Hi, I see we've checked in Cargo.lock recently #14135, and I think it's good!
But I'm not sure whether this was discussed: what about not updating Cargo.toml (for minor/patch versions), but only Cargo.lock?
From the discussion, I can see the main motivation is to have reproducible build (agains near latest dependencies) in CI. To achieve this, Cargo.lock (updated by bot) is enough.
Whether or not updating Cargo.toml means whether or not force downstream users to use only the latest dependency versions. Personally I prefer a more tolerable version range, so that downstream can update deps 1 by 1 and audit each dep's changes.
FYI in iceberg-rust, we have similar discussions on this topic, and we prefer to have a wider range of versions support, to allow users to choose their dep version (by not updating Cargo.toml too often) https://lists.apache.org/thread/pv3onm41229lovs1odqg94fdc60wcp73
Hi, I see we've checked in
Cargo.lockrecently #14135, and I think it's good!But I'm not sure whether this was discussed: what about not updating
Cargo.toml(for minor/patch versions), but onlyCargo.lock?From the discussion, I can see the main motivation is to have reproducible build (agains near latest dependencies) in CI. To achieve this,
Cargo.lock(updated by bot) is enough.Whether or not updating
Cargo.tomlmeans whether or not force downstream users to use only the latest dependency versions. Personally I prefer a more tolerable version range, so that downstream can update deps 1 by 1 and audit each dep's changes.FYI in iceberg-rust, we have similar discussions on this topic, and we prefer to have a wider range of versions support, to allow users to choose their dep version (by not updating Cargo.toml too often) https://lists.apache.org/thread/pv3onm41229lovs1odqg94fdc60wcp73