Skip to content

Bump lru from 0.12.5 to 0.16.3 in /native - #167

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/native/lru-0.16.3
Closed

Bump lru from 0.12.5 to 0.16.3 in /native#167
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/native/lru-0.16.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Apr 28, 2026

Copy link
Copy Markdown

Bumps lru from 0.12.5 to 0.16.3.

Changelog

Sourced from lru's changelog.

v0.16.3 - 2026-01-07

  • Fix Stacked Borrows violation in IterMut.

v0.16.2 - 2025-10-14

  • Upgrade hashbrown dependency to 0.16.0.

v0.16.1 - 2025-09-08

  • Fix Clone for unbounded cache.

v0.16.0 - 2025-07-02

  • Implement Clone for caches with custom hashers.

v0.15.0 - 2025-06-26

  • Return bool from promote and demote to indicate whether key was found.

v0.14.0 - 2025-04-12

  • Use NonZeroUsize::MAX instead of unwrap(), and update MSRV to 1.70.0.

v0.13.0 - 2025-01-27

  • Add peek_mru and pop_mru methods, upgrade dependency on hashbrown to 0.15.2, and update MSRV to 1.65.0.
Commits
  • af233e5 Merge pull request #225 from jeromefroe/jerome/prepare-0-16-3-release
  • cf56f9a Prepare 0.16.3 release
  • 62be24c Merge pull request #224 from paolobarbolini/iter-mut-stacked-borrows-violation
  • 25669e7 Add regression test for IterMut stacked borrows violation
  • b9bca34 Fix stacked borrows violation in IterMut::next and IterMut::next_back
  • c1f843d Merge pull request #223 from jeromefroe/jerome/prepare-0-16-2-release
  • fc4f309 Prepare 0.16.2 release
  • e91ea2b Merge pull request #222 from torokati44/hashbrown-0.16
  • 90d05fe Update hashbrown to 0.16
  • c699209 Merge pull request #220 from jeromefroe/jerome/prepare-0-16-1-release
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [lru](https://github.com/jeromefroe/lru-rs) from 0.12.5 to 0.16.3.
- [Changelog](https://github.com/jeromefroe/lru-rs/blob/master/CHANGELOG.md)
- [Commits](jeromefroe/lru-rs@0.12.5...0.16.3)

---
updated-dependencies:
- dependency-name: lru
  dependency-version: 0.16.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Apr 28, 2026
schenksj added a commit that referenced this pull request Jun 19, 2026
* chore(deps): consolidate Dependabot updates

Triage and apply the open Dependabot dependency PRs in a single change.

Maven (pom.xml):
- jackson-databind 2.15.2 -> 2.22.0 (#178)
- maven-surefire-plugin 3.1.2 -> 3.5.6 (#177)
- exec-maven-plugin 3.1.0 -> 3.6.3 (#175)
- test-dependencies group (#173): junit 5.10.0 -> 6.0.3,
  s3 2.21.29 -> 2.43.0, azure-storage-blob 12.25.0 -> 12.33.3,
  azure-identity 1.12.0 -> 1.18.2, azure-core 1.48.0 -> 1.57.1,
  testcontainers 1.19.0 -> 2.0.5, google-cloud-storage 2.29.1 -> 2.67.0,
  google-cloud-nio 0.127.12 -> 0.131.0, mockito 5.7.0 -> 5.23.0,
  iceberg 1.7.1 -> 1.10.1, and maven-{compiler,resources,jar,source,
  javadoc,gpg}-plugin + central-publishing-maven-plugin bumps.

Cargo (native):
- futures 0.3.31 -> 0.3.32 (#164)
- tokio 1.45 -> 1.50 (#166)
- lru 0.12 -> 0.16 (#167)
- sha2 0.10 -> 0.11 (#163)
- thiserror 1 -> 2 (#170)
- libc / moka lockfile bumps (#169, #165)

GitHub Actions:
- actions/checkout v4 -> v6 (#162)

Held back (incompatible, not applied):
- scala-library 2.13.12 -> 3.8.3 (#173 sub-update): Scala 2->3 major;
  s3mock_2.13 requires Scala 2.13. Kept at 2.13.12.
- arrow-array / arrow-buffer 57 -> 58 (#168, #172): arrow, arrow-schema
  and parquet remain at 57 (pinned transitively by delta-kernel 0.19 and
  the quickwit fork). Mixing arrow 57/58 fails to compile.
- object_store 0.12 -> 0.13 (#171): breaking API changes and coupling
  with delta-kernel 0.19 / quickwit which pin 0.12.

Verified: `cargo check` clean; `mvn test-compile` clean;
PythonParityTest + BooleanFieldTest pass under junit 6 / surefire 3.5.6.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(deps): hold junit at 5.12.2 — 6.0.3 requires Java 17

JUnit 6.0.x raised its baseline to Java 17 (junit-jupiter-api class files
are bytecode 61). This project targets Java 11, and CI compiles with
JDK 11, so the test sources failed with "class file has wrong version
61.0, should be 55.0". It only passed locally because the dev machine
runs JDK 19.

Bump to 5.12.2 instead — the latest Java 8/11-compatible 5.x line (still
an upgrade from the original 5.10.0). Verified compiling and running
tests under JDK 11.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* test(txlog): serialize global-cache tests to fix parallel race

CI surfaced flaky failures in txlog::cache tests (e.g.
test_clear_all_caches_removes_all_entries, test_global_cache_stats).
Root cause is test cross-contamination, not a production bug: several
tests exercise the process-wide cache registry / global manifest cache,
and `clear_all_caches()` wipes that shared state. Under cargo's parallel
runner one test's clear races with another's get/put/stats.

Reproduced deterministically on the unmodified code at
`--test-threads=16`: 13/40 runs failed across test_global_cache_stats,
test_get_or_create_cache_reuse, test_global_manifest_cache and the
clear_all_caches tests. Serializing them on a shared mutex: 0/40.

The moka 0.12.13 -> 0.12.15 patch in this PR only shifted scheduling
enough to make CI hit a pre-existing latent race; production code is
sound (get_or_create_cache uses double-checked locking, the cache is
best-effort with TTL/LRU eviction so a flush racing a read is at worst a
miss, and the sole production caller is an explicit invalidate-all JNI
API).

Add a poison-tolerant mutex (lock_global_state) and guard the six tests
that touch global cache state. Local-instance tests still run in
parallel.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@schenksj

schenksj commented Jul 5, 2026

Copy link
Copy Markdown
Collaborator

Consolidated into #184

@schenksj schenksj closed this Jul 5, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jul 5, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/cargo/native/lru-0.16.3 branch July 5, 2026 02:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant