Skip to content

chore(deps): keep cargo updates that cannot resolve out of the non-major Renovate group (LAB-6633) - #91

Merged
27Bslash6 merged 3 commits into
mainfrom
lab-6633-hold-getrandom
Sep 30, 2026
Merged

27Bslash6 merged 3 commits into
mainfrom
lab-6633-hold-getrandom

Conversation

@27Bslash6

@27Bslash6 27Bslash6 commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Renovate's all-minor-patch group has failed its Cargo.lock update since 2026-09-28, so no routine Rust update lands. This adds three packageRules to renovate.json so one update that cannot resolve no longer blocks the rest of the group.

Why the group breaks. Today's group bumps getrandom from 0.2 to 0.4 and keeps features = ["js"]. getrandom 0.3 removed that feature, so cargo update fails:

package `cachekit-core` depends on `getrandom` with feature `js` but `getrandom` does not have that feature.

That failure hides two more. Cargo treats a 0.x minor bump (0.12 to 0.14) as semver-incompatible, but Renovate classes it as minor and groups it. With getrandom left at 0.2, the group resolves but fails CI: aes 0.9.3 requires rustc 1.89, above this crate's 1.85 rust-version. The sha2 / aes-gcm bumps also leave [dev-dependencies] on 0.10, because dev-dependencies go to a separate group, so the test build sees two sha2 crates (E0464). Also, crypto-common 0.1 pins generic-array to exactly 0.14.7, so the group's generic-array 0.14.9 lock file update cannot resolve either. Renovate runs every lock file update in a group as one cargo update --precise chain, so any one failure fails the whole group.

Rule 1: cargo 0.x minor updates get their own PR (matchCurrentVersion: "<1.0.0", matchUpdateTypes: ["minor"], groupName: null). 0.x patch updates stay in the group. A crate's normal and dev-dependency bumps now share one branch, renovate/<crate>-0.x, so they move together.

Rule 2: hold getrandom at 0.2. ring 0.17 and rand_core 0.6 still depend on getrandom 0.2, and the direct 0.2 entry is what turns on js for that 0.2 copy on wasm32. Cargo unifies features per version, so a direct 0.4 entry would leave the 0.2 copy without it.

Rule 3: hold generic-array 0.14 patch updates until nothing depends on crypto-common 0.1.

Rules 2 and 3 set groupName: null and dependencyDashboardApproval: true, so the update waits under Pending Approval on the Dependency Dashboard and no branch opens for it. Vulnerability updates are not held, because Renovate forces dependencyDashboardApproval off for them. No rule sets allowedVersions: Renovate does not override that key for vulnerability updates, so it would silence them.

Checked with Renovate 43.288.0. The shared preset and this file were merged the way Renovate merges extends, deps were extracted from this repo's Cargo.toml and Cargo.lock by Renovate's cargo extractor, and each case ran through Renovate's own branchifyUpgrades:

Case main This branch
getrandom 0.2 → 0.4 (minor) in renovate/all-minor-patch, not held renovate/getrandom-0.x, held
serde minor, same run in renovate/all-minor-patch in renovate/all-minor-patch, not held
serde patch in renovate/all-minor-patch in renovate/all-minor-patch, not held
getrandom vulnerability update (GitHub alert and OSV) renovate/crate-getrandom-vulnerability, not held same, not held
getrandom 0.2.x patch in renovate/all-minor-patch in renovate/all-minor-patch
lz4_flex 0.12 → 0.13 (minor) in renovate/all-minor-patch renovate/lz4_flex-0.x, not held
lz4_flex 0.12.x patch in renovate/all-minor-patch in renovate/all-minor-patch
sha2 0.10 → 0.11, normal + dev dependency split across renovate/all-minor-patch and renovate/rust-dev-deps one branch, renovate/sha2-0.x
generic-array 0.14.7 → 0.14.9 in renovate/all-minor-patch own branch, held
generic-array vulnerability update not held not held

A --platform=local --dry-run=lookup run against crates.io agrees. On this branch renovate/all-minor-patch holds only the thiserror, serde, xxhash-rust, zeroize and cbindgen lock file updates. lz4_flex, hkdf, sha2, hmac, aes-gcm, aes, blake2 and criterion each get their own branch, and getrandom and generic-array wait for approval. Those five lock file updates, applied by hand with cargo update --precise, resolve and pass fmt, clippy, the stable and 1.85 test suites and cargo audit. renovate-config-validator --strict --no-global renovate.json passes.

This fixes the lock file update, not every check. The regenerated group will still fail cargo deny and cargo vet. thiserror 2.0.21 and serde 1.0.229 pull in syn 3 next to syn 2, and cbindgen 0.29.4 adds a second windows-sys, both of which multiple-versions = "deny" rejects. The new versions are also not yet vetted. Those are separate changes.

Summary

Adds a Renovate packageRules entry that removes generic-array patch updates from the non-major update group and requires manual approval via the Dependency Dashboard.

Changes

renovate.json: new rule scoped to:

  • matchManagers: cargo
  • matchPackageNames: generic-array
  • matchUpdateTypes: patch
  • groupName: null: excludes these updates from the grouped non-major PR.
  • dependencyDashboardApproval: true: updates wait under "Pending Approval" on the Dependency Dashboard.

Rationale

crypto-common 0.1, a dependency of the RustCrypto 0.10 crates, pins generic-array to exactly 0.14.7. Any other 0.14.x patch bump fails the Cargo.lock update. Because the bump is grouped with the other non-major updates, that failure blocks the entire group. Holding generic-array separately lets the rest of the group proceed.

Notes

  • Vulnerability updates are not held by this rule.
  • The rule's description says to remove it once nothing in Cargo.lock depends on crypto-common 0.1.
  • No public APIs or source code are modified. The change affects dependency automation configuration only.

getrandom 0.3 removed the js feature. The direct 0.2 entry exists to turn
that feature on for the getrandom 0.2 copy that ring and rand_core also use
on wasm32, so a bump past 0.2 fails the Cargo.lock update and blocks every
other update in the all-minor-patch group.

Take such an update out of the group and hold it under Pending Approval on
the Dependency Dashboard. Vulnerability updates are not held: Renovate
forces dependencyDashboardApproval off for them. Patch updates within 0.2
stay in the group.
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

Next included review available in 36 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: cachekit-io/cachekit-core/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: d9e75f0c-741f-4b30-86e2-86357a28d5c6

📥 Commits

Reviewing files that changed from the base of the PR and between dc1f719 and 778a58e.

📒 Files selected for processing (1)
  • renovate.json

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: cachekit-io/cachekit-core/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 922ce954-6107-447d-954f-0657e9784f4a

📥 Commits

Reviewing files that changed from the base of the PR and between 33c0f8a and dc1f719.

📒 Files selected for processing (1)
  • renovate.json

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

The Renovate configuration adds a Cargo package rule for minor and major getrandom updates. The rule sets groupName to null and enables dependency dashboard approval. Its description records the stated constraint, exception, and removal condition.

Changes

getrandom update configuration

Layer / File(s) Summary
Configure getrandom updates
renovate.json
A Cargo package rule matches minor and major getrandom updates, sets groupName to null, and enables dependency dashboard approval. The description records the stated constraint, vulnerability-update exception, and removal condition. The existing Renovate preset remains configured.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~5 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to dc1f7

Routine getrandom minor and major upgrades require dashboard approval while patch grouping and vulnerability remediation remain unaffected; no material merge blocker is indicated.

Security Architecture Review

Security architecture risk: 🔵 Low · up to dc1f7

The change is narrowly scoped to routine getrandom minor and major updates. It does not update application dependencies or add credentials or privileges. Available evidence supports preserving vulnerability-remediation updates, but the deployed approval and retry behavior has not been independently verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The direct exposure is this repository's dependency-update scheduling. The inspected change does not expand bot credentials, IAM permissions, network access, application runtime authority, or dependency versions.

Trust Boundaries and Controls

  • inferred — The rule adds an approval gate for routine matching updates without configuring a new approval identity. Prior documentation inspection and the reported simulation support vulnerability remediation bypassing that gate; the effective hosted configuration and recovery transitions remain a coverage gap, not a verified security failure.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarises the main change: it keeps breaking Cargo 0.x dependency updates out of the non-major Renovate group. It is concise, specific, and relevant to the getrandom rule.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@kodus-27b

kodus-27b Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

@27Bslash6 27Bslash6 changed the title fix(deps): hold getrandom at 0.2 out of the non-major Renovate group (LAB-6633) chore(deps): hold getrandom at 0.2 out of the non-major Renovate group (LAB-6633) Sep 30, 2026
kodus-27b[bot]
kodus-27b Bot previously approved these changes Sep 30, 2026
coderabbitai[bot]
coderabbitai Bot previously approved these changes Sep 30, 2026
Cargo treats a 0.x minor bump as semver-incompatible, but Renovate classes
it as minor and puts it in the all-minor-patch group. Holding getrandom was
not enough: reqwest 0.12 to 0.13 removed the rustls-tls feature and fails the
same Cargo.lock update, and other 0.x bumps in the group raise rust-version
past 1.85 or change APIs. Give every cargo 0.x minor update its own PR so one
breaking bump no longer blocks the routine ones. 0.x patch updates stay in
the group; the getrandom hold stays on top.
@27Bslash6 27Bslash6 changed the title chore(deps): hold getrandom at 0.2 out of the non-major Renovate group (LAB-6633) chore(deps): keep breaking cargo 0.x bumps out of the non-major Renovate group (LAB-6633) Sep 30, 2026
@kodus-27b

kodus-27b Bot commented Sep 30, 2026

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

kodus-27b[bot]
kodus-27b Bot previously approved these changes Sep 30, 2026
crypto-common 0.1 pins generic-array to exactly 0.14.7, so Renovate's
0.14.9 lock file update cannot resolve. Renovate runs every lock file update
in a group as one cargo chain, so this one failure would fail the whole
all-minor-patch group. Hold it under Pending Approval instead.
@27Bslash6 27Bslash6 changed the title chore(deps): keep breaking cargo 0.x bumps out of the non-major Renovate group (LAB-6633) chore(deps): keep cargo updates that cannot resolve out of the non-major Renovate group (LAB-6633) Sep 30, 2026
@kodus-27b

kodus-27b Bot commented Sep 30, 2026

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

@27Bslash6
27Bslash6 merged commit f68ca10 into main Sep 30, 2026
34 checks passed
@27Bslash6
27Bslash6 deleted the lab-6633-hold-getrandom branch September 30, 2026 11:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant