vectordotdev/vector · error

Cargo.lock was modified by `cargo

Error message

Cargo.lock was modified by `cargo {tool}`. Please commit the updated Cargo.lock.

What it means

`vdev check rust` runs `cargo clippy`/`cargo fmt` (via `app::exec`) and then verifies `Cargo.lock` was not changed. If the lockfile differs before and after running the tool, it bails, because dependency resolution changes must be an explicit, committed change.

Solutions

  1. Run `cargo check` (or the tool named in the message) to regenerate the lockfile.
  2. Commit the updated `Cargo.lock` in the same change.
  3. Re-run `make check-clippy` / `make check-fmt`.
Defensive patterns

Strategy: validation

Validate before calling

git diff --exit-code Cargo.lock # must be empty after running clippy/fmt

Prevention

When it happens

Trigger: Running `cargo fmt` or `cargo clippy` resolves dependencies differently than the committed lockfile — e.g. new transitive deps available, version requirements unlocked, or Cargo.toml edited without updating the lock.

Common situations: Dependency added to Cargo.toml without `cargo check`/`cargo build` updating the lock first; `cargo update` artifacts missing from the commit; using a different cargo version that resolves differently.

Understand the failure class

Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.

Related errors


AI-assisted analysis of vectordotdev/vector@bdb87aeaa4 (2026-09-16). Data as JSON: /api/errors/882d4d0455838030. Report an issue: GitHub.

Appendix: source

Thrown at vdev/src/commands/check/rust.rs:81

            .chain_args(feature_args)
            .chain_args(pre_args)
    }

    pub fn exec(self) -> Result<()> {
        let lock_file = paths::find_repo_root()?.join("Cargo.lock");
        let lock_before = fs::read(&lock_file)?;

        let tool = if self.clippy {
            Tool::Clippy
        } else {
            Tool::Check
        };

        app::exec("cargo", self.build_args(tool), true)?;

        let lock_after = fs::read(&lock_file)?;
        if lock_before != lock_after {
            bail!(
                "Cargo.lock was modified by `cargo {tool}`. Please commit the updated Cargo.lock."
            );
        }

        // If --fix was used, check for changes and commit them.
        if self.fix {
            let has_changes = !git::get_modified_files()?.is_empty();
            if has_changes {
                app::exec("cargo", ["fmt", "--all"], true)?;
                git::commit("chore(vdev): apply vdev rust check fixes")?;
            }
        }

        Ok(())
    }
}

#[cfg(test)]

View on GitHub (pinned to bdb87aeaa4)