[GitHub] [avro] kojiromike opened a new pull request, #2363: Cleanup Unused Imports and Variable Assignments

2023-07-17 Thread via GitHub


kojiromike opened a new pull request, #2363:
URL: https://github.com/apache/avro/pull/2363

   ## What is the purpose of the change
   
   This is a cleanup change to remove unused imports and variable assignments.
   
   
   ## Verifying this change
   
   This change is a trivial rework / code cleanup without any test coverage.
   
   
   ## Documentation
   
   No features or need for additional documentation.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[GitHub] [avro] martin-g merged pull request #2356: Bump syn from 2.0.25 to 2.0.26 in /lang/rust

2023-07-17 Thread via GitHub


martin-g merged PR #2356:
URL: https://github.com/apache/avro/pull/2356


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[GitHub] [avro] martin-g merged pull request #2362: Bump quote from 1.0.29 to 1.0.31 in /lang/rust

2023-07-17 Thread via GitHub


martin-g merged PR #2362:
URL: https://github.com/apache/avro/pull/2362


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[GitHub] [avro] martin-g merged pull request #2358: Bump serde_json from 1.0.102 to 1.0.103 in /lang/rust

2023-07-17 Thread via GitHub


martin-g merged PR #2358:
URL: https://github.com/apache/avro/pull/2358


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[GitHub] [avro] martin-g merged pull request #2361: Bump uuid from 1.4.0 to 1.4.1 in /lang/rust

2023-07-17 Thread via GitHub


martin-g merged PR #2361:
URL: https://github.com/apache/avro/pull/2361


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[GitHub] [avro] martin-g merged pull request #2359: Bump anyhow from 1.0.71 to 1.0.72 in /lang/rust

2023-07-17 Thread via GitHub


martin-g merged PR #2359:
URL: https://github.com/apache/avro/pull/2359


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[GitHub] [avro] dependabot[bot] closed pull request #2360: Bump quote from 1.0.29 to 1.0.30 in /lang/rust

2023-07-17 Thread via GitHub


dependabot[bot] closed pull request #2360: Bump quote from 1.0.29 to 1.0.30 in 
/lang/rust
URL: https://github.com/apache/avro/pull/2360


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[GitHub] [avro] dependabot[bot] opened a new pull request, #2362: Bump quote from 1.0.29 to 1.0.31 in /lang/rust

2023-07-17 Thread via GitHub


dependabot[bot] opened a new pull request, #2362:
URL: https://github.com/apache/avro/pull/2362

   Bumps [quote](https://github.com/dtolnay/quote) from 1.0.29 to 1.0.31.
   
   Release notes
   Sourced from https://github.com/dtolnay/quote/releases;>quote's releases.
   
   1.0.31
   
   Eliminate build.rs to reduce build time
   
   1.0.30
   
   Documentation improvements
   
   
   
   
   Commits
   
   https://github.com/dtolnay/quote/commit/c90bb02fdff6573246aaeb409556b15c60fd672f;>c90bb02
 Release 1.0.31
   https://github.com/dtolnay/quote/commit/c266c3eca88f0775385179ca0346ea3afad71c8f;>c266c3e
 Import from alloc to make remaining std dependencies clear
   https://github.com/dtolnay/quote/commit/3dc55fd1cca84eead7632025e2fa79cf72cceedd;>3dc55fd
 Pull in 2021-edition proc-macro2
   https://github.com/dtolnay/quote/commit/eeafe7a4128d0d16a60b24cd5b6268eaaaf1ed99;>eeafe7a
 Delete build.rs, as no version detection is still used
   https://github.com/dtolnay/quote/commit/8a3481b4fafa445f2717242f1570790b5c40523f;>8a3481b
 Delete needs_invalid_span_woraround config for rustc older than 1.53
   https://github.com/dtolnay/quote/commit/67b54a8c9e88ba57481e47f426e3aa21cddfd1d2;>67b54a8
 Delete rustc minimum version check from build.rs
   https://github.com/dtolnay/quote/commit/3d94d95b8b9321a5207ae48e06dbec6002809263;>3d94d95
 Resolve manual_strip clippy lint
   https://github.com/dtolnay/quote/commit/2b4591ee88e84fe63c1537e67e71df02ed435547;>2b4591e
 Raise required compiler to rust 1.56
   https://github.com/dtolnay/quote/commit/e047e424f4f1e85ca821e0fad5aaecd995965aaf;>e047e42
 Release 1.0.30
   https://github.com/dtolnay/quote/commit/119b223c5334fbab98abea0a40f5dbf6d2d46cc1;>119b223
 Opt in to generate-link-to-definition when building on docs.rs
   Additional commits viewable in https://github.com/dtolnay/quote/compare/1.0.29...1.0.31;>compare 
view
   
   
   
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=quote=cargo=1.0.29=1.0.31)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[GitHub] [avro] martin-g merged pull request #2357: Bump proc-macro2 from 1.0.64 to 1.0.66 in /lang/rust

2023-07-17 Thread via GitHub


martin-g merged PR #2357:
URL: https://github.com/apache/avro/pull/2357


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[GitHub] [avro] kojiromike merged pull request #1181: AVRO-1938: Add fingerprinting support to Python implementation

2023-07-17 Thread via GitHub


kojiromike merged PR #1181:
URL: https://github.com/apache/avro/pull/1181


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[DISCUSS] Release maintenance and lifecycle

2023-07-17 Thread Ryan Skraba
Hello!  There's a number of outstanding questions and discussions
about releases, maintenance, lifecycle :D  I thought it might be
productive to make a goal to work towards.

Specifically, I couldn't point to a policy about this question being
asked on the user@ mailing list: when do we stop maintaining a
version?  My experience over the last few years has been that we only
have one version under development at a time.

One of the major brakes in doing this last release was deciding what
to do with each and every commit on the master branch -- having a
concrete policy and decision on this would definitely help committers
decide when, what and where to cherry-pick changes!

>From 1.12.0 on, I'd like to propose maintaining *two* major versions
(i.e. 1.12.x and 1.11.x).  That would allow us to deprecate and modify
APIs and give developers one whole major release to switch.  The
"older" major version would receive *only* bug and security fixes, the
"newest" major version gets those as well as non-API breaking
features.

All work is committed to master, and the committer makes the decision
how far to cherry-pick, or (in the absence of time) keeps the JIRA
fixVersion up-to-date for someone to pick up the intention.

That's just one suggestion that seems plausible to me!  We can
probably do better without much additional effort (on the limited
resources we have).  What do you think?

All my best regards, Ryan

On Mon, Jul 17, 2023 at 9:43 PM Ryan Skraba  wrote:
>
> Hello!  While Avro doesn't have an official "end-of-life" statement or
> policy, there is no active development on the 1.9 or 1.10 branch.
>
> Our current policy is to add major features to the next major release
> (1.12.0) while bug fixes, CVEs and minor features will be backported
> to the next minor release (1.11.3).
>
> I think we *should* have a policy in place, for projects that depend
> on Avro to have a better visiblity.  I will bring this up on the
> dev@avro.apache.org mailing list -- please feel free to join the
> discussion!
>
> All my best, Ryan
>
>
> On Mon, Jul 17, 2023 at 11:19 AM Pranav Kumar (EXT) via user
>  wrote:
> >
> > Hi,
> >
> >
> >
> > Could you please share End of life/End of support detail or any EoS 
> > criteria that is followed for below:
> >
> >
> >
> > Apache Avro version-1.9.2
> >
> >
> >
> > Regards,
> >
> > Pranav


[GitHub] [avro] dependabot[bot] opened a new pull request, #2361: Bump uuid from 1.4.0 to 1.4.1 in /lang/rust

2023-07-17 Thread via GitHub


dependabot[bot] opened a new pull request, #2361:
URL: https://github.com/apache/avro/pull/2361

   Bumps [uuid](https://github.com/uuid-rs/uuid) from 1.4.0 to 1.4.1.
   
   Release notes
   Sourced from https://github.com/uuid-rs/uuid/releases;>uuid's releases.
   
   1.4.1
   What's Changed
   
   Fix macro hygiene by https://github.com/teohhanhui;>@​teohhanhui in https://redirect.github.com/uuid-rs/uuid/pull/694;>uuid-rs/uuid#694
   Add #[inline] for Uuid::from_bytes[_ref] and Uuid::{as,into}_bytes by https://github.com/jrose-signal;>@​jrose-signal in https://redirect.github.com/uuid-rs/uuid/pull/693;>uuid-rs/uuid#693
   Print uuids in examples by https://github.com/KodrAus;>@​KodrAus in https://redirect.github.com/uuid-rs/uuid/pull/697;>uuid-rs/uuid#697
   Prepare for 1.4.1 release by https://github.com/KodrAus;>@​KodrAus in https://redirect.github.com/uuid-rs/uuid/pull/698;>uuid-rs/uuid#698
   
   New Contributors
   
   https://github.com/teohhanhui;>@​teohhanhui 
made their first contribution in https://redirect.github.com/uuid-rs/uuid/pull/694;>uuid-rs/uuid#694
   https://github.com/jrose-signal;>@​jrose-signal made 
their first contribution in https://redirect.github.com/uuid-rs/uuid/pull/693;>uuid-rs/uuid#693
   
   Full Changelog: https://github.com/uuid-rs/uuid/compare/1.4.0...1.4.1;>https://github.com/uuid-rs/uuid/compare/1.4.0...1.4.1
   
   
   
   Commits
   
   https://github.com/uuid-rs/uuid/commit/97b7f07b3ea7455409e44f0bb4bc697009b7b844;>97b7f07
 Merge pull request https://redirect.github.com/uuid-rs/uuid/issues/698;>#698 from 
uuid-rs/cargo/1.4.1
   https://github.com/uuid-rs/uuid/commit/8e930cf511291725964dfd46f2fa42ddf2e9c606;>8e930cf
 prepare for 1.4.1 release
   https://github.com/uuid-rs/uuid/commit/0041b3b0b42fb9ce3945945f95c6818ba02c94c3;>0041b3b
 Merge pull request https://redirect.github.com/uuid-rs/uuid/issues/697;>#697 from 
uuid-rs/chore/example-printing
   https://github.com/uuid-rs/uuid/commit/5a1f3f56d34365a7c85a36585225bc3f20a9b6f3;>5a1f3f5
 use uuid_unstable
   https://github.com/uuid-rs/uuid/commit/6b0cfb2e281408127e20301f7a88fafb7de68902;>6b0cfb2
 Merge pull request https://redirect.github.com/uuid-rs/uuid/issues/693;>#693 from 
jrose-signal/inline-from_bytes
   https://github.com/uuid-rs/uuid/commit/33f6b3edd9ade424ce014dfc808576f657803fa3;>33f6b3e
 print uuids in examples
   https://github.com/uuid-rs/uuid/commit/bd7df72944ae0775c86aa1db11678eb9e719062c;>bd7df72
 Merge pull request https://redirect.github.com/uuid-rs/uuid/issues/694;>#694 from 
teohhanhui/fix/macro-hygiene
   https://github.com/uuid-rs/uuid/commit/1d1ae31e6c42dbc302b17a50f33b5f1afa714559;>1d1ae31
 Fix macro hygiene
   https://github.com/uuid-rs/uuid/commit/317d925536a82ec5ca1cf9fdf8c6f91203bce8b8;>317d925
 Add #[inline] for Uuid::from_bytes[_ref] and Uuid::{as,into}_bytes
   See full diff in https://github.com/uuid-rs/uuid/compare/1.4.0...1.4.1;>compare 
view
   
   
   
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=uuid=cargo=1.4.0=1.4.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about 

[GitHub] [avro] dependabot[bot] opened a new pull request, #2360: Bump quote from 1.0.29 to 1.0.30 in /lang/rust

2023-07-17 Thread via GitHub


dependabot[bot] opened a new pull request, #2360:
URL: https://github.com/apache/avro/pull/2360

   Bumps [quote](https://github.com/dtolnay/quote) from 1.0.29 to 1.0.30.
   
   Release notes
   Sourced from https://github.com/dtolnay/quote/releases;>quote's releases.
   
   1.0.30
   
   Documentation improvements
   
   
   
   
   Commits
   
   https://github.com/dtolnay/quote/commit/e047e424f4f1e85ca821e0fad5aaecd995965aaf;>e047e42
 Release 1.0.30
   https://github.com/dtolnay/quote/commit/119b223c5334fbab98abea0a40f5dbf6d2d46cc1;>119b223
 Opt in to generate-link-to-definition when building on docs.rs
   https://github.com/dtolnay/quote/commit/54c6efb2a246471eaa4295d9a7b6b869a14c9467;>54c6efb
 Update ui test suite to nightly-2023-07-09
   https://github.com/dtolnay/quote/commit/49dcb3fdda1b138498370fb12949f1ad66fa1df6;>49dcb3f
 Move minimal-versions CI to dedicated job
   See full diff in https://github.com/dtolnay/quote/compare/1.0.29...1.0.30;>compare 
view
   
   
   
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=quote=cargo=1.0.29=1.0.30)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[GitHub] [avro] dependabot[bot] opened a new pull request, #2359: Bump anyhow from 1.0.71 to 1.0.72 in /lang/rust

2023-07-17 Thread via GitHub


dependabot[bot] opened a new pull request, #2359:
URL: https://github.com/apache/avro/pull/2359

   Bumps [anyhow](https://github.com/dtolnay/anyhow) from 1.0.71 to 1.0.72.
   
   Release notes
   Sourced from https://github.com/dtolnay/anyhow/releases;>anyhow's 
releases.
   
   1.0.72
   
   Documentation improvements
   
   
   
   
   Commits
   
   https://github.com/dtolnay/anyhow/commit/e458996b0a0027983bfc329bb42c456bad6928a5;>e458996
 Release 1.0.72
   https://github.com/dtolnay/anyhow/commit/660fb0f06803550e8faf78aa58a5680a1d46ab74;>660fb0f
 Opt in to generate-link-to-definition when building on docs.rs
   https://github.com/dtolnay/anyhow/commit/24d91665819f8a9888d9e27ed97c658405ce286a;>24d9166
 Add CI job using minimal-versions
   https://github.com/dtolnay/anyhow/commit/2c913b30787418f9f9d615a9c8de006ef5bff739;>2c913b3
 Remove .clippy.toml in favor of respecting rust-version from Cargo.toml
   https://github.com/dtolnay/anyhow/commit/1f17666ef1d4d3cd1f05a9ee5e79f75d66801c66;>1f17666
 Ignore needless_else clippy lint in test suite
   https://github.com/dtolnay/anyhow/commit/60466748142e0d3c615553cfc60026dedf7adb6c;>6046674
 Show error details during miri setup in CI
   https://github.com/dtolnay/anyhow/commit/dffcb4bf6cd925a8cf4f780db524212336ce7f0f;>dffcb4b
 Revert Temporarily disable miri CI
   https://github.com/dtolnay/anyhow/commit/438fec6036ab93691f5fc8995a4e55be2058df4f;>438fec6
 Temporarily disable miri CI
   See full diff in https://github.com/dtolnay/anyhow/compare/1.0.71...1.0.72;>compare 
view
   
   
   
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=anyhow=cargo=1.0.71=1.0.72)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[GitHub] [avro] dependabot[bot] opened a new pull request, #2358: Bump serde_json from 1.0.102 to 1.0.103 in /lang/rust

2023-07-17 Thread via GitHub


dependabot[bot] opened a new pull request, #2358:
URL: https://github.com/apache/avro/pull/2358

   Bumps [serde_json](https://github.com/serde-rs/json) from 1.0.102 to 1.0.103.
   
   Release notes
   Sourced from https://github.com/serde-rs/json/releases;>serde_json's 
releases.
   
   v1.0.103
   
   Documentation improvements
   
   
   
   
   Commits
   
   https://github.com/serde-rs/json/commit/54bcb4dc94a29a0fe67ec735c5525760823a5499;>54bcb4d
 Release 1.0.103
   https://github.com/serde-rs/json/commit/9c2879a848ae3117d2c99a03d415bb77a1ac7d34;>9c2879a
 Opt in to generate-link-to-definition when building on docs.rs
   https://github.com/serde-rs/json/commit/d1a07e29f2a665e133a8bee4d58666bea8ea40ef;>d1a07e2
 Fix rustdoc::bare_urls lint in lexical code
   See full diff in https://github.com/serde-rs/json/compare/v1.0.102...v1.0.103;>compare 
view
   
   
   
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=serde_json=cargo=1.0.102=1.0.103)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[GitHub] [avro] dependabot[bot] opened a new pull request, #2357: Bump proc-macro2 from 1.0.64 to 1.0.66 in /lang/rust

2023-07-17 Thread via GitHub


dependabot[bot] opened a new pull request, #2357:
URL: https://github.com/apache/avro/pull/2357

   Bumps [proc-macro2](https://github.com/dtolnay/proc-macro2) from 1.0.64 to 
1.0.66.
   
   Release notes
   Sourced from https://github.com/dtolnay/proc-macro2/releases;>proc-macro2's 
releases.
   
   1.0.65
   
   Documentation improvements
   
   
   
   
   Commits
   
   https://github.com/dtolnay/proc-macro2/commit/64b4608278be46fcc8d63ae1138da8cb600e258a;>64b4608
 Release 1.0.66
   https://github.com/dtolnay/proc-macro2/commit/11d8cabc70009c644482182b1dfa1584609b590e;>11d8cab
 Update supported compiler in description of semver exempt polyfill
   https://github.com/dtolnay/proc-macro2/commit/fc8af0d27760113ff45c4f1d3c752f7954e95cbe;>fc8af0d
 Revert Fix test failure due to quoting change in str's Debug
   https://github.com/dtolnay/proc-macro2/commit/177c70071151a0be9117f1439d2f487e6722df3c;>177c700
 Import from alloc to make remaining std dependencies clear
   https://github.com/dtolnay/proc-macro2/commit/00360bc9fd589ec04c9ad753faefb381cce8baa1;>00360bc
 Delete no_group_open_close config for rustc older than 1.55
   https://github.com/dtolnay/proc-macro2/commit/346cc0533f0049cd84267f002ac6fc9356c5a170;>346cc05
 Inline compiler_literal_from_str
   https://github.com/dtolnay/proc-macro2/commit/2d8dd97adcc3a5495bac96caad29247872499073;>2d8dd97
 Delete no_literal_from_str config for rustc older than 1.54
   https://github.com/dtolnay/proc-macro2/commit/3f96a77cb5c63ca3106784b0c4287c8f11b21b78;>3f96a77
 Delete no_ident_new_raw config for rustc older than 1.47
   https://github.com/dtolnay/proc-macro2/commit/56c04ea4a23673947191de8904bb4c391dd7b985;>56c04ea
 Delete no_hygiene config for rustc older than 1.45
   https://github.com/dtolnay/proc-macro2/commit/467a0b40da2b039d4434ebcadbb27186f2a13761;>467a0b4
 Delete no_lexerror_display config for rustc older than 1.44
   Additional commits viewable in https://github.com/dtolnay/proc-macro2/compare/1.0.64...1.0.66;>compare 
view
   
   
   
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=proc-macro2=cargo=1.0.64=1.0.66)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[GitHub] [avro] dependabot[bot] opened a new pull request, #2356: Bump syn from 2.0.25 to 2.0.26 in /lang/rust

2023-07-17 Thread via GitHub


dependabot[bot] opened a new pull request, #2356:
URL: https://github.com/apache/avro/pull/2356

   Bumps [syn](https://github.com/dtolnay/syn) from 2.0.25 to 2.0.26.
   
   Release notes
   Sourced from https://github.com/dtolnay/syn/releases;>syn's 
releases.
   
   2.0.26
   
   Implement Spanned for QSelf (https://redirect.github.com/dtolnay/syn/issues/1465;>#1465)
   
   
   
   
   Commits
   
   https://github.com/dtolnay/syn/commit/a4d7aa80e32647b1f3e6e8fd80c68aa5125f3c0e;>a4d7aa8
 Release 2.0.26
   https://github.com/dtolnay/syn/commit/ee59842458f2272a874b158f4d222de4a5c20ccc;>ee59842
 Merge pull request https://redirect.github.com/dtolnay/syn/issues/1486;>#1486 from 
dtolnay/qselfspan
   https://github.com/dtolnay/syn/commit/9e32a34bbd081b0e453e7515b322047ca48d1e61;>9e32a34
 Implement Spanned for QSelf
   See full diff in https://github.com/dtolnay/syn/compare/2.0.25...2.0.26;>compare 
view
   
   
   
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=syn=cargo=2.0.25=2.0.26)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[GitHub] [avro] clesaec opened a new pull request, #2355: AVRO-3801: [java] change method signature

2023-07-17 Thread via GitHub


clesaec opened a new pull request, #2355:
URL: https://github.com/apache/avro/pull/2355

   
   
   ## What is the purpose of the change
   
   [AVRO-3801](https://issues.apache.org/jira/browse/AVRO-3801) : simplify 
Parse addTypes signature.
   
   
   ## Verifying this change
Unit test added
   
   ## Documentation
   
   - Does this pull request introduce a new feature? (no)
   - If yes, how is the feature documented? (not applicable)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[GitHub] [avro] martin-g merged pull request #2354: AVRO-3800: [Rust] profile section should be declared in the root package

2023-07-17 Thread via GitHub


martin-g merged PR #2354:
URL: https://github.com/apache/avro/pull/2354


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[jira] [Created] (AVRO-3801) Modify Schema.Parser.addTypes signature

2023-07-17 Thread Christophe Le Saec (Jira)
Christophe Le Saec created AVRO-3801:


 Summary: Modify Schema.Parser.addTypes signature
 Key: AVRO-3801
 URL: https://issues.apache.org/jira/browse/AVRO-3801
 Project: Apache Avro
  Issue Type: Improvement
Reporter: Christophe Le Saec
Assignee: Christophe Le Saec


On java module, method addTypes is defined with a Map as input parameter
{code:java}
public Parser addTypes(Map types) {
{code}
But key is never used.
So, very basic, simple improvement, is to change to 
{code:java}
public Parser addTypes(Iterabler types) {
{code}
(keeping current one as deprecated for backward compatibility purpose)





--
This message was sent by Atlassian Jira
(v8.20.10#820010)


[GitHub] [avro] sarutak opened a new pull request, #2354: AVRO-3800: [Rust] profile section should be declared in the root package.

2023-07-17 Thread via GitHub


sarutak opened a new pull request, #2354:
URL: https://github.com/apache/avro/pull/2354

   AVRO-3800
   
   ## What is the purpose of the change
   
   This PR fixes an issue that [profile.release] declared in 
`wasm-demo/Cargo.toml` is ignored.
   In that section, `opt-level = "s"` is specified but it's ignored.
   
   ```
   $ cargo test -v --test demos --release
   ...
Running `rustc --crate-name hello_wasm ... opt-level=3 ...`
Running `rustc --crate-name demos ... opt-level=3 ...`
   ```
   
   To fix this issue, this change moves the section to `Cargo.toml` of the root 
package.
   
   ## Verifying this change
   
   After this change is applied, we can confirm that opt-level is changed as 
expected.
   ```
   $ cargo test -v --test demos --release
   ...
Running `rustc --crate-name hello_wasm ... opt-level=s ...`
Running `rustc --crate-name demos ... opt-level=s ...`
   ```
   
   ## Documentation
   
   No new docs as this PR introduces no new features.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[jira] [Created] (AVRO-3800) profile section should be declared in the root package.

2023-07-17 Thread Kousuke Saruta (Jira)
Kousuke Saruta created AVRO-3800:


 Summary: profile section should be declared in the root package.
 Key: AVRO-3800
 URL: https://issues.apache.org/jira/browse/AVRO-3800
 Project: Apache Avro
  Issue Type: Bug
  Components: build, rust
Affects Versions: 1.12.0
Reporter: Kousuke Saruta


In wasm-demo/Cargo.toml, [profile.release] is declared but it's ignored.
It should be declared in Cargo.toml of root package.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)


[GitHub] [avro] clesaec opened a new pull request, #2353: AVRO-2204: [java] owasp dependency check to the build.

2023-07-17 Thread via GitHub


clesaec opened a new pull request, #2353:
URL: https://github.com/apache/avro/pull/2353

   
   
   ## What is the purpose of the change
   
   [AVRO-2204](https://issues.apache.org/jira/browse/AVRO-2204) : Add owasp to 
CI.
   
   
   ## Verifying this change
   
   - This check directly in CI.
   
   ## Documentation
   
   - Does this pull request introduce a new feature? (no)
   - If yes, how is the feature documented? (not applicable)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[GitHub] [avro] martin-g merged pull request #2352: AVRO-3799: [Rust] Enable the schema parser to read and parse from input streams for Rust binding

2023-07-17 Thread via GitHub


martin-g merged PR #2352:
URL: https://github.com/apache/avro/pull/2352


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@avro.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org