Skip to content

Bump syn from 3.0.3 to 3.0.6 in /rust in the rust-dependencies group across 1 directory - #1462

Merged
bgentry merged 1 commit into
masterfrom
dependabot/cargo/rust/rust-dependencies-01d3730bfa
Oct 8, 2026
Merged

bgentry merged 1 commit into
masterfrom
dependabot/cargo/rust/rust-dependencies-01d3730bfa

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the rust-dependencies group with 1 update in the /rust directory: syn.

Updates syn from 3.0.3 to 3.0.6

Release notes

Sourced from syn's releases.

3.0.6

  • Fix parsing interpolated lifetime at statement start (#2082)

3.0.5

3.0.4

  • Allow safe fn in impl Parse for ForeignItemFn (#2078)
Commits
  • 559cab5 Release 3.0.6
  • 9088cad Merge pull request #2082 from dtolnay/lifetimevar
  • 3eb43bb Fix parsing interpolated lifetime at statement start
  • 7b2f6f9 Add regression test for issue 2081
  • d55bcd2 Update test suite to nightly-2026-09-13
  • 8e37bca Resolve non_kebab_case_bins warning
  • 4dfd88f Update test suite to nightly-2026-09-06
  • e0ad92d Release 3.0.5
  • 74e7d75 Merge pull request #2080 from sunshowers/lit-str-span
  • 4c264f3 In LitStr::parse_with, report correct span for lex errors
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 6, 2026
@dependabot
dependabot Bot force-pushed the dependabot/cargo/rust/rust-dependencies-01d3730bfa branch 3 times, most recently from 1e45877 to c9aab0a Compare October 7, 2026 05:03
Bumps the rust-dependencies group with 1 update in the /rust directory: [syn](https://github.com/dtolnay/syn).


Updates `syn` from 3.0.3 to 3.0.6
- [Release notes](https://github.com/dtolnay/syn/releases)
- [Commits](dtolnay/syn@3.0.3...3.0.6)

---
updated-dependencies:
- dependency-name: syn
  dependency-version: 3.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: rust-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/cargo/rust/rust-dependencies-01d3730bfa branch from c9aab0a to 8e6bfa8 Compare October 7, 2026 17:26

@bgentry bgentry left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Codex review: Approved after dependency security and compatibility review.

Upgrade

  • syn: 3.0.3 → 3.0.6
  • Reviewed head: 8e6bfa8e2116418c310100a0c585d990e1156b4b
  • Prospective merge also validated with master 81c96bfe8167ab90a5009dad6098195b9857cb62; its only staged dependency delta is the same Cargo.lock update. The intervening master changes affect two Rust test files, so affected checks were rerun on that combined tree.

Security review

  • Independently calculated both crate SHA256s and matched Cargo.lock, crates.io metadata and registry index; releases are non-yanked. New artifact: 8593e8e72159ed2257d083c7a454a85cbf854f37a0966d8d483aff8c8a3ebcee.
  • All 101 published payload files per version match canonical upstream release-tag source byte-for-byte. Release commits have GitHub-valid signatures; publisher/sole owner remains dtolnay. License, MSRV, features and normal dependencies are unchanged; no trusted-publishing attestation is claimed.
  • Reviewed all changed shipped source and tests: foreign safe fn parsing, literal lexer error spans and interpolated lifetime parsing. No new build hook, native code, unsafe delta, network/process/credential/filesystem behavior or generated runtime artifact.
  • River's lockfile replaces only syn 3.0.3 with 3.0.6 and retargets seven existing macro/derive edges. Syn 2.0.119 is unchanged; no new graph package, source override or same-version checksum rewrite.
  • No syn advisory was found in GitHub's Rust advisory metadata or RustSec. Release notes identify bug fixes; this is not classified as a confirmed security update.

Compatibility verification

  • On the exact reviewed head: make lint/rust, make test/rust with a dedicated PostgreSQL 18.6 database and all features, and make check/rust/dependencies — passed. Tests include macro derive/trybuild, unit/doc, SQLite and PostgreSQL integration coverage. An initial database URL omitted the user and SQLx selected anonymous; rerunning with the explicit local user resolved that environment error.
  • On the prospective merge with current master: make lint/rust, make test/rust, make doc/rust, make check/rust/dependencies, make check/rust/package, and make check/rust/semver against published rust/v0.3.0 — passed. This includes PostgreSQL-only/SQLite-only lint builds, documentation/examples, publishable archive verification and API compatibility.
  • Local Rust toolchain is 1.98.1. The reviewed head's hosted Rust 1.95/1.96/1.97, nightly documentation and PostgreSQL 14–18 checks are successful; those toolchain/database matrices were not recreated locally. No Go source/test changes require another Go suite for this PR.

Residual risk

  • No blocking issue identified. Ordinary unknown third-party vulnerability/account-compromise risk remains; compatibility results apply to the reviewed head and tested master combination. Exact-version/integrity evidence can be reused across a rebase only when those artifact identities remain unchanged.

@bgentry
bgentry merged commit 0be1dd9 into master Oct 8, 2026
24 checks passed
@bgentry
bgentry deleted the dependabot/cargo/rust/rust-dependencies-01d3730bfa branch October 8, 2026 01:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant