Hmbown/CodeWhale · error · ValidationError

depends on workspace crate [ ], which is not in the…

Error message

{dependent} depends on workspace crate {dependency_name} [{kind}], which is not in the codewhale-* release inventory

What it means

For every non-dev (normal/build/etc.) path dependency a codewhale-* crate has on another workspace crate, that dependency must also appear in the codewhale-* publish inventory (crates.sh), since it must be published too and before its dependent. Dev-dependencies are skipped because Cargo does not compile them during publish verification. If a required dependency is missing from the inventory, this error names the dependent, the dependency, and the dependency kind.

Solutions

  1. Rename the dependency crate to the codewhale-* convention and add it to scripts/release/crates.sh before its dependents.
  2. Or vendor/inline the helper code to remove the cross-crate dependency.
  3. Or, if the dependency must not be published, restructure so the published crate does not depend on it (e.g. move shared code into a published crate).
  4. If the edge is test-only, declare it as a dev-dependency (validator skips those).

Example fix

// before (crates/tui/Cargo.toml)
[dependencies]
my-helper = { path = "../my-helper" }
// after
[dev-dependencies]
my-helper = { path = "../my-helper" }  # or rename to codewhale-* and add to crates.sh
Defensive patterns

Strategy: validation

Validate before calling

for dep in dependent_pkg['dependencies']:
    if dep.get('kind') in (None, 'normal', 'build') and dep.get('path') \
       and dep['name'] in workspace and dep['name'] not in ordered:
        print('add to crates.sh:', dep['name'])

Try / catch

try:
    validate_order(...)
except ValidationError as e:
    print('publish inventory gap:', e)

Prevention

When it happens

Trigger: A crate gains a new normal path dependency on a workspace crate whose name does not start with codewhale-* (so it is not in release_names), or on a workspace crate excluded from the publish list; a crate is renamed so it drops out of the inventory.

Common situations: Adding an internal helper crate without the codewhale- prefix; converting a dev-dependency to a normal dependency (now it becomes a publish edge); introducing a private crate not intended for publishing but depended on by a published one.

Understand the failure class

Background: "not installed", "pip install", "required for": how missing-dependency errors surface across open-source libraries — this error's family across 34 libraries.

Related errors


AI-assisted analysis of Hmbown/CodeWhale@433685b202 (2026-09-15). Data as JSON: /api/errors/2d71a888e667600c. Report an issue: GitHub.

Appendix: source

Thrown at scripts/release/validate-crate-publish-order.py:140

    publish_edges: set[tuple[str, str, str]] = set()
    for dependent in release_names:
        dependencies = workspace_by_name[dependent].get("dependencies", [])
        if not isinstance(dependencies, list):
            raise ValidationError(f"Cargo metadata dependencies for {dependent} must be a list")
        for dependency in dependencies:
            if not isinstance(dependency, dict) or dependency.get("path") is None:
                continue
            dependency_name = dependency.get("name")
            if dependency_name not in workspace_by_name:
                continue
            has_workspace_dependencies[dependent] = True
            kind = dependency.get("kind") or "normal"
            # Cargo does not compile dev-dependencies while verifying a publish.
            # They may legitimately point back across the publication DAG.
            if kind == "dev":
                continue
            if dependency_name not in positions:
                raise ValidationError(
                    f"{dependent} depends on workspace crate {dependency_name} "
                    f"[{kind}], which is not in the codewhale-* release inventory"
                )
            publish_edges.add((dependency_name, dependent, str(kind)))

    violations = sorted(
        (
            dependency,
            dependent,
            kind,
        )
        for dependency, dependent, kind in publish_edges
        if positions[dependency] >= positions[dependent]
    )
    if violations:
        lines = ["crate publication order is not topological:"]
        for dependency, dependent, kind in violations:
            lines.append(

View on GitHub (pinned to 433685b202)