Skip to content

Bump thiserror from 2.0.20 to 2.0.21 in /src-tauri - #793

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/cargo/src-tauri/master/thiserror-2.0.21
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/cargo/src-tauri/master/thiserror-2.0.21

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown
Contributor

Bumps thiserror from 2.0.20 to 2.0.21.

Release notes

Sourced from thiserror's releases.

2.0.21

  • Fix parsing of generic unit variants in display expressions (#459)
Commits
  • b1827ee Release 2.0.21
  • 58037b5 Merge pull request #459 from dtolnay/turbofish
  • f82a0cf Keep track of nested turbofish depth
  • 72ea492 Raise required compiler to Rust 1.77
  • 72eea0d Resolve io_other_error clippy lint in tests
  • 07f09a2 Raise required compiler to Rust 1.74
  • 2715388 Update ui test suite to nightly-2026-09-22
  • 5a306c7 Update ui test suite to nightly-2026-09-05
  • ef9383b Update ui test suite to nightly-2026-08-22
  • 8336b84 Update ui tests for version 2.0.20
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [thiserror](https://github.com/dtolnay/thiserror) from 2.0.20 to 2.0.21.
- [Release notes](https://github.com/dtolnay/thiserror/releases)
- [Commits](dtolnay/thiserror@2.0.20...2.0.21)

---
updated-dependencies:
- dependency-name: thiserror
  dependency-version: 2.0.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 27, 2026
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits.
Credits must be used to enable repository wide code reviews.

@lamemustafa

Copy link
Copy Markdown
Member

Independent review (local, Sonnet) of 9962ae3

Scope: the whole diff against base 3e2c2cc, which is src-tauri/Cargo.lock only (thiserror and thiserror-impl 2.0.20 → 2.0.21).

Verdict: P2: it cannot merge as pushed. It changes a pinned file without a reseal and leaves the Rust license inventory stale. CI fails on both, so neither failure is silent.

P2-1: src-tauri/Cargo.lock is pinned, and the surface still holds the base's hash.

  • The pin is ac2dd868…, the base's hash; the head's bytes hash to 69d494b3….
  • "Tally portable core" fails at tests::real_tree_has_complete_migration_and_report_surface_coverage (bridge-tally-compatibility/src/lib_tests.rs:936) with surface_file_changed.
  • Fix: scripts/reseal.sh on the branch, in a slot.

P2-2: THIRD_PARTY_LICENSES_RUST.txt still lists thiserror 2.0.20.

  • "Rust format" fails at the inventory step with Rust third-party inventory drift (missing: thiserror 2.0.21, thiserror-impl 2.0.21; …).
  • Fix: regenerate with scripts/generate-rust-licenses.mjs.
  • The same drift message also lists as stale about twenty crates unrelated to this bump (base64 0.21.7, proptest 1.11.0, rand 0.9.5, …). I have not established why. It may mean the committed inventory is already behind master, which the regeneration would show.

The upgrade itself: no impact found.

Noted, not introduced here: tools/Cargo.lock pins thiserror 2.0.19, and the inventory checker covers src-tauri only.


Generated by Claude Code

@lamemustafa

Copy link
Copy Markdown
Member

Superseded by #805, which carries this bump together with the other Dependabot updates, the regenerated notices and one compatibility reseal.

@dependabot @github

dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/cargo/src-tauri/master/thiserror-2.0.21 branch September 27, 2026 16:13
lamemustafa added a commit that referenced this pull request Sep 27, 2026
…hree frontend dev tools, with one reseal (#805)

Bumps tauri to 2.11.6, which carries the fix for GHSA-w28w-mhc8-qvjv (IPC channel payloads and large invoke responses are bound to the webview that created them), plus thiserror 2.0.21, toml 1.1.6 (tauri-utils now resolves to the already-locked toml 0.9.12), lucide-react 1.48, and the frontend dev tools @tauri-apps/cli 2.11.5, jsdom 30.1.1 and vite 8.3.1. The third-party notices are regenerated with the pinned tools (version lines only), and the compatibility surface re-pins Cargo.lock, package.json and pnpm-lock.yaml (schema 2). No workflow, dialog, egress or source file changes.

Replaces the Dependabot PRs #793, #794, #795, #797 and #798.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@lamemustafa lamemustafa added this to the 0.4.0 milestone Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant