{"record":{"id":"882d4d0455838030","repo":"vectordotdev/vector","slug":"cargo-lock-was-modified-by-cargo-tool-please-commit-the","errorCode":null,"errorMessage":"Cargo.lock was modified by `cargo {tool}`. Please commit the updated Cargo.lock.","messagePattern":"Cargo\\.lock was modified by `cargo (.+?)`\\. Please commit the updated Cargo\\.lock\\.","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"vdev/src/commands/check/rust.rs","lineNumber":81,"sourceCode":"            .chain_args(feature_args)\n            .chain_args(pre_args)\n    }\n\n    pub fn exec(self) -> Result<()> {\n        let lock_file = paths::find_repo_root()?.join(\"Cargo.lock\");\n        let lock_before = fs::read(&lock_file)?;\n\n        let tool = if self.clippy {\n            Tool::Clippy\n        } else {\n            Tool::Check\n        };\n\n        app::exec(\"cargo\", self.build_args(tool), true)?;\n\n        let lock_after = fs::read(&lock_file)?;\n        if lock_before != lock_after {\n            bail!(\n                \"Cargo.lock was modified by `cargo {tool}`. Please commit the updated Cargo.lock.\"\n            );\n        }\n\n        // If --fix was used, check for changes and commit them.\n        if self.fix {\n            let has_changes = !git::get_modified_files()?.is_empty();\n            if has_changes {\n                app::exec(\"cargo\", [\"fmt\", \"--all\"], true)?;\n                git::commit(\"chore(vdev): apply vdev rust check fixes\")?;\n            }\n        }\n\n        Ok(())\n    }\n}\n\n#[cfg(test)]","sourceCodeStart":63,"sourceCodeEnd":99,"githubUrl":"https://github.com/vectordotdev/vector/blob/bdb87aeaa4c4ff27c0ba643c1c77b21bf2ef4013/vdev/src/commands/check/rust.rs#L63-L99","documentation":"`vdev check rust` runs `cargo clippy`/`cargo fmt` (via `app::exec`) and then verifies `Cargo.lock` was not changed. If the lockfile differs before and after running the tool, it bails, because dependency resolution changes must be an explicit, committed change.","triggerScenarios":"Running `cargo fmt` or `cargo clippy` resolves dependencies differently than the committed lockfile — e.g. new transitive deps available, version requirements unlocked, or Cargo.toml edited without updating the lock.","commonSituations":"Dependency added to Cargo.toml without `cargo check`/`cargo build` updating the lock first; `cargo update` artifacts missing from the commit; using a different cargo version that resolves differently.","solutions":["Run `cargo check` (or the tool named in the message) to regenerate the lockfile.","Commit the updated `Cargo.lock` in the same change.","Re-run `make check-clippy` / `make check-fmt`."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"git diff --exit-code Cargo.lock # must be empty after running clippy/fmt","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Commit Cargo.lock together with any Cargo.toml change.","Run `cargo check` before invoking clippy/fmt so the lock is already resolved.","Keep a consistent cargo version across contributors and CI."],"tags":["cargo","dependencies","lockfile","ci"],"backgroundTag":"checksum-mismatch","analyzedSha":"bdb87aeaa4c4ff27c0ba643c1c77b21bf2ef4013","analyzedAt":"2026-09-16T02:53:35.741Z","contentChangedAt":"2026-09-16T02:53:35.741Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}