Skip to content

build(deps): bump gix from 0.87.1 to 0.88.0 - #106

Merged
abemedia merged 2 commits into
masterfrom
dependabot/cargo/gix-0.88.0
Oct 5, 2026
Merged

abemedia merged 2 commits into
masterfrom
dependabot/cargo/gix-0.88.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps gix from 0.87.1 to 0.88.0.

Release notes

Sourced from gix's releases.

gix v0.88.0

Bug Fixes (BREAKING)

  • preserve causes across fallible conversions

    Rubber stamp, looked at diff. This is a cleanup commit. There is going to be considerable cleanup done later as well.

    Parsers and adapters discarded encoding, integer, date, signature, and object-access failures when replacing them with context. Preserve their concrete causes so classification and downcasting keep working after conversion to gix::Error or an I/O error.

    Return Exn from fallible path, command-line, gitdir, and pack-entry conversions where necessary, and adapt their consumers in the same change. Packed-ref and reflog errors retain their parser sources and input details; reflog recovery reports the actual recovery failure. Loose-object verification now propagates lookup and enumeration failures instead of treating every lookup error as retryable or silently skipping failed enumeration.

    Remove unnecessary UTF-8 conversions for ASCII suffixes and check span bounds before narrowing. Parsers that only return () explicitly destructure it. No production map_err() closure still discards a wildcard-bound error. Also preserve causes in formatting-only CLI and commit-graph adapters, where stringification previously lost checksum corruption classifications.

  • locate vi/vim in Git's core directory on Windows; change Repository::editor() -> Option<gix_command::Prepare>

    On Windows, Git's bundled vi may not be available through PATH. Resolve the default editor in Git's core directory first and retain the bare command as fallback.

New Features (BREAKING)

  • return the local branches actually deleted

    Callers that needed to know whether branch deletion removed anything had to look up each reference separately. That duplicated reference reads and could report stale existence information by the time deletion took its locks.

    Return sorted, deduplicated full names from the committed reference edits whose previous values were observed under lock. Missing branches are excluded while their stale local configuration is still removed. Expose the same list as deleted in delete::Error::Cleanup so callers can recover it when only configuration cleanup fails; retain references as the full requested batch.

    The success value changes from () to Vec<FullName>, and Cleanup gains

... (truncated)

Commits
  • 37860b3 Release gix-error v0.4.0, gix-date v0.17.0, gix-actor v0.43.0, gix-trace v0.2...
  • 7f69d07 chore: add cargo smart-release incantation to justfile
  • e11a4c2 report proofing
  • 9f1a6cc report September 2026
  • 591380a Merge pull request #3019 from GitoxideLabs/mailmap-perf
  • b9b3d42 chore(gix-mailmap): modernize integration test layout
  • 4163b89 fix(gix-mailmap): build snapshots without quadratic insertion
  • 6356013 Merge pull request #2847 from GitoxideLabs/gix-error-completion
  • da0f21d change(gix-error)!: unify diagnostics as Message and preserve causes
  • f79ab74 Exclude Rust tests and examples from CodeQL analysis
  • Additional commits viewable in compare view

Summary by CodeRabbit

  • Bug Fixes
    • Hook installation now completes with a warning when no repository is found, rather than failing.
    • Removing the last stash entry no longer reports an error if its reference is already missing or has changed.
    • Repository status checks now skip paths with validation errors, while other path errors continue to be reported.
    • Git-related errors encountered during repository operations are handled consistently, improving error reporting across status and workflow actions.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Oct 1, 2026
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 7fbd4dec-0cf5-4300-b38e-9754cce46bba
📥 Commits

Reviewing files that changed from the base of the PR and between cdf4d26 and c7e75e8.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (5)
  • Cargo.toml
  • src/hook.rs
  • src/main.rs
  • src/status.rs
  • src/workflow.rs

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The pull request updates gix from 0.87 to 0.88 and changes error handling in hook installation, status collection, and workflow operations. It also updates workflow error variants and final stash-reference deletion handling.

Changes

gix Error Handling Updates

Layer / File(s) Summary
gix compatibility
Cargo.toml, src/hook.rs, src/main.rs
The gix dependency moves to 0.88. Hook installation handles qualifying repository discovery errors using the saved current directory. Git byte-path conversion maps gix::Exn to an error.
Status error handling
src/status.rs
Status and revision errors now store gix::Error directly. Path scoping skips normalization errors classified as validation; other errors return Error::Path.
Workflow error types
src/workflow.rs
The workflow error enum uses gix::Error for more operation sources, consolidates merge errors, adds Config, and removes several dedicated variants.
Workflow error mapping
src/workflow.rs
Workflow operations map failures to the updated error variants. Final stash-reference deletion treats not-found and ReferenceOutOfDate errors as success.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Other

Suggested reviewers: abemedia

Merge Risk: ⚪ Minimal · up to c7e75

This change upgrades gix to 0.88 and adapts error handling across status, hooks, and workflow operations. No outstanding defect has been established, and the reported path-formatting compile error does not occur with the locked thiserror version.

Security Architecture Review

Security architecture risk: 🔵 Low · up to c7e75

The inspected changes preserve stash identity checks, repository locks, and recovery safeguards. No introduced security defect was established. Some uncertainty remains because the new dependency’s error classifications could affect which failures are silently skipped or treated as successful cleanup.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The inspected exposure is local repository state under the invoking process’s filesystem authority. It includes index entries, dirty and requested untracked-file backups, common-directory stash references and reflogs, and the configured hook destination. The backup scope is broader than only the files passed to tasks.

Trust Boundaries and Controls

  • inferred — Broader validation-error skipping does not directly admit rejected paths into task execution: insertion still requires successful normalization. Nevertheless, whether it newly suppresses a security-relevant failure depends on unavailable dependency classification semantics.
  • observed — Final stash deletion requires refs/stash to match the workflow’s owned commit OID. Although the explicit lock is released before that transaction, the expected-value condition remains and guards against deleting a concurrently replaced stash reference. Reflog rewriting holds both reference and reflog locks.

Resilience and Maintainability Implications

  • observed — Restoration uses the saved backup OID. The attempted flag prevents automatic repetition after restoration starts, and a restoration failure leaves the backup available for explicit recovery. These application-level recovery controls remain unchanged by the error-contract migration.

Hardening Proposals

  • proposed — Verify the new classification predicates against explicit allowed terminal states: rejected out-of-scope paths, absent repositories, and absent or replaced owned stash references. This would resolve the remaining uncertainty about silently suppressed failures without implying that a defect has been demonstrated.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the main change: updating the gix dependency from 0.87.1 to 0.88.0.
Docstring Coverage ✅ Passed Docstring coverage is 83.33% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 12 functions across 4 files. (1 skipped: 1 …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
✨ Simplify code
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
stagelint-docs c7e75e8 Commit Preview URL

Branch Preview URL
Oct 05 2026, 10:15 AM

@dependabot
dependabot Bot force-pushed the dependabot/cargo/gix-0.88.0 branch from ac062b7 to 48a062c Compare October 4, 2026 00:25
Repository owner deleted a comment from coderabbitai Bot Oct 5, 2026
coderabbitai[bot]

This comment was marked as resolved.

@abemedia
abemedia force-pushed the dependabot/cargo/gix-0.88.0 branch from 594d049 to 3bd7987 Compare October 5, 2026 10:13
dependabot Bot and others added 2 commits October 5, 2026 11:14
Bumps [gix](https://github.com/GitoxideLabs/gitoxide) from 0.87.1 to 0.88.0.
- [Release notes](https://github.com/GitoxideLabs/gitoxide/releases)
- [Changelog](https://github.com/GitoxideLabs/gitoxide/blob/main/CHANGELOG.md)
- [Commits](GitoxideLabs/gitoxide@gix-v0.87.1...gix-v0.88.0)

---
updated-dependencies:
- dependency-name: gix
  dependency-version: 0.88.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@abemedia
abemedia force-pushed the dependabot/cargo/gix-0.88.0 branch from 3bd7987 to c7e75e8 Compare October 5, 2026 10:14
Repository owner deleted a comment from coderabbitai Bot Oct 5, 2026
@abemedia
abemedia merged commit 3b48732 into master Oct 5, 2026
6 checks passed
@abemedia
abemedia deleted the dependabot/cargo/gix-0.88.0 branch October 5, 2026 10:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant