vectordotdev/vector · error
Cargo.lock was modified by `cargo
Error message
Cargo.lock was modified by `cargo {tool}`. Please commit the updated Cargo.lock. What it means
`vdev check rust` runs `cargo clippy`/`cargo fmt` (via `app::exec`) and then verifies `Cargo.lock` was not changed. If the lockfile differs before and after running the tool, it bails, because dependency resolution changes must be an explicit, committed change.
Solutions
- Run `cargo check` (or the tool named in the message) to regenerate the lockfile.
- Commit the updated `Cargo.lock` in the same change.
- Re-run `make check-clippy` / `make check-fmt`.
Defensive patterns
Strategy: validation
Validate before calling
git diff --exit-code Cargo.lock # must be empty after running clippy/fmt
Prevention
- Commit Cargo.lock together with any Cargo.toml change.
- Run `cargo check` before invoking clippy/fmt so the lock is already resolved.
- Keep a consistent cargo version across contributors and CI.
When it happens
Trigger: Running `cargo fmt` or `cargo clippy` resolves dependencies differently than the committed lockfile — e.g. new transitive deps available, version requirements unlocked, or Cargo.toml edited without updating the lock.
Common situations: Dependency added to Cargo.toml without `cargo check`/`cargo build` updating the lock first; `cargo update` artifacts missing from the commit; using a different cargo version that resolves differently.
Understand the failure class
Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.
Related errors
- duplicate upgrade-guide anchor '#
- expected package version
- Failed to build Vector for example validation
- invalid breaking fragment
- invalid breaking fragment
AI-assisted analysis of vectordotdev/vector@bdb87aeaa4 (2026-09-16).
Data as JSON: /api/errors/882d4d0455838030.
Report an issue: GitHub.
Appendix: source
Thrown at vdev/src/commands/check/rust.rs:81
.chain_args(feature_args)
.chain_args(pre_args)
}
pub fn exec(self) -> Result<()> {
let lock_file = paths::find_repo_root()?.join("Cargo.lock");
let lock_before = fs::read(&lock_file)?;
let tool = if self.clippy {
Tool::Clippy
} else {
Tool::Check
};
app::exec("cargo", self.build_args(tool), true)?;
let lock_after = fs::read(&lock_file)?;
if lock_before != lock_after {
bail!(
"Cargo.lock was modified by `cargo {tool}`. Please commit the updated Cargo.lock."
);
}
// If --fix was used, check for changes and commit them.
if self.fix {
let has_changes = !git::get_modified_files()?.is_empty();
if has_changes {
app::exec("cargo", ["fmt", "--all"], true)?;
git::commit("chore(vdev): apply vdev rust check fixes")?;
}
}
Ok(())
}
}
#[cfg(test)]View on GitHub (pinned to bdb87aeaa4)