Skip to content

build(deps): bump borsh from 0.10.4 to 1.6.0 in /logic#107

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/cargo/logic/borsh-1.6.0
Open

build(deps): bump borsh from 0.10.4 to 1.6.0 in /logic#107
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/cargo/logic/borsh-1.6.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Feb 16, 2026

Bumps borsh from 0.10.4 to 1.6.0.

Release notes

Sourced from borsh's releases.

borsh-derive-v1.6.0

No release notes provided.

borsh-v1.6.0

Added

  • Use core::net instead of std::net; bumped MSRV to 1.77 (#356)

Fixed

  • Avoid variant name shadowing in BorshSchema derive (#361)

Other

  • Upgrade the CI base image to use ubuntu-24.04 instead of the deprecated ubuntu-20.04 (#359)
  • Include license files in published crates (#354)
  • add automatically_derived attribute to derive macros (#341)

borsh-derive-v1.5.7

No release notes provided.

borsh-v1.5.7

Other

  • replace Result::unwrap err msg with proc_macro_crate::crate_name tag (#351)

borsh-derive-v1.5.6

No release notes provided.

borsh-v1.5.6

Fixed

  • add indexmap support (#346)

Other

  • add mention of indexmap feature (#349)

borsh-derive-v1.5.5

No release notes provided.

borsh-v1.5.5

Other

  • bump hashbrown to 0.15 (#333)
  • fix typo in private module name (#332)

borsh-derive-v1.5.4

No release notes provided.

... (truncated)

Changelog

Sourced from borsh's changelog.

1.6.0 - 2025-11-25

Added

  • Use core::net instead of std::net; bumped MSRV to 1.77 (#356)

Fixed

  • Avoid variant name shadowing in BorshSchema derive (#361)

Other

  • Upgrade the CI base image to use ubuntu-24.04 instead of the deprecated ubuntu-20.04 (#359)
  • Include license files in published crates (#354)
  • add automatically_derived attribute to derive macros (#341)

1.5.7 - 2025-03-25

Other

  • replace Result::unwrap err msg with proc_macro_crate::crate_name tag (#351)

1.5.6 - 2025-03-18

Fixed

  • add indexmap support (#346)

Other

  • add mention of indexmap feature (#349)

1.5.5 - 2025-01-18

Other

  • bump hashbrown to 0.15 (#333)
  • fix typo in private module name (#332)

1.5.4 - 2025-01-13

Other

  • make doc examples testable in ci (#326)
  • add more CODEOWNERS (#327)

1.5.3 - 2024-11-13

Fixed

... (truncated)

Commits
  • 819fa55 chore: release v1.6.0 (#360)
  • 9010ec4 fix: Avoid variant name shadowing in BorshSchema derive (#361)
  • f5b3b4a feat: Use core::net instead of std::net; bumped MSRV to 1.77 (#356)
  • 5d8516b ci: Upgrade the CI base image to use ubuntu-24.04 instead of the deprecated u...
  • f1b75a6 chore: add automatically_derived attribute to derive macros (#341)
  • 54fc720 chore: Include license files in published crates (#354)
  • abb9582 chore: release v1.5.7 (#352)
  • 299be9c replace Result::unwrap err msg with proc_macro_crate::crate_name tag (#351)
  • b9b7f09 chore: release v1.5.6 (#348)
  • f215994 doc: add mention of indexmap feature (#349)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note

Medium Risk
This is a major-version serialization dependency upgrade (borsh), which can introduce compile-time or runtime/compatibility issues in encoded data formats even though the change is mostly dependency/lockfile churn.

Overview
Bumps the logic crate’s borsh dependency from the 0.10.x line to 1.6.0 in Cargo.toml.

Regenerates Cargo.lock to reflect the new borsh resolution, removing older transitive entries (e.g., ahash/older hashbrown) and normalizing downstream calimero-* dependencies to reference borsh without a pinned version in the lockfile.

Written by Cursor Bugbot for commit c61da40. This will update automatically on new commits. Configure here.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Feb 16, 2026
Bumps [borsh](https://github.com/near/borsh-rs) from 0.10.4 to 1.6.0.
- [Release notes](https://github.com/near/borsh-rs/releases)
- [Changelog](https://github.com/near/borsh-rs/blob/master/CHANGELOG.md)
- [Commits](near/borsh-rs@borsh-v0.10.4...borsh-v1.6.0)

---
updated-dependencies:
- dependency-name: borsh
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Feb 16, 2026
@vercel
Copy link
Copy Markdown

vercel Bot commented Feb 16, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
calimero-curb-chat Ready Ready Preview, Comment Feb 16, 2026 8:50pm
calimero-curb-rs Ready Ready Preview, Comment Feb 16, 2026 8:50pm

Request Review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants