rust-lang/cargo · error
all dependencies must have a version requirement specified…
Error message
all dependencies must have a version requirement specified when {}.
dependency `{}` does not specify a version
Note: The {} dependency will use the version from {},
the `{}` specification will be removed from the dependency declaration. What it means
Thrown by `check_dep_has_version` during `cargo package` or `cargo publish` when a path or git dependency does not specify a version requirement (`specified_req()` is false) and the dependency is transitive (will be included in the published artifact). Path/git dependencies need a version field so that when the path/git source is stripped on publish, the registry version can fill in.
Solutions
- Add a `version` key to the dependency declaration in Cargo.toml.
- If the dependency is dev-only, move it under `[dev-dependencies]` so it is not transitive.
- If optional, mark it `optional = true` so it is not required for publish.
Example fix
# Cargo.toml (before)
[dependencies]
my-crate = { path = "../my-crate" }
# Cargo.toml (after)
[dependencies]
my-crate = { path = "../my-crate", version = "1.0" } Defensive patterns
Strategy: validation
Validate before calling
fn check_path_git_deps_have_version(manifest: &toml::Value) -> Result<(), String> {
let deps = manifest.get("dependencies").and_then(|d| d.as_table());
if let Some(deps) = deps {
for (name, val) in deps {
if let Some(t) = val.as_table() {
let has_path_or_git = t.contains_key("path") || t.contains_key("git");
let has_version = t.contains_key("version");
let optional = t.get("optional").and_then(|o| o.as_bool()).unwrap_or(false);
if has_path_or_git && !has_version && !optional {
return Err(format!("dependency `{}` has path/git but no version requirement", name));
}
}
}
}
Ok(())
} Prevention
- Always add a `version` field to path and git dependencies.
- Run `cargo publish --dry-run` before publishing to catch missing versions.
- For dev-only path deps, place them under `[dev-dependencies]`.
When it happens
Trigger: Running `cargo package` or `cargo publish` on a crate that has a `[dependencies]` entry with `path = "..."` or `git = "..."` but no `version = "..."` key, and that dependency is non-optional and non-dev-only (transitive).
Common situations: Workspace members referencing each other by path without a version; a git dependency declared without a version field; prototyping with path deps and forgetting to add versions before publishing.
Related errors
- files in the working directory contain changes that were…
- attempting to update a git repository, but
- can only edit absolute paths, got
- can't checkout from ' ': you are in the offline mode ( )
- cannot add ` ` as a dependency to itself
AI-assisted analysis of rust-lang/cargo@495c385d08 (2026-08-11).
Data as JSON: /api/errors/5d7d07f7d7967ec3.
Report an issue: GitHub.
Appendix: source
Thrown at src/ops/mod.rs:101
/// This check is performed on dependencies before publishing or packaging
fn check_dep_has_version(
dep: &crate::workspace::Dependency,
publish: bool,
) -> crate::CargoResult<bool> {
let which = if dep.source_id().is_path() {
"path"
} else if dep.source_id().is_git() {
"git"
} else {
return Ok(false);
};
if !dep.specified_req() && dep.is_transitive() {
let dep_version_source = dep.registry_id().map_or_else(
|| CRATES_IO_DOMAIN.to_string(),
|registry_id| registry_id.display_registry_name(),
);
anyhow::bail!(
"all dependencies must have a version requirement specified when {}.\n\
dependency `{}` does not specify a version\n\
Note: The {} dependency will use the version from {},\n\
the `{}` specification will be removed from the dependency declaration.",
if publish { "publishing" } else { "packaging" },
dep.package_name(),
if publish { "published" } else { "packaged" },
dep_version_source,
which,
)
}
Ok(true)
}
View on GitHub (pinned to 495c385d08)