Skip to content

deps: consolidate dependabot bumps - #4370

Merged
ben-dz merged 3 commits into
mainfrom
bdz/deps-consolidate-2026-09
Sep 25, 2026
Merged

ben-dz merged 3 commits into
mainfrom
bdz/deps-consolidate-2026-09

Conversation

@ben-dz

@ben-dz ben-dz commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Consolidates the open Dependabot PRs that can land without moving Solana.

This changes the DoubleZero Ledger program binaries. borsh 1.8.1, bytemuck, thiserror and serde are in the build tree of serviceability and record, and nothing checks those programs' checksums. The next ledger program release will ship these versions, so it should be a deliberate decision. The L1 programs under solana/ are untouched, and solana/Cargo.lock is unchanged.

No solana-*, agave-*, spl-* or ruint version moves in any lockfile. The solana-* minor bumps in the rust-minor-patch group are held back because solana-compute-budget-interface 3.1 pulls solana-instruction 4.0 into the serviceability build. ruint stays at 1.16 because 1.17 and later use edition 2024, which the SBF toolchain can't parse. testcontainers-go stays at 0.40 because 0.43 moves to the moby API types and breaks e2e. clickhouse-go 2.47+ and goose 3.27.3 require it, so they stay back as well. solana-go is held with the other Solana crates.

Two bumps need code changes. ureq 3 needs a small change in fork-accounts, and tint 1.2 deprecates NewHandler, so its call sites move to NewTextHandler, which it already wraps. ureq and ureq-proto are pinned in the lockfile to avoid pulling in base64 0.23.

Closes #3887
Closes #4117
Closes #4139
Closes #4210
Closes #4258
Closes #4292
Closes #4293
Closes #4359

Still open after this merges: the Solana 4.x PRs (#4134, #4135, #4136, #4137, #4140, #4141), #4263 (it fails the SBF build and would move the solana/ checksums), #4138 (base64 is pinned in Cargo.toml), #4262, and whatever is left of #4250, #4290 and #4348.

Testing Verification

The account compatibility check passes against devnet, testnet and mainnet. Rust lint and tests, the fixture builds and the revdist Python tests pass. The Go packages that can run without root pass. SBF builds and e2e are left to CI.

Holds every solana-*, agave-*, spl-* and ruint version at main's, and
holds testcontainers-go (plus clickhouse-go and goose, which require it)
and solana-go back.
@ben-dz
ben-dz marked this pull request as ready for review September 25, 2026 20:24
@ben-dz
ben-dz requested a review from a team September 25, 2026 20:24
@ben-dz
ben-dz merged commit c681ff7 into main Sep 25, 2026
44 checks passed
@ben-dz
ben-dz deleted the bdz/deps-consolidate-2026-09 branch September 25, 2026 23:16
ben-dz added a commit that referenced this pull request Sep 28, 2026
Bumps testcontainers-go and its clickhouse and redpanda modules from
0.40 to 0.44, and clickhouse-go from 2.46 to 2.48. These were held back
in #4370: testcontainers 0.43 moved its request types from
`github.com/docker/docker` to `github.com/moby/moby/api`, and
clickhouse-go 2.47+ requires testcontainers 0.43.

Only the types handed to testcontainers change: `ConfigModifier`,
`HostConfigModifier`, `EndpointSettingsModifier`, `Resources`, network
IPAM, and wait/mapped ports, which are now plain strings. Direct Docker
client calls (`dockerClient.ContainerList`, filters, inspect) stay on
`github.com/docker/docker`, so go.mod now carries both. Moving those
calls to `github.com/moby/moby/client` is a larger rewrite, and it can
be done separately.

The moby types use `netip` for IPs and subnets. The CYOA IPs for the
client and ip-verifier and the network subnets are now parsed before
use, and a bad value returns an error instead of being passed through as
a string.

goose stays at 3.27.0. 3.27.3 requires go 1.25.7, and the test and
release images build on `golang:1.25.0`/`1.25.5`, which set
`GOTOOLCHAIN=local` and can't fetch a newer toolchain. Rust and Solana
dependencies are untouched.

## Testing Verification

All six e2e shards and the three shard-e2e jobs pass in CI, and so do
the container tests (`go-container-test`) and `go-test`. Locally, `go
vet` is clean under every build tag in the repo (none, `qa`, `e2e`,
`e2e,stress`, `container_tests`), and golangci-lint reports no issues.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants