From 0c8fd182bf7f77dc601a45e68ed7882b48227fdf Mon Sep 17 00:00:00 2001 From: Brandur Date: Tue, 6 Oct 2026 12:35:27 -0500 Subject: [PATCH] Assorted dependency updates MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit A Codex pass to consolidate our various dependency updates so we don't have to merge so many separate PRs and undoubtedly rebase them all on top of each other as we do. - Rust: `base64` 0\.23.1, `syn` 3\.0.3, `rand` 0\.10.3, `thiserror` 2\.0.21. - Actions: checkout, setup-go, setup-node → v7; cache → v6, across all workflows and composite actions. --- .github/actions/setup-js/action.yaml | 2 +- .github/workflows/ci.yaml | 28 ++++++++++++++-------------- .github/workflows/conformance.yaml | 6 +++--- .github/workflows/js.yaml | 14 +++++++------- .github/workflows/rust.yaml | 16 ++++++++-------- rust/Cargo.lock | 26 ++++++++++++++++---------- rust/Cargo.toml | 4 ++-- 7 files changed, 51 insertions(+), 45 deletions(-) diff --git a/.github/actions/setup-js/action.yaml b/.github/actions/setup-js/action.yaml index 48f96b4f1..f48956aba 100644 --- a/.github/actions/setup-js/action.yaml +++ b/.github/actions/setup-js/action.yaml @@ -16,7 +16,7 @@ runs: with: package_json_file: js/package.json - - uses: actions/setup-node@v6 + - uses: actions/setup-node@v7 with: cache: pnpm cache-dependency-path: js/pnpm-lock.yaml diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 5361bfbcb..499b13c35 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -47,10 +47,10 @@ jobs: - 5432:5432 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Setup Go ${{ matrix.go-version }} - uses: actions/setup-go@v6 + uses: actions/setup-go@v7 with: go-version: ${{ matrix.go-version }} @@ -118,10 +118,10 @@ jobs: - 5432:5432 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Setup Go ${{ matrix.go-version }} - uses: actions/setup-go@v6 + uses: actions/setup-go@v7 with: go-version: ${{ matrix.go-version }} @@ -157,10 +157,10 @@ jobs: timeout-minutes: 5 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: Setup Go ${{ matrix.go-version }} - uses: actions/setup-go@v6 + uses: actions/setup-go@v7 with: go-version: ${{ matrix.go-version }} @@ -225,7 +225,7 @@ jobs: # adds the bundled client tools to PATH for all subsequent steps. $env:PGBIN | Out-File -FilePath $env:GITHUB_PATH -Encoding utf8 -Append - - uses: actions/setup-go@v6 + - uses: actions/setup-go@v7 with: go-version: "stable" check-latest: true @@ -246,7 +246,7 @@ jobs: shell: pwsh - name: Checkout - uses: actions/checkout@v6 + uses: actions/checkout@v7 - name: export RIVER_CMD_DIR run: | @@ -386,13 +386,13 @@ jobs: pull-requests: read steps: - - uses: actions/setup-go@v6 + - uses: actions/setup-go@v7 with: go-version: "stable" check-latest: true - name: Checkout - uses: actions/checkout@v6 + uses: actions/checkout@v7 - name: Lint uses: golangci/golangci-lint-action@v9 @@ -416,9 +416,9 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v6 + uses: actions/checkout@v7 - - uses: actions/setup-go@v6 + - uses: actions/setup-go@v7 with: go-version: "1.27" @@ -444,13 +444,13 @@ jobs: runs-on: ubuntu-latest steps: - - uses: actions/setup-go@v6 + - uses: actions/setup-go@v7 with: go-version: "stable" check-latest: true - name: Checkout - uses: actions/checkout@v6 + uses: actions/checkout@v7 - name: Check all go/toolchain directives match run: CHECK=true make update-mod-go diff --git a/.github/workflows/conformance.yaml b/.github/workflows/conformance.yaml index 8a4dde8c4..04899d01f 100644 --- a/.github/workflows/conformance.yaml +++ b/.github/workflows/conformance.yaml @@ -45,11 +45,11 @@ jobs: timeout-minutes: 15 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 with: persist-credentials: false - - uses: actions/setup-go@v6 + - uses: actions/setup-go@v7 with: go-version-file: go.work @@ -57,7 +57,7 @@ jobs: id: rust - name: Cache Rust dependencies and build artifacts - uses: actions/cache@v5 + uses: actions/cache@v6 with: path: | ~/.cargo/registry/index diff --git a/.github/workflows/js.yaml b/.github/workflows/js.yaml index 40d1bca74..8ee1ea607 100644 --- a/.github/workflows/js.yaml +++ b/.github/workflows/js.yaml @@ -45,7 +45,7 @@ jobs: timeout-minutes: 20 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 with: persist-credentials: false @@ -74,7 +74,7 @@ jobs: timeout-minutes: 10 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 with: persist-credentials: false @@ -116,7 +116,7 @@ jobs: RIVER_REQUIRE_POSTGRES: "1" steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 with: persist-credentials: false @@ -152,7 +152,7 @@ jobs: DATABASE_URL: postgres://postgres:postgres@localhost:5432/river_test?sslmode=disable steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 with: persist-credentials: false @@ -176,7 +176,7 @@ jobs: node-version: ["26.0.0", ""] steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 with: persist-credentials: false @@ -186,7 +186,7 @@ jobs: # Some unit tests read fixtures generated from River's Go # implementation. - - uses: actions/setup-go@v6 + - uses: actions/setup-go@v7 with: go-version-file: go.work @@ -227,7 +227,7 @@ jobs: TEST_DATABASE_URL: postgres://postgres:postgres@localhost:5432/river_test?sslmode=disable steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 with: persist-credentials: false diff --git a/.github/workflows/rust.yaml b/.github/workflows/rust.yaml index d524012a3..76a3343e8 100644 --- a/.github/workflows/rust.yaml +++ b/.github/workflows/rust.yaml @@ -37,7 +37,7 @@ jobs: timeout-minutes: 20 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 with: fetch-depth: 0 - uses: dtolnay/rust-toolchain@stable @@ -45,7 +45,7 @@ jobs: with: components: clippy,rustfmt - name: Cache Rust dependencies and build artifacts - uses: actions/cache@v5 + uses: actions/cache@v6 with: path: | ~/.cargo/registry/index @@ -95,13 +95,13 @@ jobs: rust-version: ["1.95", "1.96", "1.97"] steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: dtolnay/rust-toolchain@master id: rust with: toolchain: ${{ matrix.rust-version }} - name: Cache Rust dependencies and build artifacts - uses: actions/cache@v5 + uses: actions/cache@v6 with: path: | ~/.cargo/registry/index @@ -111,7 +111,7 @@ jobs: key: rust-v1-${{ runner.os }}-${{ runner.arch }}-${{ github.job }}-${{ steps.rust.outputs.cachekey }}-${{ hashFiles('rust/**/Cargo.toml', 'rust/Cargo.lock') }} restore-keys: rust-v1-${{ runner.os }}-${{ runner.arch }}-${{ github.job }}-${{ steps.rust.outputs.cachekey }}- # Tests read fixtures generated from River's Go implementation. - - uses: actions/setup-go@v6 + - uses: actions/setup-go@v7 with: go-version-file: go.work - name: Check every target and feature @@ -143,11 +143,11 @@ jobs: - 5432:5432 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - uses: dtolnay/rust-toolchain@stable id: rust - name: Cache Rust dependencies and build artifacts - uses: actions/cache@v5 + uses: actions/cache@v6 with: path: | ~/.cargo/registry/index @@ -157,7 +157,7 @@ jobs: key: rust-v1-${{ runner.os }}-${{ runner.arch }}-${{ github.job }}-${{ steps.rust.outputs.cachekey }}-${{ hashFiles('rust/**/Cargo.toml', 'rust/Cargo.lock') }} restore-keys: rust-v1-${{ runner.os }}-${{ runner.arch }}-${{ github.job }}-${{ steps.rust.outputs.cachekey }}- # Tests read fixtures generated from River's Go implementation. - - uses: actions/setup-go@v6 + - uses: actions/setup-go@v7 with: go-version-file: go.work - name: Create test database diff --git a/rust/Cargo.lock b/rust/Cargo.lock index c61ec9e09..7a7552d86 100644 --- a/rust/Cargo.lock +++ b/rust/Cargo.lock @@ -55,6 +55,12 @@ version = "0.22.1" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "72b3254f16251a8381aa12e40e3c4d2f0199f8c6508fbecb9d91f575e0fbb8c6" +[[package]] +name = "base64" +version = "0.23.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ac07cdecf99051d9a5238b80f35af32cdeba5b336e55d957b318b50137e18da5" + [[package]] name = "bitflags" version = "2.13.1" @@ -888,9 +894,9 @@ checksum = "f8dcc9c7d52a811697d2151c701e0d08956f92b0e24136cf4cf27b57a6a0d9bf" [[package]] name = "rand" -version = "0.10.2" +version = "0.10.3" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "c7f5fa3a058cd35567ef9bfa5e75732bee0f9e4c55fa90477bef2dfcdbc4be80" +checksum = "65c9fb96cbc91e3478eaae79a69fcd3f1ae4ad052e471fe6732fff548984b4af" dependencies = [ "chacha20", "getrandom 0.4.3", @@ -932,7 +938,7 @@ version = "0.50.0-alpha.1" dependencies = [ "anyhow", "async-trait", - "base64", + "base64 0.23.1", "chrono", "chrono-tz", "futures-util", @@ -970,7 +976,7 @@ dependencies = [ "quote", "riverqueue", "serde", - "syn 2.0.119", + "syn 3.0.3", "trybuild", ] @@ -1213,7 +1219,7 @@ version = "0.9.0" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "05b44e85bf579a8eeb4ceaa77a3a523baf2bf0e9bac7e40f405d537b5d2d5ccb" dependencies = [ - "base64", + "base64 0.22.1", "bytes", "cfg-if", "chrono", @@ -1316,7 +1322,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "87a2bdd6e83f6b3ea525ca9fee568030508b58355a43d0b2c1674d5f79dcd65e" dependencies = [ "atoi", - "base64", + "base64 0.22.1", "bitflags", "byteorder", "chrono", @@ -1443,18 +1449,18 @@ dependencies = [ [[package]] name = "thiserror" -version = "2.0.20" +version = "2.0.21" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "ec86235f5fcc2a73650310756d2ac5b138a5780bbbdfae3eeccec992c435ba4f" +checksum = "09e52cb86a36cede5cb101bf8908837b3e4c6e5e59fe7fd85c23fb56200d189e" dependencies = [ "thiserror-impl", ] [[package]] name = "thiserror-impl" -version = "2.0.20" +version = "2.0.21" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "bc04cd3e1236dd4a98afca4569f2deb3f120e5422a4023be2cb683f8486292af" +checksum = "fe5197923287db20a58125f0bc85c062f7f2c892de97b18c356f9efb14b28524" dependencies = [ "proc-macro2", "quote", diff --git a/rust/Cargo.toml b/rust/Cargo.toml index f0a30f705..c94326258 100644 --- a/rust/Cargo.toml +++ b/rust/Cargo.toml @@ -19,7 +19,7 @@ version = "0.50.0-alpha.1" [workspace.dependencies] async-trait = "0.1.92" -base64 = "0.22.1" +base64 = "0.23.1" chrono = { version = "0.4.45", features = ["serde"] } futures-util = { version = "0.3.34", default-features = false, features = ["std"] } proc-macro2 = "1.0.107" @@ -29,7 +29,7 @@ serde = { version = "1.0.229", features = ["derive"] } serde_json = { version = "1.0.151", features = ["raw_value"] } sha2 = "0.11.0" sqlx = { version = "0.9.0", default-features = false, features = ["runtime-tokio"] } -syn = { version = "2.0", features = ["full"] } +syn = { version = "3.0", features = ["full"] } thiserror = "2.0.20" tokio = { version = "1.53.1", features = ["macros", "rt", "sync", "time"] } tokio-util = { version = "0.7.19", features = ["rt"] }