Skip to content

chore(deps): update rust-dev-deps - #85

Open
cachekit-renovate-bot[bot] wants to merge 1 commit into
mainfrom
renovate/rust-dev-deps
Open

cachekit-renovate-bot[bot] wants to merge 1 commit into
mainfrom
renovate/rust-dev-deps

Conversation

@cachekit-renovate-bot

@cachekit-renovate-bot cachekit-renovate-bot Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
serde_json dev-dependencies patch 1.0.149 → 1.0.151
wasm-bindgen-test dev-dependencies patch =0.3.71 → =0.3.79

Release Notes

serde-rs/json (serde_json)

v1.0.151

Compare Source

v1.0.150

Compare Source


Configuration

📅 Schedule: (in timezone Australia/Sydney)

  • Branch creation
    • "before 6am"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@cachekit-renovate-bot cachekit-renovate-bot Bot added the dependencies Pull requests that update a dependency file label Sep 29, 2026
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: cachekit-io/cachekit-core/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 66d831b0-01c6-4a70-911b-0fe5c5269b82

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@kodus-27b

kodus-27b Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

Kody Code Review — 2 suggested fixes.
Paste the prompt below to your agent and all review fixed at once!

🛠️ Open Agent Prompt
A code review identified the following issues in this pull request.
Each section describes what was found and includes a reference implementation where available.

Files involved:
- Cargo.toml:68
- Cargo.toml:73

---

### [1/2] Cargo.toml:68
Issue identified during code review:
Unverified breaking bump in Cargo.toml: `blake2` moves from 0.10 to 0.11, a semver-breaking change, without CVE/supply-chain evidence or an updated Cargo.lock. When only pre-release 0.11 versions are published, as was long the case across the RustCrypto stack, the bare `"0.11"` requirement fails to resolve and the build breaks. Fix: confirm a stable 0.11 release exists, attach cargo-audit or OSV output to the PR, and commit the updated Cargo.lock.

**Also found in:**
- `Cargo.toml:73-73`
- `Cargo.toml:72-72`
- `Cargo.toml:74-74`

---

### [2/2] Cargo.toml:73
Issue identified during code review:
Version conflict in Cargo.toml [dev-dependencies]: `sha2` and `aes-gcm` are bumped to 0.11, but [dependencies] still declares `sha2 = "0.10"` (line 44) and `aes-gcm = "0.10"` (line 52), and Cargo unifies a same-named dependency and dev-dependency into one extern crate, so ^0.10 and ^0.11 conflict. Running `cargo test --features encryption` either fails dependency resolution or gives rustc two candidates for `sha2`/`aes_gcm`. If 0.11 wins, `Hkdf::<Sha256>` in src/encryption/key_derivation.rs:109 breaks because hkdf 0.12 is built on digest 0.10, and tests/wasm32_compat_tests.rs:72-113 breaks on the 0.10 GenericArray `Nonce::from_slice` API. Fix: pin the dev-dependency versions to match production (0.10), or bump sha2/aes-gcm/aes/hkdf/hmac/generic-array together in [dependencies] and migrate the code.
Reference implementation (from code review):

// Cargo.toml:73
sha2 = "0.10"
aes-gcm = { version = "0.10", features = ["zeroize"] }

---

Review each issue in context, use the reference implementations as guidance, and apply fixes that are consistent with the surrounding codebase.

Comment thread Cargo.toml Outdated
Comment thread Cargo.toml Outdated
@kodus-27b

This comment has been minimized.

Comment thread Cargo.toml Outdated
Comment thread Cargo.toml Outdated
@kodus-27b

kodus-27b Bot commented Sep 30, 2026

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

@cachekit-renovate-bot cachekit-renovate-bot Bot changed the title chore(deps): update rust-dev-deps chore(deps): update rust crate serde_json to v1.0.151 Sep 30, 2026
@cachekit-renovate-bot cachekit-renovate-bot Bot changed the title chore(deps): update rust crate serde_json to v1.0.151 chore(deps): update rust-dev-deps Oct 3, 2026
Comment thread Cargo.toml
# runner pin in ci.yml together).
[target.'cfg(target_arch = "wasm32")'.dev-dependencies]
wasm-bindgen-test = "=0.3.71"
wasm-bindgen-test = "=0.3.79"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug medium

Version mismatch in .github/workflows/ci.yml: Cargo.toml now pins wasm-bindgen-test = "=0.3.79" and Cargo.lock resolves wasm-bindgen to 0.2.129, but line 88 still sets WASM_BINDGEN_VERSION to "0.2.121" with the old SHA256 on line 90. When the wasm32 job runs, the 'Guard wasm-bindgen lockfile drift' step (ci.yml lines 104-110) sees cargo pkgid wasm-bindgen = 0.2.129 ≠ 0.2.121 and exits 1, and even without the guard the 0.2.121 wasm-bindgen-test-runner rejects the 0.2.129 ABI, so the wasm32 ratio-product vector test never runs. Fix: in this PR, set WASM_BINDGEN_VERSION to "0.2.129" and WASM_BINDGEN_SHA256 to the checksum of the 0.2.129 release tarball, as the comment on lines 81-85 requires.

wasm-bindgen-test = "=0.3.79"
# and in .github/workflows/ci.yml:
#   WASM_BINDGEN_VERSION: "0.2.129"
#   WASM_BINDGEN_SHA256: "<sha256 of wasm-bindgen-0.2.129-x86_64-unknown-linux-musl.tar.gz>"
Prompt for LLM

File Cargo.toml:

Line 87:

Version mismatch in .github/workflows/ci.yml: Cargo.toml now pins `wasm-bindgen-test = "=0.3.79"` and Cargo.lock resolves wasm-bindgen to 0.2.129, but line 88 still sets WASM_BINDGEN_VERSION to "0.2.121" with the old SHA256 on line 90. When the wasm32 job runs, the 'Guard wasm-bindgen lockfile drift' step (ci.yml lines 104-110) sees `cargo pkgid wasm-bindgen` = 0.2.129 ≠ 0.2.121 and exits 1, and even without the guard the 0.2.121 wasm-bindgen-test-runner rejects the 0.2.129 ABI, so the wasm32 ratio-product vector test never runs. Fix: in this PR, set WASM_BINDGEN_VERSION to "0.2.129" and WASM_BINDGEN_SHA256 to the checksum of the 0.2.129 release tarball, as the comment on lines 81-85 requires.

Suggested Code:

wasm-bindgen-test = "=0.3.79"
# and in .github/workflows/ci.yml:
#   WASM_BINDGEN_VERSION: "0.2.129"
#   WASM_BINDGEN_SHA256: "<sha256 of wasm-bindgen-0.2.129-x86_64-unknown-linux-musl.tar.gz>"

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread Cargo.toml
# runner pin in ci.yml together).
[target.'cfg(target_arch = "wasm32")'.dev-dependencies]
wasm-bindgen-test = "=0.3.71"
wasm-bindgen-test = "=0.3.79"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug medium

Stale cargo-vet exemptions in supply-chain/config.toml: lines 321-351 still exempt only 0.3.71, 0.2.121 and 0.4.71, while the new pin pulls in wasm-bindgen-test/-macro 0.3.79, wasm-bindgen* 0.2.129 and wasm-bindgen-futures 0.4.79. When the cargo vet step in .github/workflows/security.yml line 372 runs, it reports the new versions as unvetted and fails the security workflow. Fix: run cargo vet regenerate exemptions, or update those exemption entries to the newly locked versions.

wasm-bindgen-test = "=0.3.79"
# and update supply-chain/config.toml exemptions:
#   wasm-bindgen / -macro / -macro-support / -shared / -test-shared -> 0.2.129
#   wasm-bindgen-test / -test-macro -> 0.3.79
#   wasm-bindgen-futures -> 0.4.79
Prompt for LLM

File Cargo.toml:

Line 87:

Stale cargo-vet exemptions in supply-chain/config.toml: lines 321-351 still exempt only 0.3.71, 0.2.121 and 0.4.71, while the new pin pulls in wasm-bindgen-test/-macro 0.3.79, wasm-bindgen* 0.2.129 and wasm-bindgen-futures 0.4.79. When the `cargo vet` step in .github/workflows/security.yml line 372 runs, it reports the new versions as unvetted and fails the security workflow. Fix: run `cargo vet regenerate exemptions`, or update those exemption entries to the newly locked versions.

Suggested Code:

wasm-bindgen-test = "=0.3.79"
# and update supply-chain/config.toml exemptions:
#   wasm-bindgen / -macro / -macro-support / -shared / -test-shared -> 0.2.129
#   wasm-bindgen-test / -test-macro -> 0.3.79
#   wasm-bindgen-futures -> 0.4.79

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

@kodus-27b

kodus-27b Bot commented Oct 3, 2026

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant