chore(deps): update all non-major dependencies - #79
cachekit-renovate-bot[bot] wants to merge 1 commit into
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: cachekit-io/cachekit-core/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
Kody Code Review — 4 suggested fixes. 🛠️ Open Agent Prompt |
|
|
||
| # wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets | ||
| getrandom = { version = "0.2", features = ["js"], optional = true } | ||
| getrandom = { version = "0.4", features = ["js"], optional = true } |
There was a problem hiding this comment.
Build break in the getrandom dependency in Cargo.toml: getrandom 0.4 has no js feature, which was renamed to wasm_js in 0.3, and it replaces getrandom::getrandom() with getrandom::fill(). When building with the encryption/wasm feature, Cargo rejects features = ["js"] during dependency resolution, and the wasm32 call getrandom::getrandom(&mut seed_bytes) at src/encryption/core.rs:92 no longer compiles. Fix: use features = ["wasm_js"], change core.rs:92 to getrandom::fill(&mut seed_bytes), and set the getrandom_backend="wasm_js" cfg flag for wasm32 targets, or keep getrandom at 0.2.
getrandom = { version = "0.4", features = ["wasm_js"], optional = true }Prompt for LLM
File Cargo.toml:
Line 49:
Build break in the getrandom dependency in Cargo.toml: getrandom 0.4 has no `js` feature, which was renamed to `wasm_js` in 0.3, and it replaces `getrandom::getrandom()` with `getrandom::fill()`. When building with the `encryption`/`wasm` feature, Cargo rejects `features = ["js"]` during dependency resolution, and the wasm32 call `getrandom::getrandom(&mut seed_bytes)` at src/encryption/core.rs:92 no longer compiles. Fix: use `features = ["wasm_js"]`, change core.rs:92 to `getrandom::fill(&mut seed_bytes)`, and set the `getrandom_backend="wasm_js"` cfg flag for wasm32 targets, or keep getrandom at 0.2.
Suggested Code:
getrandom = { version = "0.4", features = ["wasm_js"], optional = true }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
| aes-gcm = { version = "0.11", features = ["zeroize"], optional = true } | ||
| aes = { version = "0.9", features = ["zeroize"], optional = true } |
There was a problem hiding this comment.
API break in the aes-gcm/aes upgrade in Cargo.toml: aes-gcm 0.11 and aes 0.9 move from generic-array to hybrid-array, but src/encryption/core.rs:520 and :577 still call the 0.10 API AesGcmNonce::from_slice(...). Because these calls sit behind cfg(target_arch = "wasm32"), native CI passes while wasm32 builds fail on the encrypt and decrypt paths. Fix: keep aes-gcm at 0.10 and aes at 0.8, or construct the nonce with AesGcmNonce::try_from(&nonce_bytes[..]) in core.rs and add a wasm32 build to CI.
aes-gcm = { version = "0.10", features = ["zeroize"], optional = true }
aes = { version = "0.8", features = ["zeroize"], optional = true }Prompt for LLM
File Cargo.toml:
Line 52 to 53:
API break in the aes-gcm/aes upgrade in Cargo.toml: aes-gcm 0.11 and aes 0.9 move from generic-array to hybrid-array, but src/encryption/core.rs:520 and :577 still call the 0.10 API `AesGcmNonce::from_slice(...)`. Because these calls sit behind `cfg(target_arch = "wasm32")`, native CI passes while wasm32 builds fail on the encrypt and decrypt paths. Fix: keep aes-gcm at 0.10 and aes at 0.8, or construct the nonce with `AesGcmNonce::try_from(&nonce_bytes[..])` in core.rs and add a wasm32 build to CI.
Suggested Code:
aes-gcm = { version = "0.10", features = ["zeroize"], optional = true }
aes = { version = "0.8", features = ["zeroize"], optional = true }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
|
|
||
| # wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets | ||
| getrandom = { version = "0.2", features = ["js"], optional = true } | ||
| getrandom = { version = "0.4", features = ["js"], optional = true } |
There was a problem hiding this comment.
WHAT: getrandom jumps 0.2→0.4 while still enabling the "js" feature. WHY: getrandom 0.3+ removed the "js" feature in favor of "wasm_js" plus a cfg flag, so this may fail to build or silently break wasm RNG. The bump also has no audit evidence. HOW: verify the feature set against the 0.4 docs, attach cargo audit/OSV output, and update Cargo.lock.
Also found in:
Cargo.toml:43-43Cargo.toml:44-44Cargo.toml:33-33Cargo.toml:52-52Cargo.toml:53-53Cargo.toml:45-45
Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk
Prompt for LLM
File Cargo.toml:
Line 49:
WHAT: getrandom jumps 0.2→0.4 while still enabling the "js" feature. WHY: getrandom 0.3+ removed the "js" feature in favor of "wasm_js" plus a cfg flag, so this may fail to build or silently break wasm RNG. The bump also has no audit evidence. HOW: verify the feature set against the 0.4 docs, attach cargo audit/OSV output, and update Cargo.lock.
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
| sha2 = { version = "0.11", optional = true } | ||
| hmac = { version = "0.13", optional = true } | ||
| generic-array = { version = "0.14", optional = true } | ||
|
|
||
| # wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets | ||
| getrandom = { version = "0.2", features = ["js"], optional = true } | ||
| getrandom = { version = "0.4", features = ["js"], optional = true } | ||
|
|
||
| # RustCrypto: pure-Rust AES-256-GCM for wasm32 targets (ring requires clang + C asm) | ||
| aes-gcm = { version = "0.10", features = ["zeroize"], optional = true } | ||
| aes = { version = "0.8", features = ["zeroize"], optional = true } | ||
| aes-gcm = { version = "0.11", features = ["zeroize"], optional = true } |
There was a problem hiding this comment.
Version split between [dependencies] and [dev-dependencies] in Cargo.toml: sha2 and aes-gcm move to 0.11 in [dependencies], but [dev-dependencies] at lines 76-77 still pin sha2 = "0.10" and aes-gcm 0.10. When tests are built with --features encryption, the wire-format and cross-implementation tests run against a different major version than production uses. Fix: bump the dev-dependencies to sha2 = "0.11" and aes-gcm = { version = "0.11", features = ["zeroize"] }.
sha2 = { version = "0.11", optional = true }
# and in [dev-dependencies]:
# sha2 = "0.11"
# aes-gcm = { version = "0.11", features = ["zeroize"] }Prompt for LLM
File Cargo.toml:
Line 44 to 52:
Version split between [dependencies] and [dev-dependencies] in Cargo.toml: sha2 and aes-gcm move to 0.11 in [dependencies], but [dev-dependencies] at lines 76-77 still pin sha2 = "0.10" and aes-gcm 0.10. When tests are built with `--features encryption`, the wire-format and cross-implementation tests run against a different major version than production uses. Fix: bump the dev-dependencies to sha2 = "0.11" and aes-gcm = { version = "0.11", features = ["zeroize"] }.
Suggested Code:
sha2 = { version = "0.11", optional = true }
# and in [dev-dependencies]:
# sha2 = "0.11"
# aes-gcm = { version = "0.11", features = ["zeroize"] }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
fe19428 to
9faef17
Compare
|
|
||
| # wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets | ||
| getrandom = { version = "0.2", features = ["js"], optional = true } | ||
| getrandom = { version = "0.4", features = ["js"], optional = true } |
There was a problem hiding this comment.
Build break in Cargo.toml getrandom dependency: getrandom 0.4 has no js feature (0.3 replaced it with wasm_js, which also requires --cfg getrandom_backend="wasm_js") and renames the free function getrandom::getrandom to getrandom::fill. Cargo rejects the missing js feature during dependency resolution, so every build fails, native included; even with the feature renamed, getrandom::getrandom(&mut seed_bytes) at src/encryption/core.rs:92 fails to compile, and wasm32-unknown-unknown has no RNG backend without the cfg. Fix: keep getrandom at 0.2, or switch to features = ["wasm_js"], add getrandom_backend="wasm_js" to the wasm target rustflags, and change core.rs:92 to getrandom::fill(&mut seed_bytes).
getrandom = { version = "0.2", features = ["js"], optional = true }Prompt for LLM
File Cargo.toml:
Line 49:
Build break in Cargo.toml getrandom dependency: getrandom 0.4 has no `js` feature (0.3 replaced it with `wasm_js`, which also requires `--cfg getrandom_backend="wasm_js"`) and renames the free function `getrandom::getrandom` to `getrandom::fill`. Cargo rejects the missing `js` feature during dependency resolution, so every build fails, native included; even with the feature renamed, `getrandom::getrandom(&mut seed_bytes)` at src/encryption/core.rs:92 fails to compile, and wasm32-unknown-unknown has no RNG backend without the cfg. Fix: keep getrandom at 0.2, or switch to `features = ["wasm_js"]`, add `getrandom_backend="wasm_js"` to the wasm target rustflags, and change core.rs:92 to `getrandom::fill(&mut seed_bytes)`.
Suggested Code:
getrandom = { version = "0.2", features = ["js"], optional = true }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
|
|
||
| # wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets | ||
| getrandom = { version = "0.2", features = ["js"], optional = true } | ||
| getrandom = { version = "0.4", features = ["js"], optional = true } |
There was a problem hiding this comment.
WHAT: getrandom jumps two minor versions, from 0.2 to 0.4, and still enables the 'js' feature. WHY: getrandom 0.3+ removed the 'js' feature in favor of 'wasm_js' plus a cfg flag, so this may break the wasm32 build or its RNG. It is a risky upgrade with no audit evidence. HOW: Verify the feature set against the 0.4 docs, run cargo audit or OSV, and document the results.
Also found in:
Cargo.toml:43-43Cargo.toml:33-33Cargo.toml:53-53Cargo.toml:52-52Cargo.toml:44-44Cargo.toml:45-45
Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk
Prompt for LLM
File Cargo.toml:
Line 49:
WHAT: getrandom jumps two minor versions, from 0.2 to 0.4, and still enables the 'js' feature. WHY: getrandom 0.3+ removed the 'js' feature in favor of 'wasm_js' plus a cfg flag, so this may break the wasm32 build or its RNG. It is a risky upgrade with no audit evidence. HOW: Verify the feature set against the 0.4 docs, run cargo audit or OSV, and document the results.
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
| sha2 = { version = "0.11", optional = true } | ||
| hmac = { version = "0.13", optional = true } | ||
| generic-array = { version = "0.14", optional = true } | ||
|
|
||
| # wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets | ||
| getrandom = { version = "0.2", features = ["js"], optional = true } | ||
| getrandom = { version = "0.4", features = ["js"], optional = true } | ||
|
|
||
| # RustCrypto: pure-Rust AES-256-GCM for wasm32 targets (ring requires clang + C asm) | ||
| aes-gcm = { version = "0.10", features = ["zeroize"], optional = true } | ||
| aes = { version = "0.8", features = ["zeroize"], optional = true } | ||
| aes-gcm = { version = "0.11", features = ["zeroize"], optional = true } |
There was a problem hiding this comment.
Version split in Cargo.toml dev-dependencies: normal deps now use sha2 = "0.11" and aes-gcm = "0.11", but dev-dependencies still pin sha2 = "0.10" and aes-gcm = "0.10" (lines 72-73), so two semver-incompatible crates share the same extern name. When tests build with --features encryption, the use sha2::{Digest, Sha256} imports in tests/wire_format_vectors.rs:29 and tests/decode_bounds_vectors.rs:22 and the aes_gcm usage in tests/wasm32_compat_tests.rs:72 fail to build or compile against a different API than the library uses. Fix: bump the dev-dependency pins for sha2 and aes-gcm to 0.11.
# [dev-dependencies]
sha2 = "0.11"
aes-gcm = { version = "0.11", features = ["zeroize"] }Prompt for LLM
File Cargo.toml:
Line 44 to 52:
Version split in Cargo.toml dev-dependencies: normal deps now use `sha2 = "0.11"` and `aes-gcm = "0.11"`, but dev-dependencies still pin `sha2 = "0.10"` and `aes-gcm = "0.10"` (lines 72-73), so two semver-incompatible crates share the same extern name. When tests build with `--features encryption`, the `use sha2::{Digest, Sha256}` imports in tests/wire_format_vectors.rs:29 and tests/decode_bounds_vectors.rs:22 and the `aes_gcm` usage in tests/wasm32_compat_tests.rs:72 fail to build or compile against a different API than the library uses. Fix: bump the dev-dependency pins for `sha2` and `aes-gcm` to 0.11.
Suggested Code:
# [dev-dependencies]
sha2 = "0.11"
aes-gcm = { version = "0.11", features = ["zeroize"] }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
9faef17 to
2c80b64
Compare
This comment has been minimized.
This comment has been minimized.
2c80b64 to
91de3e4
Compare
|
|
||
| # wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets | ||
| getrandom = { version = "0.2", features = ["js"], optional = true } | ||
| getrandom = { version = "0.4", features = ["js"], optional = true } |
There was a problem hiding this comment.
Build break in the getrandom dependency (Cargo.toml line 49): the upgrade to getrandom 0.4 keeps the js feature and the getrandom::getrandom call, but getrandom 0.3 removed both, replacing them with the wasm_js feature (which requires --cfg getrandom_backend="wasm_js") and getrandom::fill. With encryption enabled, Cargo rejects the missing js feature, and on wasm32 src/encryption/core.rs:92 (getrandom::getrandom(&mut seed_bytes)) fails to compile, so the WASM_INSTANCE_COUNTER that seeds nonces cannot be built. Fix: stay on getrandom = { version = "0.2", features = ["js"] }, or switch to features = ["wasm_js"], add the backend cfg in .cargo/config.toml, and change core.rs:92 to getrandom::fill(&mut seed_bytes).
getrandom = { version = "0.2", features = ["js"], optional = true }Prompt for LLM
File Cargo.toml:
Line 49:
Build break in the getrandom dependency (Cargo.toml line 49): the upgrade to getrandom 0.4 keeps the `js` feature and the `getrandom::getrandom` call, but getrandom 0.3 removed both, replacing them with the `wasm_js` feature (which requires `--cfg getrandom_backend="wasm_js"`) and `getrandom::fill`. With `encryption` enabled, Cargo rejects the missing `js` feature, and on wasm32 src/encryption/core.rs:92 (`getrandom::getrandom(&mut seed_bytes)`) fails to compile, so the WASM_INSTANCE_COUNTER that seeds nonces cannot be built. Fix: stay on `getrandom = { version = "0.2", features = ["js"] }`, or switch to `features = ["wasm_js"]`, add the backend cfg in `.cargo/config.toml`, and change core.rs:92 to `getrandom::fill(&mut seed_bytes)`.
Suggested Code:
getrandom = { version = "0.2", features = ["js"], optional = true }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
|
|
||
| # wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets | ||
| getrandom = { version = "0.2", features = ["js"], optional = true } | ||
| getrandom = { version = "0.4", features = ["js"], optional = true } |
There was a problem hiding this comment.
Removed feature in the getrandom dependency (Cargo.toml): the jump from getrandom 0.2 to 0.4 keeps the js feature, but getrandom 0.3+ replaced it with wasm_js plus a getrandom_backend cfg flag. A wasm32 build with this manifest fails because Cargo cannot resolve the js feature. Fix: use features = ["wasm_js"], set the getrandom_backend cfg as documented, and update Cargo.lock.
Also found in:
Cargo.toml:43-43Cargo.toml:44-44Cargo.toml:52-52Cargo.toml:33-33Cargo.toml:45-45Cargo.toml:53-53
Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk
Prompt for LLM
File Cargo.toml:
Line 49:
Removed feature in the getrandom dependency (Cargo.toml): the jump from getrandom 0.2 to 0.4 keeps the `js` feature, but getrandom 0.3+ replaced it with `wasm_js` plus a `getrandom_backend` cfg flag. A wasm32 build with this manifest fails because Cargo cannot resolve the `js` feature. Fix: use `features = ["wasm_js"]`, set the `getrandom_backend` cfg as documented, and update Cargo.lock.
**Also found in:**
- `Cargo.toml:43-43`
- `Cargo.toml:44-44`
- `Cargo.toml:52-52`
- `Cargo.toml:33-33`
- `Cargo.toml:45-45`
- `Cargo.toml:53-53`
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
| hkdf = { version = "0.13", optional = true } | ||
| sha2 = { version = "0.11", optional = true } | ||
| hmac = { version = "0.13", optional = true } | ||
| generic-array = { version = "0.14", optional = true } | ||
|
|
||
| # wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets | ||
| getrandom = { version = "0.2", features = ["js"], optional = true } | ||
| getrandom = { version = "0.4", features = ["js"], optional = true } | ||
|
|
||
| # RustCrypto: pure-Rust AES-256-GCM for wasm32 targets (ring requires clang + C asm) | ||
| aes-gcm = { version = "0.10", features = ["zeroize"], optional = true } | ||
| aes = { version = "0.8", features = ["zeroize"], optional = true } | ||
| aes-gcm = { version = "0.11", features = ["zeroize"], optional = true } | ||
| aes = { version = "0.9", features = ["zeroize"], optional = true } |
There was a problem hiding this comment.
Version mismatch in the RustCrypto dependencies (Cargo.toml lines 43-53): aes-gcm and sha2 move to 0.11, but the dev-dependencies still pin aes-gcm 0.10 (line 73) and sha2 0.10 (line 72). aes-gcm 0.11 also replaces generic-array with hybrid-array, which breaks AesGcmNonce::from_slice at src/encryption/core.rs:501/558. When tests run with --features encryption, either the extern crate names clash or tests/wasm32_compat_tests.rs checks the wire format against a different aes-gcm major version than production uses, and on wasm32 the from_slice calls fail to compile. Fix: upgrade the dev-dependencies to aes-gcm 0.11 and sha2 0.11 and migrate the nonce construction to the hybrid-array API, or keep aes-gcm/aes at 0.10/0.8 until that code is migrated.
aes-gcm = { version = "0.10", features = ["zeroize"], optional = true }
aes = { version = "0.8", features = ["zeroize"], optional = true }Prompt for LLM
File Cargo.toml:
Line 43 to 53:
Version mismatch in the RustCrypto dependencies (Cargo.toml lines 43-53): aes-gcm and sha2 move to 0.11, but the dev-dependencies still pin aes-gcm 0.10 (line 73) and sha2 0.10 (line 72). aes-gcm 0.11 also replaces generic-array with hybrid-array, which breaks `AesGcmNonce::from_slice` at src/encryption/core.rs:501/558. When tests run with `--features encryption`, either the extern crate names clash or tests/wasm32_compat_tests.rs checks the wire format against a different aes-gcm major version than production uses, and on wasm32 the `from_slice` calls fail to compile. Fix: upgrade the dev-dependencies to aes-gcm 0.11 and sha2 0.11 and migrate the nonce construction to the hybrid-array API, or keep aes-gcm/aes at 0.10/0.8 until that code is migrated.
Suggested Code:
aes-gcm = { version = "0.10", features = ["zeroize"], optional = true }
aes = { version = "0.8", features = ["zeroize"], optional = true }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
91de3e4 to
a47440e
Compare
a47440e to
1d44b56
Compare
This PR contains the following updates:
0.29.2→0.29.41.0.228→1.0.2292.0.18→2.0.210.8.15→0.8.180.8.191.8.2→1.9.0Release Notes
mozilla/cbindgen (cbindgen)
v0.29.4Compare Source
v0.29.3Compare Source
* Fix doc attribute parsing to properly handle block comments
* Check for CMSE ABI's as well
* ci: Add a meta job to block the merge queue on it.
* Allow
pubaccess toReprTypefields* In C23 mode, define sized enums as enums rather than typedefs.
serde-rs/serde (serde)
v1.0.229Compare Source
dtolnay/thiserror (thiserror)
v2.0.21Compare Source
v2.0.20Compare Source
v2.0.19Compare Source
RustCrypto/utils (zeroize)
v1.9.0Compare Source
Configuration
📅 Schedule: (in timezone Australia/Sydney)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.