Repository navigation
Bump syn from 3.0.3 to 3.0.6 in /rust in the rust-dependencies group across 1 directory - #1462
Merged
bgentry merged 1 commit intoOct 8, 2026
Conversation
dependabot
Bot
force-pushed
the
dependabot/cargo/rust/rust-dependencies-01d3730bfa
branch
3 times, most recently
from
October 7, 2026 05:03
1e45877 to
c9aab0a
Compare
Bumps the rust-dependencies group with 1 update in the /rust directory: [syn](https://github.com/dtolnay/syn). Updates `syn` from 3.0.3 to 3.0.6 - [Release notes](https://github.com/dtolnay/syn/releases) - [Commits](dtolnay/syn@3.0.3...3.0.6) --- updated-dependencies: - dependency-name: syn dependency-version: 3.0.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: rust-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/cargo/rust/rust-dependencies-01d3730bfa
branch
from
October 7, 2026 17:26
c9aab0a to
8e6bfa8
Compare
bgentry
approved these changes
Oct 8, 2026
bgentry
left a comment
Contributor
There was a problem hiding this comment.
🤖 Codex review: Approved after dependency security and compatibility review.
Upgrade
syn:3.0.3→3.0.6- Reviewed head:
8e6bfa8e2116418c310100a0c585d990e1156b4b - Prospective merge also validated with master
81c96bfe8167ab90a5009dad6098195b9857cb62; its only staged dependency delta is the same Cargo.lock update. The intervening master changes affect two Rust test files, so affected checks were rerun on that combined tree.
Security review
- Independently calculated both crate SHA256s and matched Cargo.lock, crates.io metadata and registry index; releases are non-yanked. New artifact:
8593e8e72159ed2257d083c7a454a85cbf854f37a0966d8d483aff8c8a3ebcee. - All 101 published payload files per version match canonical upstream release-tag source byte-for-byte. Release commits have GitHub-valid signatures; publisher/sole owner remains dtolnay. License, MSRV, features and normal dependencies are unchanged; no trusted-publishing attestation is claimed.
- Reviewed all changed shipped source and tests: foreign
safe fnparsing, literal lexer error spans and interpolated lifetime parsing. No new build hook, native code, unsafe delta, network/process/credential/filesystem behavior or generated runtime artifact. - River's lockfile replaces only syn 3.0.3 with 3.0.6 and retargets seven existing macro/derive edges. Syn 2.0.119 is unchanged; no new graph package, source override or same-version checksum rewrite.
- No syn advisory was found in GitHub's Rust advisory metadata or RustSec. Release notes identify bug fixes; this is not classified as a confirmed security update.
Compatibility verification
- On the exact reviewed head:
make lint/rust,make test/rustwith a dedicated PostgreSQL 18.6 database and all features, andmake check/rust/dependencies— passed. Tests include macro derive/trybuild, unit/doc, SQLite and PostgreSQL integration coverage. An initial database URL omitted the user and SQLx selectedanonymous; rerunning with the explicit local user resolved that environment error. - On the prospective merge with current master:
make lint/rust,make test/rust,make doc/rust,make check/rust/dependencies,make check/rust/package, andmake check/rust/semveragainst publishedrust/v0.3.0— passed. This includes PostgreSQL-only/SQLite-only lint builds, documentation/examples, publishable archive verification and API compatibility. - Local Rust toolchain is 1.98.1. The reviewed head's hosted Rust 1.95/1.96/1.97, nightly documentation and PostgreSQL 14–18 checks are successful; those toolchain/database matrices were not recreated locally. No Go source/test changes require another Go suite for this PR.
Residual risk
- No blocking issue identified. Ordinary unknown third-party vulnerability/account-compromise risk remains; compatibility results apply to the reviewed head and tested master combination. Exact-version/integrity evidence can be reused across a rebase only when those artifact identities remain unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the rust-dependencies group with 1 update in the /rust directory: syn.
Updates
synfrom 3.0.3 to 3.0.6Release notes
Sourced from syn's releases.
Commits
559cab5Release 3.0.69088cadMerge pull request #2082 from dtolnay/lifetimevar3eb43bbFix parsing interpolated lifetime at statement start7b2f6f9Add regression test for issue 2081d55bcd2Update test suite to nightly-2026-09-138e37bcaResolve non_kebab_case_bins warning4dfd88fUpdate test suite to nightly-2026-09-06e0ad92dRelease 3.0.574e7d75Merge pull request #2080 from sunshowers/lit-str-span4c264f3In LitStr::parse_with, report correct span for lex errors