Skip to content

Dependency Dashboard #8

Description

@renovate

This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.
View this repository on the Mend.io Web Portal.

Repository Problems

These problems occurred while renovating this repository. View logs.

  • ⚠️ WARN: Detected empty commit - aborting git push

Deprecations / Replacements

Warning

The following dependencies are either deprecated or have replacements available.

Datasource Package Replacement PR?
npm @types/handlebars Unavailable

Other Branches

The following updates are pending. To force the creation of a PR, click on a checkbox below.

  • chore(deps): update rust crate google-cloud-auth to v1.17.0

Open

The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.

PR Closed (Blocked)

The following updates are blocked by an existing closed PR. To recreate the PR, click on a checkbox below.

Detected Dependencies

cargo (26)
Cargo.toml (98)
  • anyhow 1.0.102
  • async-recursion 1.1.1
  • async-stream 0.3
  • async-trait 0.1.89
  • aws-config 1.8.13
  • aws-sdk-bedrockruntime 1.129.0
  • aws-credential-types 1.2.14
  • aws-smithy-types 1.4.3
  • aws-smithy-runtime-api 1.11.3
  • aws-smithy-async 1.2.11
  • aws-smithy-runtime 1.10
  • base64 0.23.0
  • bstr 1.12.1
  • bytes 1.11.1
  • chrono 0.4.44
  • clap 4.6.0
  • clap_complete 4.6.0
  • colored 3.1.1
  • console 0.16.3
  • convert_case 0.12.0
  • derive_more 2.1.1
  • enable-ansi-support 0.3.1
  • derive_setters 0.1.9
  • dirs 7.0.0
  • dissimilar 1.0.9
  • dotenvy 0.15.7
  • futures 0.3.32
  • gh-workflow 0.8.1 → [Updates: 0.9.0]
  • glob 0.3.3
  • grep-searcher 0.1.14
  • grep-regex 0.1.13
  • handlebars 6.4.0
  • html2md =0.2.15 → [Updates: =0.2.17]
  • http 1.2.0
  • ignore 0.4.23
  • is_ci 1.2.0
  • indexmap 2.13.0
  • infer 0.22.0
  • insta 1.47.2
  • lazy_static 1.4.0
  • machineid-rs 1.2.4
  • mockito 1.7.2
  • nom 8.0.0
  • nu-ansi-term 0.50.1
  • posthog-rs 0.27.0
  • pretty_assertions 1.4.1
  • proc-macro2 1.0
  • quote 1.0
  • rustyline 18.0.0
  • regex 1.12.3
  • reqwest 0.12.23 → [Updates: 0.13.0]
  • rustls 0.23
  • include_dir 0.7.4
  • schemars 1.2
  • serde 1.0.217
  • serde_json 1.0.143
  • serde_yml 0.0.13
  • sha2 0.11
  • similar 3.0
  • strip-ansi-escapes 0.2.1
  • strum 0.28.0
  • strum_macros 0.28.0
  • syn 3.0.0
  • sysinfo 0.38.3 → [Updates: 0.39.0]
  • tempfile 3.27.0
  • termimad 0.34.1 → [Updates: 0.35.0]
  • tiny_http 0.12.0
  • syntect 5
  • thiserror 2.0.18
  • toml_edit 0.25
  • tokio 1.51.0
  • tokio-stream 0.1.18
  • tokio-util 0.7
  • tonic 0.14.5
  • tracing 0.1.44
  • tracing-appender 0.2.3
  • tracing-subscriber 0.3.23
  • url 2.5.8
  • terminal_size 0.4
  • unicode-width 0.2
  • backon 1.5.2
  • eserde 0.1.7
  • uuid 1.23.0
  • whoami 2.1.0
  • fnv_rs 0.4.3
  • merge 0.2
  • hex 0.4.3
  • rmcp 1.0.0 → [Updates: 2.0.0]
  • open 5.3.2
  • nucleo 0.5.0
  • nucleo-picker 0.12.0
  • gray_matter 0.3.2
  • num-format 0.4
  • humantime 2.1.0
  • dashmap 7.0.0-rc2
  • async-openai 0.41.0 → [Updates: 0.42.0]
  • gix 0.88
  • google-cloud-auth 1.8.0 → [Updates: 1.8.0]
crates/forge_api/Cargo.toml
crates/forge_app/Cargo.toml (1)
  • fake 5.1.0
crates/forge_ci/Cargo.toml
crates/forge_config/Cargo.toml (2)
  • config 0.15
  • fake 5.1.0
crates/forge_display/Cargo.toml (2)
  • terminal-colorsaurus 1.0.3
  • two-face 0.5.1
crates/forge_domain/Cargo.toml (5)
  • eserde 0.1.7
  • derive-getters 0.5.0
  • lazy_static 1.5.0
  • fake 5.1.0
  • fake 5.1.0
crates/forge_embed/Cargo.toml
crates/forge_eventsource_stream/Cargo.toml (8)
  • futures-core 0.3
  • nom 8.0
  • pin-project-lite 0.2.8
  • futures 0.3
  • http 1.0
  • reqwest 0.11 → [Updates: 0.13]
  • tokio 1.0
  • url 2.2
crates/forge_eventsource/Cargo.toml (12)
  • reqwest 0.12.0 → [Updates: 0.13.0]
  • futures-core 0.3.5
  • pin-project-lite 0.2.8
  • nom 8.0.0
  • mime 0.3.16
  • futures-timer 3.0.2
  • thiserror 2.0.0
  • futures 0.3.5
  • tokio 1
  • futures-retry 0.6
  • pin-utils 0.1
  • rocket 0.5.0
crates/forge_fs/Cargo.toml (4)
  • infer 0.22.0
  • thiserror 2.0
  • tempfile 3.27.0
  • pretty_assertions 1.4.0
crates/forge_infra/Cargo.toml (9)
  • diesel 2.3.7
  • libsqlite3-sys 0.38.0
  • diesel_migrations 2.2.0
  • chrono 0.4
  • cacache 13.1.0
  • oauth2 5.0
  • serde_urlencoded 0.7.1
  • serial_test 4.0
  • fake 5.1.0
crates/forge_json_repair/Cargo.toml (1)
  • serde_json5 0.2.1
crates/forge_main/Cargo.toml (7)
  • libc 0.2
  • update-informer 1.2.0
  • terminal_size 0.4
  • serial_test 4.0
  • fake 5.1.0
  • windows-sys 0.61
  • arboard 3.4
crates/forge_markdown_stream/Cargo.toml (7)
  • streamdown-parser 0.1.4
  • streamdown-core 0.1.4
  • streamdown-ansi 0.1.4
  • streamdown-render 0.1.4
  • unicode-width 0.2
  • unicode-segmentation 1.12
  • terminal-colorsaurus 1.0.3
crates/forge_repo/Cargo.toml (9)
  • chrono 0.4
  • diesel 2.3.7
  • diesel_migrations 2.2.0
  • prost 0.14.3
  • prost-types 0.14.3
  • tonic-prost 0.14.5
  • serial_test 4.0
  • fake 5.1.0
  • tonic-prost-build 0.14.5
crates/forge_select/Cargo.toml (1)
  • crossterm 0.29.0
crates/forge_services/Cargo.toml (4)
  • lazy_static 1.5.0
  • oauth2 5.0
  • serde_urlencoded 0.7.1
  • fake 5.1.0
crates/forge_snaps/Cargo.toml
crates/forge_spinner/Cargo.toml (2)
  • indicatif 0.18.4
  • rand 0.10.0
crates/forge_stream/Cargo.toml
crates/forge_template/Cargo.toml (1)
  • html-escape 0.2.13
crates/forge_test_kit/Cargo.toml
crates/forge_tool_macros/Cargo.toml
crates/forge_tracker/Cargo.toml (1)
  • posthog-rs 0.27.0
crates/forge_walker/Cargo.toml
devcontainer (1)
.devcontainer/devcontainer.json (5)
  • mcr.microsoft.com/devcontainers/rust 2-1-bullseye
  • ghcr.io/devcontainers/features/node 2
  • ghcr.io/devcontainers/features/github-cli 1
  • ghcr.io/devcontainers/features/git 1
  • ghcr.io/devcontainers/features/common-utils 2
github-actions (7)
.github/workflows/autofix.yml (4)
  • actions/checkout v6 → [Updates: v7]
  • arduino/setup-protoc v3
  • actions-rust-lang/setup-rust-toolchain v1 → [Updates: v2]
  • rust nightly
.github/workflows/bounty.yml (2)
  • actions/checkout v6 → [Updates: v7]
  • actions/checkout v6 → [Updates: v7]
.github/workflows/ci.yml (20)
  • actions/checkout v6 → [Updates: v7]
  • arduino/setup-protoc v3
  • actions-rust-lang/setup-rust-toolchain v1 → [Updates: v2]
  • actions/checkout v6 → [Updates: v7]
  • arduino/setup-protoc v3
  • actions-rust-lang/setup-rust-toolchain v1 → [Updates: v2]
  • actions/checkout v6 → [Updates: v7]
  • release-drafter/release-drafter v7
  • actions/checkout v6 → [Updates: v7]
  • actions/checkout v6 → [Updates: v7]
  • arduino/setup-protoc v3
  • taiki-e/setup-cross-toolchain-action v1
  • ClementTsang/cargo-action v0.0.7
  • xresloader/upload-to-github-release v1
  • actions/checkout v6 → [Updates: v7]
  • arduino/setup-protoc v3
  • taiki-e/setup-cross-toolchain-action v1
  • ClementTsang/cargo-action v0.0.7
  • rust stable
  • rust stable
.github/workflows/labels.yml (1)
  • actions/checkout v6 → [Updates: v7]
.github/workflows/release-drafter.yml (2)
  • release-drafter/release-drafter v7
  • release-drafter/release-drafter v7
.github/workflows/release.yml (7)
  • actions/checkout v6 → [Updates: v7]
  • arduino/setup-protoc v3
  • taiki-e/setup-cross-toolchain-action v1
  • ClementTsang/cargo-action v0.0.7
  • xresloader/upload-to-github-release v1
  • actions/checkout v6 → [Updates: v7]
  • actions/checkout v6 → [Updates: v7]
.github/workflows/stale.yml (1)
  • actions/stale v10 → [Updates: v11]
npm (1)
package.json (19)
  • @ai-sdk/google-vertex ^5.0.0
  • @types/handlebars ^4.0.40
  • @types/node ^24.10.1
  • @types/tmp ^0.2.6
  • @types/yargs ^17.0.35
  • ai ^7.0.0
  • chalk ^6.0.0
  • csv-parse ^7.0.0
  • handlebars ^4.7.9
  • p-limit ^7.2.0
  • pino ^10.1.0
  • pino-pretty ^13.1.2
  • strip-ansi ^7.1.2
  • tmp ^0.2.5
  • tsx ^4.20.6
  • typescript ^7.0.0
  • yaml ^2.8.3
  • yargs ^18.0.0
  • zod ^4.0.0
rust-toolchain (1)
rust-toolchain.toml (1)
  • rust 1.99

  • Check this box to trigger a request for Renovate to run again on this repository

Activity

github-actions commented on Sep 20, 2025

@github-actions

Action required: Issue inactive for 30 days.
Status update or closure in 7 days.

added
state: inactiveNo current action needed/possible; issue fixed, out of scope, or superseded.
on Sep 20, 2025
removed
state: inactiveNo current action needed/possible; issue fixed, out of scope, or superseded.
on Sep 23, 2025

github-actions commented on Oct 23, 2025

@github-actions

Action required: Issue inactive for 30 days.
Status update or closure in 7 days.

added
state: inactiveNo current action needed/possible; issue fixed, out of scope, or superseded.
and removed
state: inactiveNo current action needed/possible; issue fixed, out of scope, or superseded.
on Oct 23, 2025

github-actions commented on Nov 27, 2025

@github-actions

Action required: Issue inactive for 30 days.
Status update or closure in 7 days.

added
state: inactiveNo current action needed/possible; issue fixed, out of scope, or superseded.
on Nov 27, 2025

github-actions commented on Dec 4, 2025

@github-actions

Issue closed after 7 days of inactivity.

removed
state: inactiveNo current action needed/possible; issue fixed, out of scope, or superseded.
on Apr 10, 2026

amitksingh1490 commented on Sep 16, 2026

@amitksingh1490
Contributor

Dependency Dashboard #8 — finite review, 2026-09-16

Source: #8
Board: ab0c3981-5c8f-4a07-be71-7e032ba5baf1 / 1b6f2cd0-9d57-41d5-be3f-5c19893e2d91

Scope and disposition

Frozen inventory: 2026-09-16 04:54 UTC, all 15 open bot dependency PRs. All 31 open PRs and paginated closed PR history were retrieved; no duplicate implementation PR is needed. Main inspected: 6ed5d37. This is a finite REVIEW of existing updates, not permanent completion of recurring maintenance. Dashboard remains open. Board disposition: Blocked / Needs Input; none promoted to PR Ready.

No merges, approvals, closures, workflow approvals, bot rebase/reset commands, source changes, commits, pushes, installations or builds. No other board issue started; #3860 remains the other active work. Source worktree not needed/created; future authorized source work belongs in /home/forge/worktrees/dependencies. No other worker artifacts touched. Initial disk availability was about 1.1 GiB, not enough for safe dependency builds.

Complete inventory and latest-head findings

B = Build and Test; P = Performance: zsh rprompt; L = Lint Fix. These are existing remote results, NOT locally rerun tests. All fifteen have successful Release Drafter, which is not readiness evidence. Skipped release builds are not passes. No ACTION_REQUIRED checks/runs found in fetched head checks, actions runs, or PR status rollups. Actual CI failures need fixing, not workflow-execution approval.

PR Head Actual update / classification Remote B/P/L Evidence / next action
#3537 b4e548d checkout v6→v7; automation major, overlaps #3873 fail/pass/fail 5 generated-workflow tests fail OutdatedWorkflow; nightly double_must_use errors. Update Rust generator and YAML together only with authorization. Checkout v7 changes unsafe fork checkout behavior for pull_request_target/workflow_run; do not bypass its safeguard.
#3558 36c27bb handlebars 6.4.1→6.4.4; isolated patch pass/pass/fail String-safety job fails double_must_use in forge_domain. Existing approval refers to older 08903af, not latest head. Validate template ordering/partials; release notes reverse default preserve_json_order in 6.4.4. Upstream benchmark quick-xml removal alone does not establish a Forge production vulnerability.
#3629 24f5997 cmov 0.5.3→0.5.4; lowest-risk patch candidate pass/pass/pass BEHIND main, July CI, automatic rebases disabled after 30 days. Diff is version/checksum only; head lockfile reflects older base, so do not replace current main lockfile wholesale. Needs refreshed integration tests/lints and relevant CLI validation before readiness.
#3694 fafdd6d serde_with/macros 3.18→3.21 (+bs58); SECURITY priority pass/pass/fail GHSA-7gcf-g7xr-8hxj medium, affected >=2.3,<3.21; current main 3.18. String-safety double_must_use blocks. Google cloud RPC/WKT transitively consume it; exploitable call-path reachability not proven.
#3744 08b8027 gh-workflow 0.8.1→0.9; pre-1.0 breaking migration fail/fail/fail E0063: PullRequestTarget lacks paths/paths_ignore in release_drafter.rs. Also present in #3874; not safe to assume grouped PR fixes it. Requires generator compatibility fix and generated-workflow tests, with automation-change permission.
#3762 cd101e1 quinn-proto 0.11.14→0.11.16 (+rand_pcg); SECURITY priority pass/pass/fail GHSA-4w2j-m93h-cj5j high, unbounded out-of-order reassembly memory exhaustion, patched >=0.11.15. Main 0.11.14 is affected by version. String-safety double_must_use blocks. reqwest→quinn→quinn-proto lock graph; runtime HTTP/3 feature/reachability not established.
#3775 8433284 stale v10→v11; automation major, overlaps #3873 fail/pass/fail Generated stale workflow OutdatedWorkflow; double_must_use lint. Upstream notes ESM migration and brace-expansion security fixes; review runner/runtime and preserve stale/closure policy. Do not execute stale workflow as a test.
#3778 2a8ce30 rmcp manifest v3, lock 3.4.0; breaking migration fail/fail/fail RawContent removed, ContentBlock.raw removed, start_authorization now one config argument; ClientInfo deprecated in 3.4 (warnings denied). Needs content conversion and OAuth registration/login migration, credential and stdio/HTTP MCP tests. Current 3.4 lock is NEWER than #3874's 3.3; group does not supersede this.
#3831 6a09575 posthog manifest 0.25.0, lock 0.25.2; pre-1.0 migration candidate pass/pass/pass 4 files include extra fd.rs bool simplification and transitive lock re-resolution. Renovate PR Edited/Blocked, with two autofix commits. No human review. #3874 has newer 0.25.4 but fails and is not a validated replacement. Verify telemetry opt-out, flush/shutdown and error propagation.
#3835 e6c74dc google-vertex lock 5.0.46→5.0.63; JS patch candidate pass/pass/pass 2 files: package-lock plus same unrelated fd.rs simplification. PR Edited/Blocked; dashboard advertises 5.0.84 but actual head is .63. Node >=22 and provider/provider-utils transitive changes. Rust CI does not establish TS evaluation compatibility or Vertex authentication.
#3836 9c0cf79 ai lock 7.0.57→7.0.79; JS patch candidate pass/pass/pass 2 files: package-lock plus fd.rs simplification. PR Edited/Blocked; dashboard advertises 7.0.102 but actual head is .79. Overlaps #3835's provider-utils graph, not a duplicate top-level update. Need Node >=22 install/typecheck and semantic-search evaluation smoke tests.
#3837 abda691 async-trait 0.1.91→0.1.92; isolated patch pass/pass/fail Unlike other old macro failures, remaining double_must_use is async_recursion in forge_services/policy.rs. Do not assume async-trait alone fixes lint baseline.
#3838 dcfcc3f thiserror/impl 2.0.19→2.0.20; isolated patch pass/pass/fail String-safety double_must_use in forge_domain. 1.x copy is unchanged; validate derives and error handling on refreshed base.
#3873 1287aee checkout 7 + stale 11 + setup-rust-toolchain 2 + autofix action SHA; grouped automation fail/pass/fail 6 generated-workflow tests fail OutdatedWorkflow. Clippy warnings denied under toolchain v2; inspect warning policy migration, do not weaken gates. Contains #3537/#3775 version changes but also two extra automation changes. Choose group vs individual route; no closures performed.
#3874 556f407 10 Rust major/pre-1.0 updates; defer broad group fail/fail/fail rmcp API compile failures confirmed. Includes gh-workflow 0.9 and posthog 0.25.4 overlap plus convert_case 0.12, dirs 7, sysinfo 0.39.6, termimad 0.35.4, nucleo-picker 0.12.2, async-openai 0.42, gix 0.87.1. No code migrations. Broad lock churn; later compiler errors may be masked.

Duplicate / supersession decisions

Exact validation and gaps

Performed (read-only network/API plus local parsing):

  1. gh api repos/tailcallhq/forgecode/issues/8; gh api --paginate 'repos/tailcallhq/forgecode/issues/8/comments?per_page=100'; same for timeline. Dashboard body differs from actual edited PR versions; actual heads take precedence.
  2. gh api --paginate 'repos/tailcallhq/forgecode/pulls?state=open&per_page=100' and state=closed; all pages persisted. This gh lacks --slurp; initial rejected calls were retried using jq -s add or JSONDecoder page folding.
  3. For EACH scoped N: GET pulls/N; paginated files, reviews, review comments, commits and issues/N/comments; full diff via gh api -H 'Accept: application/vnd.github.diff' repos/tailcallhq/forgecode/pulls/N. Captured head SHA identifies the reviewed version. No latest-head human approval found: the only approval, chore(deps): update rust crate handlebars to v6.4.4 #3558, targets an older commit.
  4. For EACH head SHA: paginated commits/SHA/check-runs, commits/SHA/status, actions/runs?head_sha=SHA; gh pr view N --repo tailcallhq/forgecode --json number,state,headRefOid,mergeStateStatus,reviewDecision,statusCheckRollup. All 15 inspected; no ACTION_REQUIRED. Query jobs for latest ci and autofix.ci run on each head. gh run view ID --log-failed returned empty output despite exit 0; this is NOT passing evidence. Retrieved actual failed job logs with gh api repos/tailcallhq/forgecode/actions/jobs/ID/logs instead.
  5. gh api repos/tailcallhq/forgecode/commits/main and SHA-pinned raw main/head contents. Python tomllib.loads parsed every changed Cargo.lock/Cargo.toml and tracker manifest; json.loads parsed both changed package-lock files. All parsed. Version-set deltas are in static-validation.txt. Parsing is not Cargo resolution or compatibility testing. The build(deps): bump cmov from 0.5.3 to 0.5.4 #3629 current-main comparison includes base-age differences, NOT additional changes in its PR diff.
  6. gh api advisories/GHSA-7gcf-g7xr-8hxj; paginated gh api 'advisories?ecosystem=rust&affects=quinn-proto&per_page=100'. Verified patched version ranges; not a full cargo audit or exploitability assessment. Earlier Quinn panic advisory GHSA-6xvm-j4wr-6v98 was already fixed by current 0.11.14.
  7. Read AGENTS.md and debug-cli skill. Semantic search unavailable (revoked/replaced Forge token); literal search used successfully. GitHub API access works, no GitHub login required for this review.

NOT RUN: cargo check/test/insta/clippy/build; npm ci/typecheck/tests; debug-cli --help/-p against any PR build; provider-authenticated Vertex or MCP OAuth flows; platform-specific tests. No relevant PR binary was built. Disk constraint and no authorization to alter automation prevent safe implementation/verification now. No tests deleted or snapshots accepted. Green existing CI on #3629/#3831/#3835/#3836 is useful but insufficient for project PR Ready acceptance.

For future authorized work, one PR at a time: isolated durable worktree; budget disk before compilation; crate-specific tests and lints; debug build then --help before relevant noninteractive -p smoke checks; preserve conversation originals. For #3744/#3537/#3775/#3873, ask whether to correct implementation/generator (recommended), not update failing tests to suppress drift. For #3778, test content handling, OAuth flows and token storage on its exact chosen version. #3874 additionally needs paths/home-dir platform behavior, sysinfo startup regression, terminal rendering/picker behavior, async-openai DTO and gix compatibility checks.

Needed decisions / recommended order

  1. Prioritize existing build(deps): Bump quinn-proto from 0.11.14 to 0.11.16 #3762 then build(deps): Bump serde_with from 3.18.0 to 3.21.0 #3694 security updates; refresh/retest sequentially on current main once adequate disk or a suitable runner is provided. Do not fix unrelated macro lint failures independently in every PR; establish whether they persist on rebased main first.
  2. Select individual PR route versus grouped chore(deps): bump the actions group across 1 directory with 4 updates #3873/build(deps): Bump the major group across 1 directory with 10 updates #3874. Recommend individual migrations; do not close groups or change bot automation without explicit direction.
  3. Authorize narrowly scoped workflow-generator/automation migration work if desired, including the toolchain v2 warnings-policy review. No workflow execution approval has been requested by these 15 heads at this inventory.
  4. Accept or remove the small unrelated fd.rs autofix delta in the three edited candidates; choose whether to keep current frozen versions or permit a bot refresh. Never silently discard bot/manual commits.
  5. Provide disk capacity/build runner for exact-head verification. Vertex credentials are needed only for live evaluation smoke tests; do not disclose tokens in evidence. No fresh duplicate PR should be created for these existing updates.

Evidence layout: inventory.json, inventory-time.txt, dashboard*.json, open-prs.json, closed-prs.json, main*.json/toml/lock/yml, security advisory JSON, static-validation.txt; each PR directory contains pr/files/reviews/comments/commits/checks/status/runs/rollup JSON, full diff.patch, jobs JSON, failed job logs and ANSI-stripped clean.txt, and parsed head manifests/lockfiles.

Co-Authored-By: ForgeCode noreply@forgecode.dev

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions