Skip to content

build(deps): bump smallvec from 1.15.2 to 1.16.2 - #597

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/smallvec-1.16.2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/smallvec-1.16.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Bumps smallvec from 1.15.2 to 1.16.2.

Release notes

Sourced from smallvec's releases.

v1.16.2

What's Changed

New Contributors

Full Changelog: servo/rust-smallvec@v1.16.1...v1.16.2

v1.16.1

What's Changed

New Contributors

Full Changelog: servo/rust-smallvec@v1.16.0...v1.16.1

v1.16.0

What's Changed

New Contributors

Full Changelog: servo/rust-smallvec@v1.15.2...v1.16.0

Commits
  • ccf5fc7 chore: bump version (#617)
  • af207cc Merge pull request #608 from Rayan-and-beyond/fix/manual-readme-warning-606
  • cda4b73 Merge pull request #594 from astral-sh/charlie/codex-fix-may-dangle
  • d0556cb Merge pull request #596 from astral-sh/charlie/codex-v1-compact
  • f73914c Flatten retain tests into the unit test module
  • 954d599 Move retain tests into the unit test module
  • 8d93633 Remove added retain benchmark harness
  • 88c6bfa Limit compaction optimization to retain
  • b9ef17d Fix element ownership tracking with may_dangle
  • 42029c2 Compact retained elements directly in retain and dedup_by
  • Additional commits viewable in compare view

@dependabot
dependabot Bot requested a review from eKisNonos as a code owner October 3, 2026 11:23
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 3, 2026
@senseix21

Copy link
Copy Markdown
Collaborator

Review: safe to merge — the red check is infrastructure, not this change

The verus failure is unrelated to smallvec. Pulled the job log:

curl: (22) The requested URL returned error: 500
##[error]Process completed with exit code 22

That is a 500 from a download endpoint during setup, at 26s into the run. It is not a verification failure and there is no Rust diagnostic in the log. verus is green on the four sibling Dependabot PRs cut from the same base (#596, #598, #599, #600), which rules out a base-branch regression. Re-run the job.

The change itself is as low-risk as a bump gets:

  • Lock-only (+2 / -2). Cargo.toml keeps the version = "1.15" caret requirement, so 1.16.2 already satisfies it — this PR only records what resolution would pick anyway.
  • No new transitive dependencies, so no TCB surface change and nothing for supply-chain to re-assess.
  • smallvec = { version = "1.15", default-features = false } — the no_std posture is unchanged, which is the thing that actually matters for us.
  • Minor version within 1.x, and smallvec's API here is a container we use structurally, not an interface we implement against.

One note for the record: this crate's default-features = false is load-bearing — enabling std or union later would be the real review, not a patch bump. Nothing in this PR touches that.

Re-run verus, then merge.

Bumps [smallvec](https://github.com/servo/rust-smallvec) from 1.15.2 to 1.16.2.
- [Release notes](https://github.com/servo/rust-smallvec/releases)
- [Commits](servo/rust-smallvec@v1.15.2...v1.16.2)

---
updated-dependencies:
- dependency-name: smallvec
  dependency-version: 1.16.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/cargo/smallvec-1.16.2 branch from fd1d340 to af83120 Compare October 9, 2026 05:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant