Skip to content

Conversation

@elizabethengelman
Copy link
Collaborator

@elizabethengelman elizabethengelman commented Dec 15, 2025

What

Upgrades bollard and testcontainers dependencies.

Why

These two dependencies were pretty out of date because they previously had a dependency mismatch with their version of bollard-stubs. As of the most recent version of testcontainers doesn't include bollard-stubs directly in its dependency list, so this mismatch shouldn't be a problem going forward.

Known limitations

bollard has an update that's merged into main, but not released yet that should take care of the failing cargo deny advisory check. fussybeaver/bollard#613

@github-project-automation github-project-automation bot moved this to Backlog (Not Ready) in DevX Dec 15, 2025
@socket-security
Copy link

socket-security bot commented Dec 15, 2025

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedcargo/​bollard@​0.16.1 ⏵ 0.19.463 -310093100100
Updatedcargo/​serde@​1.0.219 ⏵ 1.0.2288110093100100
Updatedcargo/​serde_derive@​1.0.219 ⏵ 1.0.22810010093100100
Updatedcargo/​testcontainers@​0.20.1 ⏵ 0.26.097 -210093100100

View full report

@elizabethengelman elizabethengelman marked this pull request as ready for review December 15, 2025 20:58
@elizabethengelman elizabethengelman self-assigned this Dec 16, 2025
@elizabethengelman
Copy link
Collaborator Author

@fnando it looks like there is a failure in the rpc-tests that several PRs have as well. I think this is probably safe to merge with that failure, what do you think?

@fnando
Copy link
Member

fnando commented Dec 19, 2025

Yes, let's merge this. I'll take a look at the failing tests. :)

@fnando fnando enabled auto-merge (squash) December 19, 2025 15:48
@fnando fnando merged commit 3ded080 into main Dec 19, 2025
28 of 30 checks passed
@fnando fnando deleted the chore/bollard-upgrade branch December 19, 2025 16:06
@github-project-automation github-project-automation bot moved this from Backlog (Not Ready) to Done in DevX Dec 19, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants