/oci-runtime-spike/ are standalone probe crates that nothing in the Makefile, tools/ or CI builds; they are deliberately left untouched. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Routine dependency refresh:
cargo updateat the repo root on 2026-09-25. Eight transitive lockfile entries moved. No source changes were needed.Crates that moved (all transitive)
Side effects visible in the diff: hyper-util 0.1.21 now depends on
base64 0.23.1(already in the tree) instead ofbase64 0.22.1, and addshttparse(already in the tree). Every other hunk is athiserror 2.0.20 -> 2.0.21reference or a checksum.rustls-platform-verifier-androidis an Android-only artifact (the Kotlin verifier shim pulled in byrustls-platform-verifier); it is not compiled on any awman target.What did not move, and why
cfg(unix)block) were checked against the crates.io index on 2026-09-25: the latest stable release of every one is already inside its existing caret range (e.g. clap 4.6.7, tokio 1.53.1, reqwest 0.13.5, axum 0.8.9, ratatui 0.30.2, rusqlite 0.40.2, toml 1.1.6, thiserror 2.0.21).cargo update --verbosereports two crates "behind latest" that cannot move:matchit 0.8.4(axum 0.8.9 requires=0.8.4) andgeneric-array 0.14.7(crypto-common 0.1.7 requires=0.14.7, reached via sha2 0.10 → termwiz → ratatui-termwiz → ratatui). Exact pins held by parent crates; out of scope.cargo updatecannot move them and forcing them would break the build. Left alone deliberately.tools/oci-runtime-spike/**/Cargo.lockleft untouched on purpose. The four lockfiles underfixture/,sqlite-resolution/probe/,strict-embed/probe/andstrict-embed/full-probe/belong to standalone throwaway probe crates for the OCI-runtime spike. The rootCargo.tomlhas no[workspace], and nothing in theMakefile,tools/*.sh,scripts/or.github/workflows/builds them (grepped). They exist to pin the specific versions the spike was run against, so bumping them would be churn with no benefit. This was a deliberate choice, not an oversight.Validation
Run locally with Rust 1.94.0 (the CI toolchain) on linux/aarch64:
make architecture-lintcargo fmt --checkcargo clippy --all-targets -- -D warningsmake test-fastcargo build --releaseawman 0.12.0)Environment caveat for
make test-fast: the preparation VM sat on a nearly full host disk and silently zeroed large freshly written object files on the first attempts (ext4 reported block-device write errors). The passing run above was done after clearingtarget/, withCARGO_BUILD_JOBS=3,CARGO_INCREMENTAL=0andCARGO_PROFILE_DEV_DEBUG=0/CARGO_PROFILE_TEST_DEBUG=0to keep artifacts small, and with the ext4 error counter confirmed unchanged for the whole run. Debuginfo level does not affect test semantics; CI runs the default profile and is the authoritative check.make test-fullwas not run locally: Docker is not available in the environment this PR was prepared in. The "Full tests with Docker (Linux)" CI job covers it.Reviewer notes
Cargo.lockonly; review is mostly confirming the table above matches the hunks.🤖 Generated with Claude Code