Cargo
Description
The cargo crawler looks recursively for all cargo crates from a specific root directory. Then for each of them, it tries to update dependencies specified in Cargo.toml.
Dependencies are read from:
[dependencies][dev-dependencies][build-dependencies]the
[workspace.dependencies]equivalents
This crawler can be enabled either automatically with default behavior by running updatecli diff from a directory containing the files to update.
Or by providing a manifest.
The automatic discovery behavior can be tuned by providing a YAML manifest with a cargo crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.
Requirements
Updates are applied by running cargo, so the toolchain has to be reachable from the environment running Updatecli.
Important | If a Cargo.lock sits next to Cargo.toml and neither the cargo command nor cargo upgrade can be found, the whole crate is skipped with a warning. Updatecli will not bump a dependency it cannot re-lock. |
cargo upgrade comes from cargo-edit. When it is available, both Cargo.toml and Cargo.lock are updated. When only plain cargo is available, a reduced command is generated that refreshes the lock file alone.
Generated manifests
Each dependency produces:
a
cargopackagesource resolving the latest crate version,a
shellcondition that stops the pipeline when the discovered version already matches what is declared,a
shelltarget invokingcargo upgradeandcargo update, guarded by afile/checksumoverCargo.tomlandCargo.lock.
The generated command honours Updatecli’s dry-run mode by passing --dry-run to cargo when $DRY_RUN is set, so updatecli diff does not modify the crate.
Private registries
Use registries to describe a non-default crate registry, so generated sources resolve versions against it rather than crates.io.
Manifests
Parameters
The crawler cargo supports the following parameters:
| Name | Type | Description | Required |
|---|---|---|---|
| ignore | array | “ignore” defines rules to exclude matching crates from the autodiscovery. remark:
| |
| crates | object | “crates” defines the crates to match, keyed by crate name. remark:
| |
| path | string | “path” defines a “Cargo.toml” path pattern. remark:
| |
| registries | array | “registries” defines the Cargo registry names to match. remark:
| |
| only | array | “only” defines rules to restrict the autodiscovery to matching crates. remark:
| |
| crates | object | “crates” defines the crates to match, keyed by crate name. remark:
| |
| path | string | “path” defines a “Cargo.toml” path pattern. remark:
| |
| registries | array | “registries” defines the Cargo registry names to match. remark:
| |
| registries | object | “registries” defines the Cargo registries used by the generated manifests, keyed by registry name. remark:
| |
| auth | object | “auth” defines the credentials used to authenticate with the cargo registry. | |
| headerformat | string | “headerformat” defines the format of the Authorization header sent with “token”. default: Bearer %s remark:
example:
| |
| token | string | “token” defines the cargo registry token used for authentication. | |
| rootdir | string | “rootdir” defines the local directory of a cargo registry index, used instead of the registry API. remark:
| |
| scmid | string | “scmid” defines the scm holding the cargo registry index, used instead of the registry API. remark:
| |
| url | string | “url” defines the URL of the cargo registry API. default: https://crates.io/api/v1/crates, when neither “rootdir” nor a scm is set. remark:
| |
| rootdir | string | “rootdir” defines the directory where the crawler starts searching for “Cargo.toml” files. default: the scm directory when “scmid” is set, otherwise the directory relative paths resolve from, by default the working directory. remark:
| |
| versionfilter | object | “versionfilter” defines the version filter used by the generated manifests. default: kind “semver” with pattern “*”, the latest version. remark:
example: | |
| kind | string | “kind” defines the versioning scheme used to select a version. default: latest remark:
example:
| |
| pattern | string | “pattern” defines the version pattern, according to “kind”. default:
remark:
example:
| |
| regex | string | “regex” defines the regular expression extracting the version from each entry. remark:
example:
| |
| replaceall | object | “replaceall” applies a regular expression replacement to each version before filtering. remark:
example: turns “curl-8_15_0” into “curl-8.15.0”. | |
| pattern | string | “pattern” defines the regular expression matching the text to replace. example:
| |
| replacement | string | “replacement” defines the text replacing each match of “pattern”. remark:
example:
| |
| strict | boolean | “strict” enforces strict semantic versioning rules when parsing versions. default: false remark:
|
Example
# updatecli.d/default.yaml
name: "Cargo compose autodiscovery using git scm"
scms:
default:
kind: git
spec:
url: https://github.com/updatecli-test/cargo-lab.git
branch: "main"
private-registry:
kind: git
spec:
url: "https://github.com/updatecli-test/fake-cargo-registry.git"
branch: "main"
autodiscovery:
scmid: default
crawlers:
cargo:
registries:
fake-private-git:
scmid: private-registry
fake-private-http:
url: "https://updatecli-test.github.io/fake-cargo-registry/api/v1/crates"