Skip to content

chore(deps): update all non-major dependencies - #79

Open
cachekit-renovate-bot[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

cachekit-renovate-bot[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@cachekit-renovate-bot

@cachekit-renovate-bot cachekit-renovate-bot Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

This PR contains the following updates:

Package Type Update Change Pending
cbindgen build-dependencies patch 0.29.2 → 0.29.4
serde (source) dependencies patch 1.0.228 → 1.0.229
thiserror dependencies patch 2.0.18 → 2.0.21
xxhash-rust dependencies patch 0.8.15 → 0.8.18 0.8.19
zeroize dependencies minor 1.8.2 → 1.9.0

Release Notes

mozilla/cbindgen (cbindgen)

v0.29.4

Compare Source

  • Support constant enums and arrays.

v0.29.3

Compare Source

  • Expose the line_endings config option to use with the builder
    * Fix doc attribute parsing to properly handle block comments
    * Check for CMSE ABI's as well
    * ci: Add a meta job to block the merge queue on it.
    * Allow pub access to ReprType fields
    * In C23 mode, define sized enums as enums rather than typedefs.
serde-rs/serde (serde)

v1.0.229

Compare Source

  • Update to syn 3
dtolnay/thiserror (thiserror)

v2.0.21

Compare Source

  • Fix parsing of generic unit variants in display expressions (#​459)

v2.0.20

Compare Source

  • Suppress redundant_field_names clippy lint in generated code (#​454)

v2.0.19

Compare Source

  • Update to syn 3
RustCrypto/utils (zeroize)

v1.9.0

Compare Source


Configuration

📅 Schedule: (in timezone Australia/Sydney)

  • Branch creation
    • "before 6am"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@cachekit-renovate-bot cachekit-renovate-bot Bot added the dependencies Pull requests that update a dependency file label Sep 28, 2026
@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: cachekit-io/cachekit-core/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 35423a18-ba03-43b5-95dc-4774343eda08

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@kodus-27b

kodus-27b Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

Kody Code Review — 4 suggested fixes.
Paste the prompt below to your agent and all review fixed at once!

🛠️ Open Agent Prompt
A code review identified the following issues in this pull request.
Each section describes what was found and includes a reference implementation where available.

Files involved:
- Cargo.toml:49
- Cargo.toml:53
- Cargo.toml:49
- Cargo.toml:52

---

### [1/4] Cargo.toml:49
Issue identified during code review:
Build break in the getrandom dependency in Cargo.toml: getrandom 0.4 has no `js` feature, which was renamed to `wasm_js` in 0.3, and it replaces `getrandom::getrandom()` with `getrandom::fill()`. When building with the `encryption`/`wasm` feature, Cargo rejects `features = ["js"]` during dependency resolution, and the wasm32 call `getrandom::getrandom(&mut seed_bytes)` at src/encryption/core.rs:92 no longer compiles. Fix: use `features = ["wasm_js"]`, change core.rs:92 to `getrandom::fill(&mut seed_bytes)`, and set the `getrandom_backend="wasm_js"` cfg flag for wasm32 targets, or keep getrandom at 0.2.
Reference implementation (from code review):

// Cargo.toml:49
getrandom = { version = "0.4", features = ["wasm_js"], optional = true }

---

### [2/4] Cargo.toml:53
Issue identified during code review:
API break in the aes-gcm/aes upgrade in Cargo.toml: aes-gcm 0.11 and aes 0.9 move from generic-array to hybrid-array, but src/encryption/core.rs:520 and :577 still call the 0.10 API `AesGcmNonce::from_slice(...)`. Because these calls sit behind `cfg(target_arch = "wasm32")`, native CI passes while wasm32 builds fail on the encrypt and decrypt paths. Fix: keep aes-gcm at 0.10 and aes at 0.8, or construct the nonce with `AesGcmNonce::try_from(&nonce_bytes[..])` in core.rs and add a wasm32 build to CI.
Reference implementation (from code review):

// Cargo.toml:53
aes-gcm = { version = "0.10", features = ["zeroize"], optional = true }
aes = { version = "0.8", features = ["zeroize"], optional = true }

---

### [3/4] Cargo.toml:49
Issue identified during code review:
WHAT: getrandom jumps 0.2→0.4 while still enabling the "js" feature. WHY: getrandom 0.3+ removed the "js" feature in favor of "wasm_js" plus a cfg flag, so this may fail to build or silently break wasm RNG. The bump also has no audit evidence. HOW: verify the feature set against the 0.4 docs, attach cargo audit/OSV output, and update Cargo.lock.

---

### [4/4] Cargo.toml:52
Issue identified during code review:
Version split between [dependencies] and [dev-dependencies] in Cargo.toml: sha2 and aes-gcm move to 0.11 in [dependencies], but [dev-dependencies] at lines 76-77 still pin sha2 = "0.10" and aes-gcm 0.10. When tests are built with `--features encryption`, the wire-format and cross-implementation tests run against a different major version than production uses. Fix: bump the dev-dependencies to sha2 = "0.11" and aes-gcm = { version = "0.11", features = ["zeroize"] }.
Reference implementation (from code review):

// Cargo.toml:52
sha2 = { version = "0.11", optional = true }
# and in [dev-dependencies]:
# sha2 = "0.11"
# aes-gcm = { version = "0.11", features = ["zeroize"] }

---

Review each issue in context, use the reference implementations as guidance, and apply fixes that are consistent with the surrounding codebase.

Comment thread Cargo.toml Outdated

# wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets
getrandom = { version = "0.2", features = ["js"], optional = true }
getrandom = { version = "0.4", features = ["js"], optional = true }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug high

Build break in the getrandom dependency in Cargo.toml: getrandom 0.4 has no js feature, which was renamed to wasm_js in 0.3, and it replaces getrandom::getrandom() with getrandom::fill(). When building with the encryption/wasm feature, Cargo rejects features = ["js"] during dependency resolution, and the wasm32 call getrandom::getrandom(&mut seed_bytes) at src/encryption/core.rs:92 no longer compiles. Fix: use features = ["wasm_js"], change core.rs:92 to getrandom::fill(&mut seed_bytes), and set the getrandom_backend="wasm_js" cfg flag for wasm32 targets, or keep getrandom at 0.2.

getrandom = { version = "0.4", features = ["wasm_js"], optional = true }
Prompt for LLM

File Cargo.toml:

Line 49:

Build break in the getrandom dependency in Cargo.toml: getrandom 0.4 has no `js` feature, which was renamed to `wasm_js` in 0.3, and it replaces `getrandom::getrandom()` with `getrandom::fill()`. When building with the `encryption`/`wasm` feature, Cargo rejects `features = ["js"]` during dependency resolution, and the wasm32 call `getrandom::getrandom(&mut seed_bytes)` at src/encryption/core.rs:92 no longer compiles. Fix: use `features = ["wasm_js"]`, change core.rs:92 to `getrandom::fill(&mut seed_bytes)`, and set the `getrandom_backend="wasm_js"` cfg flag for wasm32 targets, or keep getrandom at 0.2.

Suggested Code:

getrandom = { version = "0.4", features = ["wasm_js"], optional = true }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread Cargo.toml Outdated
Comment on lines +52 to +53
aes-gcm = { version = "0.11", features = ["zeroize"], optional = true }
aes = { version = "0.9", features = ["zeroize"], optional = true }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug high

API break in the aes-gcm/aes upgrade in Cargo.toml: aes-gcm 0.11 and aes 0.9 move from generic-array to hybrid-array, but src/encryption/core.rs:520 and :577 still call the 0.10 API AesGcmNonce::from_slice(...). Because these calls sit behind cfg(target_arch = "wasm32"), native CI passes while wasm32 builds fail on the encrypt and decrypt paths. Fix: keep aes-gcm at 0.10 and aes at 0.8, or construct the nonce with AesGcmNonce::try_from(&nonce_bytes[..]) in core.rs and add a wasm32 build to CI.

aes-gcm = { version = "0.10", features = ["zeroize"], optional = true }
aes = { version = "0.8", features = ["zeroize"], optional = true }
Prompt for LLM

File Cargo.toml:

Line 52 to 53:

API break in the aes-gcm/aes upgrade in Cargo.toml: aes-gcm 0.11 and aes 0.9 move from generic-array to hybrid-array, but src/encryption/core.rs:520 and :577 still call the 0.10 API `AesGcmNonce::from_slice(...)`. Because these calls sit behind `cfg(target_arch = "wasm32")`, native CI passes while wasm32 builds fail on the encrypt and decrypt paths. Fix: keep aes-gcm at 0.10 and aes at 0.8, or construct the nonce with `AesGcmNonce::try_from(&nonce_bytes[..])` in core.rs and add a wasm32 build to CI.

Suggested Code:

aes-gcm = { version = "0.10", features = ["zeroize"], optional = true }
aes = { version = "0.8", features = ["zeroize"], optional = true }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread Cargo.toml Outdated

# wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets
getrandom = { version = "0.2", features = ["js"], optional = true }
getrandom = { version = "0.4", features = ["js"], optional = true }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

WHAT: getrandom jumps 0.2→0.4 while still enabling the "js" feature. WHY: getrandom 0.3+ removed the "js" feature in favor of "wasm_js" plus a cfg flag, so this may fail to build or silently break wasm RNG. The bump also has no audit evidence. HOW: verify the feature set against the 0.4 docs, attach cargo audit/OSV output, and update Cargo.lock.

Also found in:

  • Cargo.toml:43-43
  • Cargo.toml:44-44
  • Cargo.toml:33-33
  • Cargo.toml:52-52
  • Cargo.toml:53-53
  • Cargo.toml:45-45

Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk

Prompt for LLM

File Cargo.toml:

Line 49:

WHAT: getrandom jumps 0.2→0.4 while still enabling the "js" feature. WHY: getrandom 0.3+ removed the "js" feature in favor of "wasm_js" plus a cfg flag, so this may fail to build or silently break wasm RNG. The bump also has no audit evidence. HOW: verify the feature set against the 0.4 docs, attach cargo audit/OSV output, and update Cargo.lock.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread Cargo.toml Outdated
Comment on lines +44 to +52
sha2 = { version = "0.11", optional = true }
hmac = { version = "0.13", optional = true }
generic-array = { version = "0.14", optional = true }

# wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets
getrandom = { version = "0.2", features = ["js"], optional = true }
getrandom = { version = "0.4", features = ["js"], optional = true }

# RustCrypto: pure-Rust AES-256-GCM for wasm32 targets (ring requires clang + C asm)
aes-gcm = { version = "0.10", features = ["zeroize"], optional = true }
aes = { version = "0.8", features = ["zeroize"], optional = true }
aes-gcm = { version = "0.11", features = ["zeroize"], optional = true }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug medium

Version split between [dependencies] and [dev-dependencies] in Cargo.toml: sha2 and aes-gcm move to 0.11 in [dependencies], but [dev-dependencies] at lines 76-77 still pin sha2 = "0.10" and aes-gcm 0.10. When tests are built with --features encryption, the wire-format and cross-implementation tests run against a different major version than production uses. Fix: bump the dev-dependencies to sha2 = "0.11" and aes-gcm = { version = "0.11", features = ["zeroize"] }.

sha2 = { version = "0.11", optional = true }
# and in [dev-dependencies]:
# sha2 = "0.11"
# aes-gcm = { version = "0.11", features = ["zeroize"] }
Prompt for LLM

File Cargo.toml:

Line 44 to 52:

Version split between [dependencies] and [dev-dependencies] in Cargo.toml: sha2 and aes-gcm move to 0.11 in [dependencies], but [dev-dependencies] at lines 76-77 still pin sha2 = "0.10" and aes-gcm 0.10. When tests are built with `--features encryption`, the wire-format and cross-implementation tests run against a different major version than production uses. Fix: bump the dev-dependencies to sha2 = "0.11" and aes-gcm = { version = "0.11", features = ["zeroize"] }.

Suggested Code:

sha2 = { version = "0.11", optional = true }
# and in [dev-dependencies]:
# sha2 = "0.11"
# aes-gcm = { version = "0.11", features = ["zeroize"] }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread Cargo.toml Outdated

# wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets
getrandom = { version = "0.2", features = ["js"], optional = true }
getrandom = { version = "0.4", features = ["js"], optional = true }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug high

Build break in Cargo.toml getrandom dependency: getrandom 0.4 has no js feature (0.3 replaced it with wasm_js, which also requires --cfg getrandom_backend="wasm_js") and renames the free function getrandom::getrandom to getrandom::fill. Cargo rejects the missing js feature during dependency resolution, so every build fails, native included; even with the feature renamed, getrandom::getrandom(&mut seed_bytes) at src/encryption/core.rs:92 fails to compile, and wasm32-unknown-unknown has no RNG backend without the cfg. Fix: keep getrandom at 0.2, or switch to features = ["wasm_js"], add getrandom_backend="wasm_js" to the wasm target rustflags, and change core.rs:92 to getrandom::fill(&mut seed_bytes).

getrandom = { version = "0.2", features = ["js"], optional = true }
Prompt for LLM

File Cargo.toml:

Line 49:

Build break in Cargo.toml getrandom dependency: getrandom 0.4 has no `js` feature (0.3 replaced it with `wasm_js`, which also requires `--cfg getrandom_backend="wasm_js"`) and renames the free function `getrandom::getrandom` to `getrandom::fill`. Cargo rejects the missing `js` feature during dependency resolution, so every build fails, native included; even with the feature renamed, `getrandom::getrandom(&mut seed_bytes)` at src/encryption/core.rs:92 fails to compile, and wasm32-unknown-unknown has no RNG backend without the cfg. Fix: keep getrandom at 0.2, or switch to `features = ["wasm_js"]`, add `getrandom_backend="wasm_js"` to the wasm target rustflags, and change core.rs:92 to `getrandom::fill(&mut seed_bytes)`.

Suggested Code:

getrandom = { version = "0.2", features = ["js"], optional = true }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread Cargo.toml Outdated

# wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets
getrandom = { version = "0.2", features = ["js"], optional = true }
getrandom = { version = "0.4", features = ["js"], optional = true }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

WHAT: getrandom jumps two minor versions, from 0.2 to 0.4, and still enables the 'js' feature. WHY: getrandom 0.3+ removed the 'js' feature in favor of 'wasm_js' plus a cfg flag, so this may break the wasm32 build or its RNG. It is a risky upgrade with no audit evidence. HOW: Verify the feature set against the 0.4 docs, run cargo audit or OSV, and document the results.

Also found in:

  • Cargo.toml:43-43
  • Cargo.toml:33-33
  • Cargo.toml:53-53
  • Cargo.toml:52-52
  • Cargo.toml:44-44
  • Cargo.toml:45-45

Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk

Prompt for LLM

File Cargo.toml:

Line 49:

WHAT: getrandom jumps two minor versions, from 0.2 to 0.4, and still enables the 'js' feature. WHY: getrandom 0.3+ removed the 'js' feature in favor of 'wasm_js' plus a cfg flag, so this may break the wasm32 build or its RNG. It is a risky upgrade with no audit evidence. HOW: Verify the feature set against the 0.4 docs, run cargo audit or OSV, and document the results.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread Cargo.toml Outdated
Comment on lines +44 to +52
sha2 = { version = "0.11", optional = true }
hmac = { version = "0.13", optional = true }
generic-array = { version = "0.14", optional = true }

# wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets
getrandom = { version = "0.2", features = ["js"], optional = true }
getrandom = { version = "0.4", features = ["js"], optional = true }

# RustCrypto: pure-Rust AES-256-GCM for wasm32 targets (ring requires clang + C asm)
aes-gcm = { version = "0.10", features = ["zeroize"], optional = true }
aes = { version = "0.8", features = ["zeroize"], optional = true }
aes-gcm = { version = "0.11", features = ["zeroize"], optional = true }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug medium

Version split in Cargo.toml dev-dependencies: normal deps now use sha2 = "0.11" and aes-gcm = "0.11", but dev-dependencies still pin sha2 = "0.10" and aes-gcm = "0.10" (lines 72-73), so two semver-incompatible crates share the same extern name. When tests build with --features encryption, the use sha2::{Digest, Sha256} imports in tests/wire_format_vectors.rs:29 and tests/decode_bounds_vectors.rs:22 and the aes_gcm usage in tests/wasm32_compat_tests.rs:72 fail to build or compile against a different API than the library uses. Fix: bump the dev-dependency pins for sha2 and aes-gcm to 0.11.

# [dev-dependencies]
sha2 = "0.11"
aes-gcm = { version = "0.11", features = ["zeroize"] }
Prompt for LLM

File Cargo.toml:

Line 44 to 52:

Version split in Cargo.toml dev-dependencies: normal deps now use `sha2 = "0.11"` and `aes-gcm = "0.11"`, but dev-dependencies still pin `sha2 = "0.10"` and `aes-gcm = "0.10"` (lines 72-73), so two semver-incompatible crates share the same extern name. When tests build with `--features encryption`, the `use sha2::{Digest, Sha256}` imports in tests/wire_format_vectors.rs:29 and tests/decode_bounds_vectors.rs:22 and the `aes_gcm` usage in tests/wasm32_compat_tests.rs:72 fail to build or compile against a different API than the library uses. Fix: bump the dev-dependency pins for `sha2` and `aes-gcm` to 0.11.

Suggested Code:

# [dev-dependencies]
sha2 = "0.11"
aes-gcm = { version = "0.11", features = ["zeroize"] }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

@kodus-27b

kodus-27b Bot commented Sep 29, 2026

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

@kodus-27b

This comment has been minimized.

Comment thread Cargo.toml Outdated

# wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets
getrandom = { version = "0.2", features = ["js"], optional = true }
getrandom = { version = "0.4", features = ["js"], optional = true }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug high

Build break in the getrandom dependency (Cargo.toml line 49): the upgrade to getrandom 0.4 keeps the js feature and the getrandom::getrandom call, but getrandom 0.3 removed both, replacing them with the wasm_js feature (which requires --cfg getrandom_backend="wasm_js") and getrandom::fill. With encryption enabled, Cargo rejects the missing js feature, and on wasm32 src/encryption/core.rs:92 (getrandom::getrandom(&mut seed_bytes)) fails to compile, so the WASM_INSTANCE_COUNTER that seeds nonces cannot be built. Fix: stay on getrandom = { version = "0.2", features = ["js"] }, or switch to features = ["wasm_js"], add the backend cfg in .cargo/config.toml, and change core.rs:92 to getrandom::fill(&mut seed_bytes).

getrandom = { version = "0.2", features = ["js"], optional = true }
Prompt for LLM

File Cargo.toml:

Line 49:

Build break in the getrandom dependency (Cargo.toml line 49): the upgrade to getrandom 0.4 keeps the `js` feature and the `getrandom::getrandom` call, but getrandom 0.3 removed both, replacing them with the `wasm_js` feature (which requires `--cfg getrandom_backend="wasm_js"`) and `getrandom::fill`. With `encryption` enabled, Cargo rejects the missing `js` feature, and on wasm32 src/encryption/core.rs:92 (`getrandom::getrandom(&mut seed_bytes)`) fails to compile, so the WASM_INSTANCE_COUNTER that seeds nonces cannot be built. Fix: stay on `getrandom = { version = "0.2", features = ["js"] }`, or switch to `features = ["wasm_js"]`, add the backend cfg in `.cargo/config.toml`, and change core.rs:92 to `getrandom::fill(&mut seed_bytes)`.

Suggested Code:

getrandom = { version = "0.2", features = ["js"], optional = true }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread Cargo.toml Outdated

# wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets
getrandom = { version = "0.2", features = ["js"], optional = true }
getrandom = { version = "0.4", features = ["js"], optional = true }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

Removed feature in the getrandom dependency (Cargo.toml): the jump from getrandom 0.2 to 0.4 keeps the js feature, but getrandom 0.3+ replaced it with wasm_js plus a getrandom_backend cfg flag. A wasm32 build with this manifest fails because Cargo cannot resolve the js feature. Fix: use features = ["wasm_js"], set the getrandom_backend cfg as documented, and update Cargo.lock.

Also found in:

  • Cargo.toml:43-43
  • Cargo.toml:44-44
  • Cargo.toml:52-52
  • Cargo.toml:33-33
  • Cargo.toml:45-45
  • Cargo.toml:53-53

Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk

Prompt for LLM

File Cargo.toml:

Line 49:

Removed feature in the getrandom dependency (Cargo.toml): the jump from getrandom 0.2 to 0.4 keeps the `js` feature, but getrandom 0.3+ replaced it with `wasm_js` plus a `getrandom_backend` cfg flag. A wasm32 build with this manifest fails because Cargo cannot resolve the `js` feature. Fix: use `features = ["wasm_js"]`, set the `getrandom_backend` cfg as documented, and update Cargo.lock.

**Also found in:**
- `Cargo.toml:43-43`
- `Cargo.toml:44-44`
- `Cargo.toml:52-52`
- `Cargo.toml:33-33`
- `Cargo.toml:45-45`
- `Cargo.toml:53-53`

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread Cargo.toml Outdated
Comment on lines +43 to +53
hkdf = { version = "0.13", optional = true }
sha2 = { version = "0.11", optional = true }
hmac = { version = "0.13", optional = true }
generic-array = { version = "0.14", optional = true }

# wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets
getrandom = { version = "0.2", features = ["js"], optional = true }
getrandom = { version = "0.4", features = ["js"], optional = true }

# RustCrypto: pure-Rust AES-256-GCM for wasm32 targets (ring requires clang + C asm)
aes-gcm = { version = "0.10", features = ["zeroize"], optional = true }
aes = { version = "0.8", features = ["zeroize"], optional = true }
aes-gcm = { version = "0.11", features = ["zeroize"], optional = true }
aes = { version = "0.9", features = ["zeroize"], optional = true }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug medium

Version mismatch in the RustCrypto dependencies (Cargo.toml lines 43-53): aes-gcm and sha2 move to 0.11, but the dev-dependencies still pin aes-gcm 0.10 (line 73) and sha2 0.10 (line 72). aes-gcm 0.11 also replaces generic-array with hybrid-array, which breaks AesGcmNonce::from_slice at src/encryption/core.rs:501/558. When tests run with --features encryption, either the extern crate names clash or tests/wasm32_compat_tests.rs checks the wire format against a different aes-gcm major version than production uses, and on wasm32 the from_slice calls fail to compile. Fix: upgrade the dev-dependencies to aes-gcm 0.11 and sha2 0.11 and migrate the nonce construction to the hybrid-array API, or keep aes-gcm/aes at 0.10/0.8 until that code is migrated.

aes-gcm = { version = "0.10", features = ["zeroize"], optional = true }
aes = { version = "0.8", features = ["zeroize"], optional = true }
Prompt for LLM

File Cargo.toml:

Line 43 to 53:

Version mismatch in the RustCrypto dependencies (Cargo.toml lines 43-53): aes-gcm and sha2 move to 0.11, but the dev-dependencies still pin aes-gcm 0.10 (line 73) and sha2 0.10 (line 72). aes-gcm 0.11 also replaces generic-array with hybrid-array, which breaks `AesGcmNonce::from_slice` at src/encryption/core.rs:501/558. When tests run with `--features encryption`, either the extern crate names clash or tests/wasm32_compat_tests.rs checks the wire format against a different aes-gcm major version than production uses, and on wasm32 the `from_slice` calls fail to compile. Fix: upgrade the dev-dependencies to aes-gcm 0.11 and sha2 0.11 and migrate the nonce construction to the hybrid-array API, or keep aes-gcm/aes at 0.10/0.8 until that code is migrated.

Suggested Code:

aes-gcm = { version = "0.10", features = ["zeroize"], optional = true }
aes = { version = "0.8", features = ["zeroize"], optional = true }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

@kodus-27b

kodus-27b Bot commented Sep 30, 2026

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant