chore(deps): update rust-dev-deps - #85
cachekit-renovate-bot[bot] wants to merge 1 commit into
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: cachekit-io/cachekit-core/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
Kody Code Review — 2 suggested fixes. 🛠️ Open Agent Prompt |
| proptest = "1.4" | ||
| serde_json = "1.0" | ||
| blake2 = "0.10" | ||
| blake2 = "0.11" |
There was a problem hiding this comment.
Unverified breaking bump in Cargo.toml: blake2 moves from 0.10 to 0.11, a semver-breaking change, without CVE/supply-chain evidence or an updated Cargo.lock. When only pre-release 0.11 versions are published, as was long the case across the RustCrypto stack, the bare "0.11" requirement fails to resolve and the build breaks. Fix: confirm a stable 0.11 release exists, attach cargo-audit or OSV output to the PR, and commit the updated Cargo.lock.
Also found in:
Cargo.toml:73-73Cargo.toml:72-72Cargo.toml:74-74
Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk
Prompt for LLM
File Cargo.toml:
Line 68:
Unverified breaking bump in Cargo.toml: `blake2` moves from 0.10 to 0.11, a semver-breaking change, without CVE/supply-chain evidence or an updated Cargo.lock. When only pre-release 0.11 versions are published, as was long the case across the RustCrypto stack, the bare `"0.11"` requirement fails to resolve and the build breaks. Fix: confirm a stable 0.11 release exists, attach cargo-audit or OSV output to the PR, and commit the updated Cargo.lock.
**Also found in:**
- `Cargo.toml:73-73`
- `Cargo.toml:72-72`
- `Cargo.toml:74-74`
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
| sha2 = "0.11" | ||
| aes-gcm = { version = "0.11", features = ["zeroize"] } |
There was a problem hiding this comment.
Version conflict in Cargo.toml [dev-dependencies]: sha2 and aes-gcm are bumped to 0.11, but [dependencies] still declares sha2 = "0.10" (line 44) and aes-gcm = "0.10" (line 52), and Cargo unifies a same-named dependency and dev-dependency into one extern crate, so ^0.10 and ^0.11 conflict. Running cargo test --features encryption either fails dependency resolution or gives rustc two candidates for sha2/aes_gcm. If 0.11 wins, Hkdf::<Sha256> in src/encryption/key_derivation.rs:109 breaks because hkdf 0.12 is built on digest 0.10, and tests/wasm32_compat_tests.rs:72-113 breaks on the 0.10 GenericArray Nonce::from_slice API. Fix: pin the dev-dependency versions to match production (0.10), or bump sha2/aes-gcm/aes/hkdf/hmac/generic-array together in [dependencies] and migrate the code.
sha2 = "0.10"
aes-gcm = { version = "0.10", features = ["zeroize"] }Prompt for LLM
File Cargo.toml:
Line 72 to 73:
Version conflict in Cargo.toml [dev-dependencies]: `sha2` and `aes-gcm` are bumped to 0.11, but [dependencies] still declares `sha2 = "0.10"` (line 44) and `aes-gcm = "0.10"` (line 52), and Cargo unifies a same-named dependency and dev-dependency into one extern crate, so ^0.10 and ^0.11 conflict. Running `cargo test --features encryption` either fails dependency resolution or gives rustc two candidates for `sha2`/`aes_gcm`. If 0.11 wins, `Hkdf::<Sha256>` in src/encryption/key_derivation.rs:109 breaks because hkdf 0.12 is built on digest 0.10, and tests/wasm32_compat_tests.rs:72-113 breaks on the 0.10 GenericArray `Nonce::from_slice` API. Fix: pin the dev-dependency versions to match production (0.10), or bump sha2/aes-gcm/aes/hkdf/hmac/generic-array together in [dependencies] and migrate the code.
Suggested Code:
sha2 = "0.10"
aes-gcm = { version = "0.10", features = ["zeroize"] }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
ec06f9d to
cdf1839
Compare
Code Review Could Not Complete
|
| Options | Enabled |
|---|---|
| Bug | ✅ |
| Performance | ✅ |
| Security | ✅ |
| Business Logic | ✅ |
This PR contains the following updates:
0.10→0.110.10→0.110.5→0.81.0.149→1.0.1510.10→0.11Release Notes
RustCrypto/AEADs (aes-gcm)
v0.11.1Compare Source
v0.11.0Compare Source
RustCrypto/hashes (blake2)
v0.11.0Compare Source
criterion-rs/criterion.rs (criterion)
v0.8.2Compare Source
Fixed
Other
v0.8.1Compare Source
Fixed
Other
v0.8.0Compare Source
BREAKING
Changed
Added
Throughput::ElementsAndBytesallows the text summary to report throughput in both units simultaneously.Fixed
Other
v0.7.0Compare Source
v0.6.0Compare Source
Changed
real_blackboxfeature no longer has any impact. Criterion always usesstd::hint::black_box()now.Users of
criterion::black_box()should switch tostd::hint::black_box().clapdependency unpinned.Fixed
Added
tokio::runtime::Handle, not only atokio::runtime::Runtimeserde-rs/json (serde_json)
v1.0.151Compare Source
v1.0.150Compare Source
Configuration
📅 Schedule: (in timezone Australia/Sydney)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.