Skip to content

build(deps): bump smallvec from 1.15.2 to 1.16.2 - #597

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/smallvec-1.16.2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/smallvec-1.16.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor

Bumps smallvec from 1.15.2 to 1.16.2.

Release notes

Sourced from smallvec's releases.

v1.16.2

What's Changed

New Contributors

Full Changelog: servo/rust-smallvec@v1.16.1...v1.16.2

v1.16.1

What's Changed

New Contributors

Full Changelog: servo/rust-smallvec@v1.16.0...v1.16.1

v1.16.0

What's Changed

New Contributors

Full Changelog: servo/rust-smallvec@v1.15.2...v1.16.0

Commits
  • ccf5fc7 chore: bump version (#617)
  • af207cc Merge pull request #608 from Rayan-and-beyond/fix/manual-readme-warning-606
  • cda4b73 Merge pull request #594 from astral-sh/charlie/codex-fix-may-dangle
  • d0556cb Merge pull request #596 from astral-sh/charlie/codex-v1-compact
  • f73914c Flatten retain tests into the unit test module
  • 954d599 Move retain tests into the unit test module
  • 8d93633 Remove added retain benchmark harness
  • 88c6bfa Limit compaction optimization to retain
  • b9ef17d Fix element ownership tracking with may_dangle
  • 42029c2 Compact retained elements directly in retain and dedup_by
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [smallvec](https://github.com/servo/rust-smallvec) from 1.15.2 to 1.16.2.
- [Release notes](https://github.com/servo/rust-smallvec/releases)
- [Commits](servo/rust-smallvec@v1.15.2...v1.16.2)

---
updated-dependencies:
- dependency-name: smallvec
  dependency-version: 1.16.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from eKisNonos as a code owner October 3, 2026 11:23
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 3, 2026
@senseix21

Copy link
Copy Markdown
Collaborator

Review: safe to merge — the red check is infrastructure, not this change

The verus failure is unrelated to smallvec. Pulled the job log:

curl: (22) The requested URL returned error: 500
##[error]Process completed with exit code 22

That is a 500 from a download endpoint during setup, at 26s into the run. It is not a verification failure and there is no Rust diagnostic in the log. verus is green on the four sibling Dependabot PRs cut from the same base (#596, #598, #599, #600), which rules out a base-branch regression. Re-run the job.

The change itself is as low-risk as a bump gets:

  • Lock-only (+2 / -2). Cargo.toml keeps the version = "1.15" caret requirement, so 1.16.2 already satisfies it — this PR only records what resolution would pick anyway.
  • No new transitive dependencies, so no TCB surface change and nothing for supply-chain to re-assess.
  • smallvec = { version = "1.15", default-features = false } — the no_std posture is unchanged, which is the thing that actually matters for us.
  • Minor version within 1.x, and smallvec's API here is a container we use structurally, not an interface we implement against.

One note for the record: this crate's default-features = false is load-bearing — enabling std or union later would be the real review, not a patch bump. Nothing in this PR touches that.

Re-run verus, then merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant