rust-lang/cargo · error

dependency ( ) specified without providing a local path…

Error message

dependency ({name_in_toml}) specified without providing a local path, Git repository, version, or workspace dependency to use

What it means

Thrown by dep_to_dependency (the parser-side dependency resolver) when a detailed dependency table has no version, path, or git field. This is the parser equivalent of the editor's missing-source error. It fires after converting a Simple version to a Detailed shape; if all three source fields are None, the dependency is unresolvable. Note this check does not account for workspace inheritance directly (that is handled upstream).

Solutions

  1. Add a 'version', 'path', or 'git' key to the dependency table.
  2. If using workspace inheritance, ensure 'workspace = true' is present and the workspace root defines the dependency.
  3. Check for misspelled keys (verison, pat) that prevent source detection.

Example fix

# before
[dependencies]
serde = { features = ["derive"] }

# after
[dependencies]
serde = { version = "1.0", features = ["derive"] }
Defensive patterns

Strategy: validation

Validate before calling

fn detailed_dep_has_source(d: &TomlDetailedDependency) -> bool {
    d.version.is_some() || d.path.is_some() || d.git.is_some()
}

Type guard

fn dep_table_has_source(table: &dyn toml_edit::TableLike) -> bool {
    ["version","path","git","workspace"].iter().any(|k| table.contains_key(*k))
}

Prevention

When it happens

Trigger: A [dependencies] entry that is a table (TomlDependency::Detailed) with orig.version, orig.path, and orig.git all None. For example { features = ["x"] } with no source. Reached via gather_dependencies and the replace/patch pipelines.

Common situations: A dependency table that relies on workspace inheritance but the inheritance was not resolved before reaching dep_to_dependency. A hand-written manifest missing the version. A migration that stripped source fields. A typo'd source key.

Related errors


AI-assisted analysis of rust-lang/cargo@98a09e7e7d (2026-08-11). Data as JSON: /api/errors/616d7d0d359f343e. Report an issue: GitHub.

Appendix: source

Thrown at src/workspace/parser/mod.rs:2259

    dep_to_dependency(config_patch, name, manifest_ctx, None)
}

fn dep_to_dependency<P: ResolveToPath + Clone>(
    orig: &manifest::TomlDependency<P>,
    name_in_toml: &str,
    manifest_ctx: &mut ManifestContext<'_, '_>,
    kind: Option<DepKind>,
) -> CargoResult<Dependency> {
    let orig = match orig {
        manifest::TomlDependency::Simple(version) => &manifest::TomlDetailedDependency::<P> {
            version: Some(version.clone()),
            ..Default::default()
        },
        manifest::TomlDependency::Detailed(details) => details,
    };

    if orig.version.is_none() && orig.path.is_none() && orig.git.is_none() {
        anyhow::bail!(
            "dependency ({name_in_toml}) specified without \
                 providing a local path, Git repository, version, or \
                 workspace dependency to use"
        );
    }

    if let Some(version) = &orig.version {
        if version.contains('+') {
            manifest_ctx.warnings.push(format!(
                "version requirement `{}` for dependency `{}` \
                     includes semver metadata which will be ignored, removing the \
                     metadata is recommended to avoid confusion",
                version, name_in_toml
            ));
        }
    }

    if orig.git.is_none() {

View on GitHub (pinned to 98a09e7e7d)