Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
63 changes: 36 additions & 27 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -84,7 +84,7 @@ criterion = { version = "0.5", features = ["html_reports"] }
# must match the locked wasm-bindgen version (bump this, Cargo.lock and the
# runner pin in ci.yml together).
[target.'cfg(target_arch = "wasm32")'.dev-dependencies]
wasm-bindgen-test = "=0.3.71"
wasm-bindgen-test = "=0.3.79"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug medium

Version mismatch in .github/workflows/ci.yml: Cargo.toml now pins wasm-bindgen-test = "=0.3.79" and Cargo.lock resolves wasm-bindgen to 0.2.129, but line 88 still sets WASM_BINDGEN_VERSION to "0.2.121" with the old SHA256 on line 90. When the wasm32 job runs, the 'Guard wasm-bindgen lockfile drift' step (ci.yml lines 104-110) sees cargo pkgid wasm-bindgen = 0.2.129 ≠ 0.2.121 and exits 1, and even without the guard the 0.2.121 wasm-bindgen-test-runner rejects the 0.2.129 ABI, so the wasm32 ratio-product vector test never runs. Fix: in this PR, set WASM_BINDGEN_VERSION to "0.2.129" and WASM_BINDGEN_SHA256 to the checksum of the 0.2.129 release tarball, as the comment on lines 81-85 requires.

wasm-bindgen-test = "=0.3.79"
# and in .github/workflows/ci.yml:
#   WASM_BINDGEN_VERSION: "0.2.129"
#   WASM_BINDGEN_SHA256: "<sha256 of wasm-bindgen-0.2.129-x86_64-unknown-linux-musl.tar.gz>"
Prompt for LLM

File Cargo.toml:

Line 87:

Version mismatch in .github/workflows/ci.yml: Cargo.toml now pins `wasm-bindgen-test = "=0.3.79"` and Cargo.lock resolves wasm-bindgen to 0.2.129, but line 88 still sets WASM_BINDGEN_VERSION to "0.2.121" with the old SHA256 on line 90. When the wasm32 job runs, the 'Guard wasm-bindgen lockfile drift' step (ci.yml lines 104-110) sees `cargo pkgid wasm-bindgen` = 0.2.129 ≠ 0.2.121 and exits 1, and even without the guard the 0.2.121 wasm-bindgen-test-runner rejects the 0.2.129 ABI, so the wasm32 ratio-product vector test never runs. Fix: in this PR, set WASM_BINDGEN_VERSION to "0.2.129" and WASM_BINDGEN_SHA256 to the checksum of the 0.2.129 release tarball, as the comment on lines 81-85 requires.

Suggested Code:

wasm-bindgen-test = "=0.3.79"
# and in .github/workflows/ci.yml:
#   WASM_BINDGEN_VERSION: "0.2.129"
#   WASM_BINDGEN_SHA256: "<sha256 of wasm-bindgen-0.2.129-x86_64-unknown-linux-musl.tar.gz>"

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug medium

Stale cargo-vet exemptions in supply-chain/config.toml: lines 321-351 still exempt only 0.3.71, 0.2.121 and 0.4.71, while the new pin pulls in wasm-bindgen-test/-macro 0.3.79, wasm-bindgen* 0.2.129 and wasm-bindgen-futures 0.4.79. When the cargo vet step in .github/workflows/security.yml line 372 runs, it reports the new versions as unvetted and fails the security workflow. Fix: run cargo vet regenerate exemptions, or update those exemption entries to the newly locked versions.

wasm-bindgen-test = "=0.3.79"
# and update supply-chain/config.toml exemptions:
#   wasm-bindgen / -macro / -macro-support / -shared / -test-shared -> 0.2.129
#   wasm-bindgen-test / -test-macro -> 0.3.79
#   wasm-bindgen-futures -> 0.4.79
Prompt for LLM

File Cargo.toml:

Line 87:

Stale cargo-vet exemptions in supply-chain/config.toml: lines 321-351 still exempt only 0.3.71, 0.2.121 and 0.4.71, while the new pin pulls in wasm-bindgen-test/-macro 0.3.79, wasm-bindgen* 0.2.129 and wasm-bindgen-futures 0.4.79. When the `cargo vet` step in .github/workflows/security.yml line 372 runs, it reports the new versions as unvetted and fails the security workflow. Fix: run `cargo vet regenerate exemptions`, or update those exemption entries to the newly locked versions.

Suggested Code:

wasm-bindgen-test = "=0.3.79"
# and update supply-chain/config.toml exemptions:
#   wasm-bindgen / -macro / -macro-support / -shared / -test-shared -> 0.2.129
#   wasm-bindgen-test / -test-macro -> 0.3.79
#   wasm-bindgen-futures -> 0.4.79

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​


[features]
default = ["compression", "checksum", "messagepack"]
Expand Down
Loading