Skip to content

chore(deps): bump git-internal from 0.4.1 to 0.8.5 - #31

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/git-internal-0.8.5
Open

chore(deps): bump git-internal from 0.4.1 to 0.8.5#31
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/git-internal-0.8.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 29, 2026

Copy link
Copy Markdown
Contributor

Bumps git-internal from 0.4.1 to 0.8.5.

Release notes

Sourced from git-internal's releases.

v0.8.5

[0.8.5] - 2026-07-29

Fixed

  • Delta decoder now returns GitError for malformed streams instead of panicking. Previously, crafted delta input could trigger a shift overflow on overlong size varints, attempt to allocate an impractically large output buffer, or silently produce wrong-length output when the instruction stream produced more bytes than the declared result size. The decoder now:
    • Rejects varints that would overflow a usize with GitError::InvalidData.
    • Reserves the output buffer incrementally and caps output at the declared result size, returning InvalidData on overrun.
    • Rejects negative-copy instructions that read before the base buffer.
  • Pack delta-rebuild path propagates decoder errors. Pack previously called a fallible delta helper directly in the thread pool and could lose failures. rebuild_delta_with_hash now reuses the hardened delta_decode function and returns GitError, and failures are surfaced through SharedParams to the pack decoder's main loop so decode stops cleanly instead of hanging on a waitlist.

Changed

  • Dependency upgrades:
    • bstr 1.12 → 1.13
    • futures 0.3.32 → 0.3.33
    • path-absolutize 3.1 → 4.0
    • uuid 1.23 → 1.24
    • tokio 1.52 → 1.53

New Contributors

Full Changelog: libra-tools/git-internal@v0.8.4...v0.8,5

v0.8.4

Patch release fixing a flaky SHA-256 pack-encoding panic that could crash downstream tools (e.g. libra bundle create) under async runtimes.

Fixed

• Pack trailer no longer panics with Invalid byte length: got 32, expected 20 on SHA-256 repositories. PackEncoder finalizes its running checksum on whichever async worker thread happens to run the task, but ObjectHash::from_bytes re-read the thread-local HashKind at finalize time. On threads where set_hash_kind was never called (default SHA-1), finalizing a SHA-256 pack aborted with a panic — surfacing as intermittent, scheduling-dependent failures such as pack encoder task failed in async runtimes that migrate tasks across worker threads. Both the delta path (encode/mod.rs) and the non-delta parallel path (encode/parallel.rs) now infer the hash kind from the checksum byte length, and propagate a GitError instead of unwrapping.

Added

• ObjectHash::from_bytes_infer_kind — constructs an ObjectHash from raw bytes by inferring the hash kind from the byte length (20 → SHA-1, 32 → SHA-256) instead of

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [git-internal](https://github.com/libra-tools/git-internal) from 0.4.1 to 0.8.5.
- [Release notes](https://github.com/libra-tools/git-internal/releases)
- [Changelog](https://github.com/libra-tools/git-internal/blob/main/CHANGELOG.md)
- [Commits](https://github.com/libra-tools/git-internal/commits/v0.8.5)

---
updated-dependencies:
- dependency-name: git-internal
  dependency-version: 0.8.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Jul 29, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: caa736890a

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread Cargo.toml

[dependencies]
git-internal = "0.4.1"
git-internal = "0.8.5"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Keep git-internal bincode support before bumping

This bump selects git-internal 0.8.5, whose locked dependency list no longer includes bincode, while src/manager/store.rs still persists git_internal::Tree and Commit via bincode::encode_to_vec/decode_from_slice. Because bincode v2 requires the external types themselves to implement Encode/Decode, normal builds that include the store code will fail to type-check until the store is migrated to a supported serialization path (for example serde/rkyv adapters) or the dependency is kept on a bincode-compatible version.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants