Skip to content

chore(deps): update all non-major dependencies - #91

Open
cachekit-renovate-bot[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

cachekit-renovate-bot[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@cachekit-renovate-bot

@cachekit-renovate-bot cachekit-renovate-bot Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
bytes dependencies minor 1.11.1 → 1.12.1
libc dependencies patch 0.2.183 → 0.2.189
moka dependencies patch 0.12.14 → 0.12.16
proc-macro2 dependencies patch 1.0.106 → 1.0.107
quote dependencies patch 1.0.45 → 1.0.47
rustix dependencies patch 1.1.4 → 1.1.5
serde (source) dependencies patch 1.0.228 → 1.0.229
serde_json dependencies patch 1.0.149 → 1.0.151
syn dependencies patch 2.0.117 → 2.0.119
thiserror dependencies patch 2.0.18 → 2.0.21
tokio (source) dependencies minor 1.50.0 → 1.53.1
uuid dependencies minor 1.22.0 → 1.26.1
zeroize dependencies minor 1.8.2 → 1.9.0

Release Notes

tokio-rs/bytes (bytes)

v1.12.1

Compare Source

Fixed
  • Properly handle when Box::new panics (#​837)

v1.12.0

Compare Source

Added
  • Add BytesMut::extend_from_within() (#​818)
  • Add BytesMut::try_unsplit() (#​746)
Fixed
  • Fix panic in get_int if nbytes is zero (#​806)
Changed
  • Pass vtable data by value (#​826)
  • Exclude development scripts from published package (#​810)
Documented
  • Document that BytesMut::{reserve,try_reserve} doesn't preserve unused capacity (#​808)
rust-lang/libc (libc)

v0.2.189

Compare Source

Added
  • Emscripten: Add pthread_sigmask, sigwait, sigwaitinfo, sigtimedwait, faccessat, and pthread_kill (#​5270)
  • Linux SPARC: Enable the clone3 syscall (#​4980)
  • Solarish: Add CLOCK_PROCESS_CPUTIME_ID and CLOCK_THREAD_CPUTIME_ID (#​5274)
Deprecated
  • Deprecate CLONE_INTO_CGROUP and CLONE_CLEAR_SIGHAND. These overflow their types and will be changed to a larger size in the future. (8c6e6710458d)
Fixed
  • Musl riscv32: Rename padding fields to avoid a conflict and fix the build (2499ff0ad993)
  • NuttX: Fix wchar_t definition under Arm (#​5245)
  • Windows: Add back link names for time-related symbols (#​5300)

v0.2.188

Compare Source

Changed

These were removed in 0.2.187 because libc does not actually make Send and Sync
guarantees about DIR (or other extern types), but this caused some crates to break.
The traits are added back for now to allow time to migrate, but will be removed again
in the future; please make sure your crates are not relying on libc::DIR: Send or
libc::DIR: Sync.

v0.2.187

Compare Source

This release contains a number of improvements related to 64-bit time_t configuration.
Of note the existing RUST_LIBC_UNSTABLE_* environment variables have been replaced
with configuration options. The new way to use these is:

RUSTFLAGS='--cfg=libc_unstable_musl_v1_2_3' cargo ...
RUSTFLAGS='--cfg=libc_unstable_gnu_time_bits="64"' cargo ...

Being able to set this via RUSTFLAGS makes it easier to only apply configuration to
specific targets (and notably, not the host if build scripts are used).

There are two other notable changes:

  • The 32-bit windows-gnu targets now respect libc_unstable_gnu_time_bits

  • uClibc now supports a similar configuration option:

    RUSTFLAGS='--cfg=libc_unstable_uclibc_time64'

As a reminder, these options are under active development and may change in the future
(hence the "unstable" in the name). It likely that we will harmonize everything under a
single configuration option before considering them stable.

Support
  • Add support for aarch64-unknown-linux-pauthtest (#​5065)
  • Add support for new QNX targets (#​5241)
  • Better document breaking change policy and recommended usage (#​5179)
Added
  • Android: Add POSIX_SPAWN_* constants (#​5104)
  • Android: Add getpwent, setpwent, and endpwent (#​5160)
  • Android: Add preadv2 and pwritev2 (#​5157)
  • Android: Add seccomp_notif* structures (#​5224)
  • Android: Add timer_[create, delete, getoverrun, gettime, settime] (#​5108)
  • Apple: Add PROC_PIDT_SHORTBSDINFO and proc_bsdshortinfo (#​5110)
  • Apple: Add SIOC* constants from sockio.h (#​5263)
  • Apple: Add _IOR, _IOW, _IOWR (#​5264)
  • Apple: Add bpf_program and bpf_insn (#​5235)
  • Apple: Add additional kqueue constants (#​5077)
  • Apple: Update vm_statistics64 with recently added fields (#​5253)
  • Apple: add IN6_IFF_* and SIOCGIFAFLAG_IN6 (#​5239)
  • Dragonfly: Add O_*, POSIX_FADV_*, NI*, and a few other missing constants (#​5116)
  • Dragonfly: add fdatasync, dlvsym, reallocarray, qsort_r, pthread_*affinity_np, ftok, extattr_*, and dup3 (#​5116)
  • Emscripten: Add in6_pktinfo (#​5256)
  • FreeBSD: Add SOL_LOCAL (#​5185)
  • FreeBSD: Add DLT_* constants (#​5235)
  • FreeBSD: Add PROC_LOGSIGEXIT_* and PPROT_* (#​4657)
  • FreeBSD: Add SO_RERROR (#​5260)
  • FreeBSD: add IN6_IFF_*, in6_ifreq, and SIOCGIFAFLAG_IN6 (#​5239)
  • FreeBSD: add _IO* helpers from sys/ioccom.h (#​5239)
  • Glibc: Add PTHREAD_*_MUTEX_INITIALIZER_NP for riscv64 (#​5094)
  • Glibc: Add new fields to struct tcp_info (#​5215)
  • Linux: Add OPEN_TREE_NAMESPACE (#​5145)
  • Linux: Add SECCOMP_IOCTL_* constants (#​5224)
  • Linux: Add SO_DETACH_REUSEPORT_BPF (#​5081)
  • Linux: Add futex_waitv (#​5125)
  • Linux: Add constants for fsopen, fsconfig, fsmount, and fspick (#​5145)
  • Linux: Add fields to statx present since 6.16 (#​4621)
  • Linux: Add network entry API (#​5049)
  • Linux: add ifaddrmsg and rtattr (#​5234)
  • Linux: add sockaddr_iucv (#​5041)
  • MacOS: Add ENOTCAPABLE (#​4925)
  • Musl: Add renameat2 (#​5113)
  • NuttX: Add F_SETFD (#​5258)
  • NuttX: Add POLLRD* and POLLWR* constants (#​5258)
  • NuttX: Add SO_KEEPALIVE and TCP keepalive constants (#​5111)
  • NuttX: Add TCP_MAXSEG (#​5258)
  • NuttX: Add eventfd and EFD_* constants (#​5258)
  • NuttX: Add pipe2 (#​5258)
  • NuttX: Add strerror_r (#​5258)
  • NuttX: Add netinet structs and constants (#​5258)
  • NuttX: Add socket structs, functions and constants (#​5258)
  • QuRT: Add POSIX timer functions (#​5091)
  • QuRT: Add missing pthread functions from QuRT SDK headers (#​5091)
  • QuRT: Add missing unistd process and file functions (#​5091)
  • QuRT: Add mqueue subsystem (message queues, select/pselect) (#​5091)
  • Redox: Add *at and dirent functions (#​5117)
  • Solarish: Add IP TTL and IPv6 Hop Limit consts (#​5089)
  • Solarish: Add port_alert and PORT_ALERT* constants (#​5203)
  • Solarish: add AI_CANONNAME (#​5085)
  • aarch64: Add SYS_sendfile and SYS_fadvise64 constants (#​5133)
Deprecated
  • Dragonfly: Deprecate compatibility aliases CPUCTL_RSMSR and UTX_DB_LASTLOG (#​5116)
Fixed
  • breaking NetBSD: Correct ts from *const timespec to *mut timespec in _lwp_park` (#​5169)
  • breaking Linux GNU: Change overflowing PTRACE_*ET_SYSCALL_USER_DISPATCH_CONFIG constants from u8 to c_uint (#​4936)
  • Fix the soundness bug in the representation of extern types (#​5021)
  • Cygwin: fix cpuset_t typo in CPU_ZERO (#​5098)
  • Dragonfly: ABI fixes including regex offsets, ifaddrs, pthread barriers, process sizing fields, and mcontext alignment (#​5116)
  • Dragonfly: Correct values of CPUCTL_CPUID*, EV_HUP, and EV_SYSFLAGS (#​5116)
  • Emscripten: fix pthread type sizes for wasm64 (MEMORY64) (#​5156)
  • Horizon: Fix the value of POLLOUT (#​5090)
  • Linux: Correct the value of EPIOC[GS]PARAMS with nonstandard _IOC (#​5188)
  • Make VxWorks shims unsafe (#​3727)
  • NetBSD: Correct getmntinfo to link __getmntinfo13 (#​5251)
  • QNX: Fix the value of PTHREAD_MUTEX_INITIALIZER (#​5241)
  • QuRT: fix type and definition inaccuracies against SDK headers (#​5091)
  • Windows: Correctly link to 32-bit time routines on 32-bit platforms (#​5059)
  • uClibc: Fix constants accidentally removed (#​5141)
  • uclibc: Fix build issues (#​5046)
  • uclibc: Fix type of PRIO_PROCESS and friends (#​5046)
Changed
  • AIX, TeeOS: Drop unneeded -> c_void (#​5240)
  • Apple: Change AIO_LISTIO_MAX to account for changes in macOS 27 (#​5253)
  • Glibc: Update the value of MS_NOUSER (#​5215)
  • L4Re: Update definitions and test infra (#​5275)
  • Linux: Update the value of SW_MAX and SW_CNT (#​5215)
  • MacOS: Add swapped_count to vm_statistics64 (#​4926)
  • Windows: Windows-GNU now respects libc_unstable_gnu_time_bits for 64-bit time_t config (#​5062)
Removed
  • Dragonfly: Remove FreeBSD-only Elf32_Lword, ip_mreq_source, and IP_ constants (#​5116)
  • Dragonfly: Remove private VM type bindings (#​5116)
  • Linux: Remove KERN_REALROOTDEV and VM_LAPTOP_MODE (#​5177)
  • VxWorks: Remove non-user-facing (kernel) API (#​5129)
Other
  • Print config information if LIBC_BUILD_VERBOSE is set (#​5272)
  • Annotate *LAST constants as potentially changing (#​5120)
  • Annotate *MAX constants as potentially changing (#​5122)
  • BSD: Annotate ELAST constants as potentially changing (#​5118)
  • FreeBSD: Annotate RAND_MAX as potentially changing (#​5119)
  • Linux, L4re: Annotate *NUM constants as potentially changing (#​5123)
  • QNX: Restructure to support new platforms (#​4984)
  • Unix: Annotate *COUNT constants as potentially changing (#​5121)
  • uClibc: Add unstable support of 64-bit time_t (#​5046)
  • (internal) FreeBSD: Replace unstable env to set version with an unstable cfg (#​5201)
  • (internal) Glibc: Remove public configuration for file offset bits (#​5268)
  • (internal) Linux: Delete config via RUST_LIBC_UNSTABLE_LINUX_TIME_BITS64 (#​5197)
  • (internal) Replace RUST_LIBC_UNSTABLE env with libc_unstable* cfg (#​4977)

v0.2.186

Compare Source

Added
  • Apple: Add KEVENT_FLAG_* constants (#​5070)
  • Linux: Add PR_SET_MEMORY_MERGE and PR_GET_MEMORY_MERGE (#​5060)
Changed
  • CI: Migrate FreeBSD CI from Cirrus CI to GitHub Actions (#​5058)

v0.2.185

Compare Source

Added
  • EspIDF: Add espidf_picolibc cfg for picolibc O_* flag values (#​5035)
  • Hexagon: add missing constants and fix types for linux-musl (#​5042)
  • Redox: Add semaphore functions (#​5051)
  • Windows: Add sprintf, snprintf, and the scanf family (#​5024)
Fixed
  • Hexagon: Decouple time64 types from musl symbol redirects (#​5040)
  • Horizon: Change POLL constants from c_short to c_int (#​5045)

v0.2.184

Compare Source

MSRV

This release increases the MSRV of libc to 1.65. With this update, you can now always use the
core::ffi::c_* types with libc definitions, since libc has been changed to reexport from
core rather than redefining them. (This usually worked before but had edge cases.)
(#​4972)

Added
  • BSD: Add IP_MINTTL to bsd (#​5026)
  • Cygwin: Add TIOCM_DSR (#​5031)
  • FreeBSD: Added xfile structe and file descriptor types (#​5002)
  • Linux: Add CAN netlink bindings (#​5011)
  • Linux: Add struct ethhdr (#​4239)
  • Linux: Add struct ifinfomsg (#​5012)
  • Linux: Define max_align_t for riscv64 (#​5029)
  • NetBSD: Add missing CLOCK_ constants (#​5020)
  • NuttX: Add _SC_HOST_NAME_MAX (#​5004)
  • VxWorks: Add flock and F_*LCK constants (#​4043)
  • WASI: Add all _SC_* sysconf constants (#​5023)
Deprecated

The remaining fixed-width integer aliases, __uint128_t, __uint128, __int128_t, and __int128,
have been deprecated. Use i128 and u128 instead. (#​4343)

Fixed
  • breaking Redox: Fix signal action constant types (#​5009)
  • EspIDF: Correct the value of DT_* constants (#​5034)
  • Redox: Fix locale values and add RTLD_NOLOAD, some TCP constants (#​5025)
  • Various: Use Padding::new(<zeroed>) rather than Padding::uninit() (#​5036)
Changed
  • potentially breaking Linux: Add new fields to struct ptrace_syscall_info (#​4966)
  • Re-export core::ffi integer types rather than redefining (#​5015)
  • Redox: Update F_DUPFD, IP, and TCP constants to match relibc (#​4990)
moka-rs/moka (moka)

v0.12.16

Compare Source

Fixed
  • Fixed a bug where cache eviction could stall permanently when the cache was
    configured with the non-default LRU eviction policy (EvictionPolicy::lru())
    by a race between insert and remove operations on the same key
    ([#​592][gh-pull-0592] by [@​kim-jhyeon][gh-kim-jhyeon], reported in
    [#​590][gh-issue-0590]):
    • This bug was introduced in v0.12.0 and affected sync::Cache,
      sync::SegmentedCache and future::Cache.
    • A race between applying a write recording for an entry and concurrently
      removing that entry from the internal concurrent hash table could leave an
      orphaned node at the front of the LRU queue. Once present, no entry was ever
      evicted again and the cache grew unboundedly past max_capacity.
    • The same race also affected the default TinyLFU eviction policy, but with
      a milder symptom: each occurrence permanently leaked one phantom entry
      slot, causing entry_count and weighted_size to over-report and the
      usable capacity to shrink by one entry per occurrence. Fixed by the same
      change.
Changed
  • Worked around a ThreadSanitizer false positive ([#​602][gh-pull-0602]):
    • Replaced the standalone fence(Acquire) in the internal MiniArc's drop
      path with an Acquire load of the reference count, so that downstream
      projects can now run ThreadSanitizer on code using Moka without hitting
      this false positive.
    • std::sync::Arc has a similar workaround.
  • Raised the minimum version of the crossbeam-epoch crate from v0.9.18 to
    v0.9.20 to avoid the following advisory ([#​603][gh-pull-0603]):
    • [RUSTSEC-2026-0204] crossbeam-epoch: invalid pointer dereference in
      fmt::Pointer for Atomic and Shared
    • Moka is not affected by this advisory because it never formats these
      pointer types. However, raising the minimum version prevents downstream
      lockfiles from resolving to an affected crossbeam-epoch version via
      Moka.

v0.12.15

Compare Source

Fixed
  • Fixed a bug where re-inserting an expired entry could cause it to lose its
    expiration time and remain in the cache indefinitely when using a custom Expiry
    policy with per-entry expiration. ([#​582][gh-pull-0582] by [@​jiangzhe][gh-jiangzhe],
    [#​581][gh-pull-0581] by [@​atrocities][gh-atrocities], reported in
    [#​575][gh-issue-0575]):
    • This occurred when an entry that had expired but not yet been evicted was
      re-inserted, and expire_after_update returned None. This primarily
      affected users who only override expire_after_create, since the default
      expire_after_update returns duration_until_expiry, which is None for
      expired entries.
    • This bug was introduced by the changes in v0.12.13 ([#​549][gh-pull-0549] and
      [#​564][gh-pull-0564]).
    • Subtle behavior change:
      • Before this fix, re-inserting an expired entry was treated as an update,
        so Expiry::expire_after_update was called.
      • After this fix, re-inserting an expired entry is treated as a creation,
        so Expiry::expire_after_create is called instead.
      • This may change the expiration time of re-inserted entries, depending on
        your Expiry trait implementation.
  • Fixed flaky tests cht::segment::tests::drop_many_values and
    drop_many_values_concurrent that were failing on high-core-count machines
    ([#​586][gh-pull-0586]):
    • These tests were using a CPU-dependent segment count, causing inconsistent
      bucket array shrinking behavior of the internal segmented hash map across
      different machines.
    • Changed these tests to use a fixed segment count (4) for consistent results.
Changed
  • Disabled flaky GC-dependent tests by default using run_flaky_tests cfg
    ([#​584][gh-pull-0584]):
    • These tests rely on epoch-based garbage collection (crossbeam-epoch) timing
      that is not guaranteed, causing intermittent failures.
    • Fixed [#​539][gh-issue-0539] and [#​580][gh-issue-0580].
    • To run these tests, set RUSTFLAGS='--cfg run_flaky_tests'.
dtolnay/proc-macro2 (proc-macro2)

v1.0.107

Compare Source

  • Documentation improvements
dtolnay/quote (quote)

v1.0.47

Compare Source

  • Documentation improvements

v1.0.46

Compare Source

bytecodealliance/rustix (rustix)

v1.1.5

Compare Source

serde-rs/serde (serde)

v1.0.229

Compare Source

  • Update to syn 3
serde-rs/json (serde_json)

v1.0.151

Compare Source

v1.0.150

Compare Source

dtolnay/syn (syn)

v2.0.119

Compare Source

  • Preserve attributes on tail-call expressions in statement position (#​1994)
  • Parse field-representing types builtin in type position (#​1996)

v2.0.118

Compare Source

  • Documentation improvements
dtolnay/thiserror (thiserror)

v2.0.21

Compare Source

  • Fix parsing of generic unit variants in display expressions (#​459)

v2.0.20

Compare Source

  • Suppress redundant_field_names clippy lint in generated code (#​454)

v2.0.19

Compare Source

  • Update to syn 3
tokio-rs/tokio (tokio)

v1.53.1: Tokio v1.53.1

Compare Source

1.53.1 (July 20th, 2026)

Fixed
  • signal: restore MSRV by removing OnceLock::wait from the Windows handler (#​8300)
Fixed (unstable)
  • time: fix alt timer cancellation and insertion race (#​8252)
Documented
  • runtime: remove dead link definition in Runtime::block_on (#​8301)

v1.53.0: Tokio v1.53.0

Compare Source

1.53.0 (July 17th, 2026)

Added
  • fs: implement From<OwnedFd> and From<OwnedHandle> for File (#​8266)
  • metrics: add task schedule latency metric (#​7986)
  • net: add SocketAddr methods to Unix sockets (#​8144)
Changed
  • io: add #[inline] to IO trait impls for in-memory types (#​8242)
  • net: implement UCred::pid on FreeBSD (#​8086)
  • net: support Nuttx target os (#​8259)
  • signal: refactor global variables on Windows (#​8231)
  • sync: mpsc::{Receiver,UnboundedReceiver} now drops waker on drop, even if there are still senders (#​8095)
  • taskdump: support taskdumps on s390x (#​8192)
  • time: add #[track_caller] to timeout_at() (#​8077)
  • time: consolidate mutex locks on spurious poll (#​8124)
  • time: defer waker clone on spurious poll (#​8107)
  • time: move lazy-registration state into Sleep (#​8132)
  • tracing: remove unnecessary span clone (#​8126)
Fixed
  • io: do not treat zero-length reads as EOF in Chain (#​8251)
  • net: use getpeereid for QNX peer credentials (#​8270)
  • runtime: avoid illegal state in FastRand (#​8078)
  • sync: wake mpsc receiver when a queued reserve[_many] returns permits (#​8260)
  • taskdump: skip double wake on Trace::capture/Trace::trace_with (#​8043)
  • time: avoid stack overflow in runtime constructor (#​8093)
  • time (alt timer): ensure timers stay in the same runtime after .reset() (#​8169)
IO uring (unstable)
  • fs: use io-uring for fs::try_exists (#​8080)
  • fs: use io-uring for renaming files (#​7800)
  • rt: flush io-uring CQE in case of CQE overflow (#​8277)
Documented
  • docs: clarify cancel safety wording (#​8181)
  • fs: clarify create_dir_all succeeds if path exists (#​8149)
  • io: add warning about stdout reordering with multiple handles (#​8276)
  • net: document pipe try_read*/try_write* readiness behavior (#​8032)
  • runtime: document interaction with fork() (#​8202)
  • sync: clarify broadcast lagging semantics (#​8239)
  • sync: document memory ordering guarantees for Semaphore (#​8119)
  • task: explain why yield_now defers its waker (#​8254)
  • time: add panic docs to timeout_at() (#​8077)
  • time: fix reversed poll order in timeout doc (#​8214)

v1.52.4: Tokio v1.52.4

Compare Source

1.52.4 (July 16th, 2026)

Fixed
  • runtime: don't skip the driver when before_park schedules work (#​8222)
Fixed (unstable)
  • taskdump: remove crate disambiguators from output (#​8264)

v1.52.3: Tokio v1.52.3

Compare Source

1.52.3 (May 8th, 2026)

Fixed
  • sync: fix underflow in mpsc channel len() (#​8062)
  • sync: notify receivers in mpsc OwnedPermit::release() method (#​8075)
  • sync: require that an RwLock has max_readers != 0 (#​8076)
  • sync: return Empty from try_recv() when mpsc is closed with outstanding permits (#​8074)

v1.52.2: Tokio v1.52.2

Compare Source

1.52.2 (May 4th, 2026)

This release reverts the LIFO slot stealing change introduced in 1.51.0 (#​7431), due to its performance impact. (#​8100)

v1.52.1: Tokio v1.52.1

Compare Source

1.52.1 (April 16th, 2026)

Fixed

v1.52.0: Tokio v1.52.0

Compare Source

1.52.0 (April 14th, 2026)

Added

  • io: AioSource::register_borrowed for I/O safety support (#​7992)
  • net: add try_io function to unix::pipe sender and receiver types (#​8030)

Added (unstable)

  • runtime: Builder::enable_eager_driver_handoff setting enable eager hand off of the I/O and time drivers before polling tasks (#​8010)
  • taskdump: add trace_with() for customized task dumps (#​8025)
  • taskdump: allow impl FnMut() in trace_with instead of just fn() (#​8040)
  • fs: support io_uring in AsyncRead for File (#​7907)

Changed

  • runtime: improve spawn_blocking scalability with sharded queue (#​7757)
  • runtime: use compare_exchange_weak() in worker queue (#​8028)

Fixed

  • runtime: overflow second half of tasks when local queue is filled instead of first half (#​8029)

Documented

  • docs: fix typo in oneshot::Sender::send docs (#​8026)
  • docs: hide #[tokio::main] attribute in the docs of sync::watch (#​8035)
  • net: add docs on ConnectionRefused errors with UDP sockets (#​7870)

v1.51.4: Tokio v1.51.4

Compare Source

1.51.4 (July 16th, 2026)

Fixed
  • runtime: don't skip the driver when before_park schedules work (#​8222)

v1.51.3: Tokio v1.51.3

Compare Source

1.51.3 (May 8th, 2026)

Fixed
  • sync: fix underflow in mpsc channel len() (#​8062)
  • sync: notify receivers in mpsc OwnedPermit::release() method (#​8075)
  • sync: require that an RwLock has max_readers != 0 (#​8076)
  • sync: return Empty from try_recv() when mpsc is closed with outstanding permits (#​8074)

v1.51.2: Tokio v1.51.1

Compare Source

1.51.2 (May 4th, 2026)

This release reverts the LIFO slot stealing change introduced in 1.51.0 (#​7431), due to its performance impact. (#​8100)

v1.51.1: Tokio v1.51.1

Compare Source

1.51.1 (April 8th, 2026)

Fixed
  • sync: fix semaphore reopens after forget (#​8021)
  • net: surface errors from SO_ERROR on recv for UDP sockets on Linux (#​8001)
Fixed (unstable)
  • metrics: fix worker_local_schedule_count test (#​8008)
  • rt: do not leak fd when cancelling io_uring open operation (#​7983)

v1.51.0: Tokio v1.51.0

Compare Source

1.51.0 (April 3rd, 2026)

Added
  • net: implement get_peer_cred on Hurd (#​7989)
  • runtime: add tokio::runtime::worker_index() (#​7921)
  • runtime: add runtime name (#​7924)
  • runtime: stabilize LocalRuntime (#​7557)
  • wasm: add wasm32-wasip2 networking support (#​7933)
Changed
  • runtime: steal tasks from the LIFO slot (#​7431)
Fixed
  • docs: do not show "Available on non-loom only." doc label (#​7977)
  • macros: improve overall macro hygiene (#​7997)
  • sync: fix notify_waiters priority in Notify (#​7996)
  • sync: fix panic in Chan::recv_many when called with non-empty vector on closed channel (#​7991)
uuid-rs/uuid (uuid)

v1.26.1

Compare Source

What's Changed

New Contributors

Full Changelog: uuid-rs/uuid@v1.26.0...v1.26.1

v1.26.0

Compare Source

What's Changed

Full Changelog: uuid-rs/uuid@1.25.0...v1.26.0

v1.25.0

Compare Source

What's Changed

New Contributors

Full Changelog: uuid-rs/uuid@v1.24.1...1.25.0

v1.24.1

Compare Source

What's Changed

New Contributors

Full Changelog: uuid-rs/uuid@v1.24.0...v1.24.1

v1.24.0

Compare Source

What's Changed

New Contributors

Full Changelog: uuid-rs/uuid@v1.23.5...v1.24.0

v1.23.5

Compare Source

What's Changed

New Contributors

Full Changelog: uuid-rs/uuid@v1.23.4...v1.23.5

v1.23.4

Compare Source

What's Changed

New Contributors

Full Changelog: uuid-rs/uuid@v1.23.3...v1.23.4

v1.23.3

Compare Source

What's Changed

Full Changelog: uuid-rs/uuid@v1.23.2...v1.23.3

v1.23.2

Compare Source

What's Changed

Full Changelog: uuid-rs/uuid@v1.23.1...v1.23.2

v1.23.1

Compare Source

What's Changed

New Contributors

Full Changelog: uuid-rs/uuid@v1.23.0...v1.23.1

v1.23.0

Compare Source

What's Changed

New Contributors

Special thanks

@​meng-xu-cs raised a series of bugs against the timestamp logic in uuid using automated tooling. The issues themselves were reasonably and responsibly presented and the end result is a better uuid library for everyone. Thanks!

Deprecations

This release includes the following deprecations:

  • Context: Renamed to ContextV1
  • Timestamp::from_gregorian: Renamed to Timestamp::from_gregorian_time

Change to Version::Max

Version::Max's u8 representation has changed

✂ Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Australia/Sydney)

  • Branch creation
    • "before 6am"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@kodus-27b

kodus-27b Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

Kody Code Review — 4 suggested fixes.
Paste the prompt below to your agent and all review fixed at once!

🛠️ Open Agent Prompt
A code review identified the following issues in this pull request.
Each section describes what was found and includes a reference implementation where available.

Files involved:
- crates/cachekit/Cargo.toml:100
- crates/cachekit/Cargo.toml:80
- crates/cachekit/Cargo.toml:66
- crates/cachekit/Cargo.toml:92

---

### [1/4] crates/cachekit/Cargo.toml:100
Issue identified during code review:
Broken dependency in crates/cachekit/Cargo.toml line 100: `getrandom = { version = "0.4", optional = true, features = ["js"] }` requests a `js` feature that no longer exists, because it was renamed to `wasm_js` in 0.3 and that backend also requires the `getrandom_backend="wasm_js"` cfg. When Cargo resolves any build with this dependency enabled, it fails on the missing feature. Even with a valid feature name, the direct 0.4 dependency would not enable the JS backend for the transitive getrandom 0.2 used by uuid/rand on wasm32, since features only unify within one semver-compatible version, so the `workers` build would trap when drawing entropy. Fix: keep `getrandom = { version = "0.2", optional = true, features = ["js"] }` until the transitive graph moves to the new version, then migrate to `wasm_js` and the required cfg together.
Reference implementation (from code review):

// crates/cachekit/Cargo.toml:100
getrandom = { version = "0.2", optional = true, features = ["js"] }

---

### [2/4] crates/cachekit/Cargo.toml:80
Issue identified during code review:
Feature mismatch in crates/cachekit/Cargo.toml line 80: the reqwest requirement moves to 0.13 but keeps the 0.12 feature name `rustls-tls`, and 0.13 renamed its TLS features around `rustls`. Because `cachekitio` is a default feature, every default build fails dependency resolution on the missing `rustls-tls` feature. Fix: replace `rustls-tls` with `rustls`, or stay on 0.12.
Reference implementation (from code review):

// crates/cachekit/Cargo.toml:80
reqwest = { version = "0.13", optional = true, default-features = false, features = ["rustls", "json"] }

---

### [3/4] crates/cachekit/Cargo.toml:66
Issue identified during code review:
WHAT: blake2 has a minor-version bump (0.10 -> 0.11) with no SCA or audit evidence. WHY: A dependency change without vulnerability review and an updated lockfile adds supply-chain risk. The 0.11 line also changes the digest/crypto trait APIs. HOW: Attach `cargo audit` or OSV results to the PR, confirm Cargo.lock is updated, and verify API compatibility.

---

### [4/4] crates/cachekit/Cargo.toml:92
Issue identified during code review:
MSRV break in crates/cachekit/Cargo.toml line 92: memcache moves to 0.21, even though the comment directly above pins it at 0.19 because 0.20+ uses `is_multiple_of` and let-chains, which are unavailable under the workspace's declared `rust-version = "1.85"`. Building with `--features memcached` on the 1.85 toolchain fails to compile the memcache dependency. Fix: revert to `0.19`, or raise the workspace rust-version and update the comment in the same change.
Reference implementation (from code review):

// crates/cachekit/Cargo.toml:92
memcache = { version = "0.19", optional = true, default-features = false }

---

Review each issue in context, use the reference implementations as guidance, and apply fixes that are consistent with the surrounding codebase.

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: cachekit-io/cachekit-rs/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 59831106-a3a1-4669-b8ef-b0cc9d1983f5

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread crates/cachekit/Cargo.toml Outdated
worker = { version = "0.8", optional = true }
js-sys = { version = "0.3", optional = true }
getrandom = { version = "0.2", optional = true, features = ["js"] }
getrandom = { version = "0.4", optional = true, features = ["js"] }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug high

Broken dependency in crates/cachekit/Cargo.toml line 100: getrandom = { version = "0.4", optional = true, features = ["js"] } requests a js feature that no longer exists, because it was renamed to wasm_js in 0.3 and that backend also requires the getrandom_backend="wasm_js" cfg. When Cargo resolves any build with this dependency enabled, it fails on the missing feature. Even with a valid feature name, the direct 0.4 dependency would not enable the JS backend for the transitive getrandom 0.2 used by uuid/rand on wasm32, since features only unify within one semver-compatible version, so the workers build would trap when drawing entropy. Fix: keep getrandom = { version = "0.2", optional = true, features = ["js"] } until the transitive graph moves to the new version, then migrate to wasm_js and the required cfg together.

getrandom = { version = "0.2", optional = true, features = ["js"] }
Prompt for LLM

File crates/cachekit/Cargo.toml:

Line 100:

Broken dependency in crates/cachekit/Cargo.toml line 100: `getrandom = { version = "0.4", optional = true, features = ["js"] }` requests a `js` feature that no longer exists, because it was renamed to `wasm_js` in 0.3 and that backend also requires the `getrandom_backend="wasm_js"` cfg. When Cargo resolves any build with this dependency enabled, it fails on the missing feature. Even with a valid feature name, the direct 0.4 dependency would not enable the JS backend for the transitive getrandom 0.2 used by uuid/rand on wasm32, since features only unify within one semver-compatible version, so the `workers` build would trap when drawing entropy. Fix: keep `getrandom = { version = "0.2", optional = true, features = ["js"] }` until the transitive graph moves to the new version, then migrate to `wasm_js` and the required cfg together.

Suggested Code:

getrandom = { version = "0.2", optional = true, features = ["js"] }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread crates/cachekit/Cargo.toml Outdated

# Optional: HTTP backend (native)
reqwest = { version = "0.12", optional = true, default-features = false, features = ["rustls-tls", "json"] }
reqwest = { version = "0.13", optional = true, default-features = false, features = ["rustls-tls", "json"] }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug high

Feature mismatch in crates/cachekit/Cargo.toml line 80: the reqwest requirement moves to 0.13 but keeps the 0.12 feature name rustls-tls, and 0.13 renamed its TLS features around rustls. Because cachekitio is a default feature, every default build fails dependency resolution on the missing rustls-tls feature. Fix: replace rustls-tls with rustls, or stay on 0.12.

reqwest = { version = "0.13", optional = true, default-features = false, features = ["rustls", "json"] }
Prompt for LLM

File crates/cachekit/Cargo.toml:

Line 80:

Feature mismatch in crates/cachekit/Cargo.toml line 80: the reqwest requirement moves to 0.13 but keeps the 0.12 feature name `rustls-tls`, and 0.13 renamed its TLS features around `rustls`. Because `cachekitio` is a default feature, every default build fails dependency resolution on the missing `rustls-tls` feature. Fix: replace `rustls-tls` with `rustls`, or stay on 0.12.

Suggested Code:

reqwest = { version = "0.13", optional = true, default-features = false, features = ["rustls", "json"] }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread crates/cachekit/Cargo.toml Outdated
thiserror = "2.0"
async-trait = "0.1"
blake2 = "0.10"
blake2 = "0.11"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

WHAT: blake2 has a minor-version bump (0.10 -> 0.11) with no SCA or audit evidence. WHY: A dependency change without vulnerability review and an updated lockfile adds supply-chain risk. The 0.11 line also changes the digest/crypto trait APIs. HOW: Attach cargo audit or OSV results to the PR, confirm Cargo.lock is updated, and verify API compatibility.

Also found in:

  • crates/cachekit/Cargo.toml:80-80
  • crates/cachekit/Cargo.toml:100-100
  • crates/cachekit/Cargo.toml:92-92
  • crates/cachekit/Cargo.toml:98-98

Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk

Prompt for LLM

File crates/cachekit/Cargo.toml:

Line 66:

WHAT: blake2 has a minor-version bump (0.10 -> 0.11) with no SCA or audit evidence. WHY: A dependency change without vulnerability review and an updated lockfile adds supply-chain risk. The 0.11 line also changes the digest/crypto trait APIs. HOW: Attach `cargo audit` or OSV results to the PR, confirm Cargo.lock is updated, and verify API compatibility.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread crates/cachekit/Cargo.toml Outdated
Comment on lines +89 to +92
# used async-memcached 0.6 shipped toxiproxy_rust/openssl as runtime deps,
# which is why it was dropped — expert panel, LAB-429). Held at 0.19: 0.20.0
# uses `is_multiple_of`/let-chains and breaks this workspace's 1.85 MSRV.
memcache = { version = "0.19", optional = true, default-features = false }
memcache = { version = "0.21", optional = true, default-features = false }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug medium

MSRV break in crates/cachekit/Cargo.toml line 92: memcache moves to 0.21, even though the comment directly above pins it at 0.19 because 0.20+ uses is_multiple_of and let-chains, which are unavailable under the workspace's declared rust-version = "1.85". Building with --features memcached on the 1.85 toolchain fails to compile the memcache dependency. Fix: revert to 0.19, or raise the workspace rust-version and update the comment in the same change.

memcache = { version = "0.19", optional = true, default-features = false }
Prompt for LLM

File crates/cachekit/Cargo.toml:

Line 89 to 92:

MSRV break in crates/cachekit/Cargo.toml line 92: memcache moves to 0.21, even though the comment directly above pins it at 0.19 because 0.20+ uses `is_multiple_of` and let-chains, which are unavailable under the workspace's declared `rust-version = "1.85"`. Building with `--features memcached` on the 1.85 toolchain fails to compile the memcache dependency. Fix: revert to `0.19`, or raise the workspace rust-version and update the comment in the same change.

Suggested Code:

memcache = { version = "0.19", optional = true, default-features = false }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread crates/cachekit/Cargo.toml Outdated
worker = { version = "0.8", optional = true }
js-sys = { version = "0.3", optional = true }
getrandom = { version = "0.2", optional = true, features = ["js"] }
getrandom = { version = "0.4", optional = true, features = ["js"] }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug high

Build break in the workers feature (Cargo.toml:100): getrandom 0.4 has no js feature because it was renamed to wasm_js in 0.3, and the direct dependency no longer matches the getrandom 0.2.17 that cachekit-core, ring and rand_core 0.6 still use (Cargo.lock lines 200, 1538, 1451). Dependency resolution fails, and even with the feature renamed, those transitive 0.2 copies lose js and hit getrandom's unsupported-target compile_error on wasm32-unknown-unknown, the only target where workers is used. Fix: keep getrandom = { version = "0.2", optional = true, features = ["js"] }, and add any needed 0.4 entry under a different name with features = ["wasm_js"].

getrandom = { version = "0.2", optional = true, features = ["js"] }
Prompt for LLM

File crates/cachekit/Cargo.toml:

Line 100:

Build break in the `workers` feature (Cargo.toml:100): getrandom 0.4 has no `js` feature because it was renamed to `wasm_js` in 0.3, and the direct dependency no longer matches the getrandom 0.2.17 that cachekit-core, ring and rand_core 0.6 still use (Cargo.lock lines 200, 1538, 1451). Dependency resolution fails, and even with the feature renamed, those transitive 0.2 copies lose `js` and hit getrandom's unsupported-target compile_error on wasm32-unknown-unknown, the only target where `workers` is used. Fix: keep `getrandom = { version = "0.2", optional = true, features = ["js"] }`, and add any needed 0.4 entry under a different name with `features = ["wasm_js"]`.

Suggested Code:

getrandom = { version = "0.2", optional = true, features = ["js"] }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread crates/cachekit/Cargo.toml Outdated

# Optional: Cloudflare Workers
worker = { version = "0.4", optional = true }
worker = { version = "0.8", optional = true }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug high

Breaking upgrade in the Workers backend (Cargo.toml:98): worker jumps from 0.4 to 0.8, four breaking releases, with no matching changes to workers.rs, which depends on RequestInit::with_method/with_headers/with_body, Request::new_with_init and Fetch::Request(..).send(). worker 0.8 requires a newer wasm-bindgen than the one the exact-pinned wasm-bindgen-test = "=0.3.71" matches (Cargo.toml:136-139), so resolution fails or the wasm32 test runner diverges from the resolved wasm-bindgen, and --locked builds fail because Cargo.lock still pins worker 0.4.2. Fix: hold worker at 0.4, or bump worker, the wasm-bindgen-test pin, the lockfile and the CI runner together and adapt workers.rs.

worker = { version = "0.4", optional = true }
Prompt for LLM

File crates/cachekit/Cargo.toml:

Line 98:

Breaking upgrade in the Workers backend (Cargo.toml:98): worker jumps from 0.4 to 0.8, four breaking releases, with no matching changes to workers.rs, which depends on RequestInit::with_method/with_headers/with_body, Request::new_with_init and Fetch::Request(..).send(). worker 0.8 requires a newer wasm-bindgen than the one the exact-pinned `wasm-bindgen-test = "=0.3.71"` matches (Cargo.toml:136-139), so resolution fails or the wasm32 test runner diverges from the resolved wasm-bindgen, and `--locked` builds fail because Cargo.lock still pins worker 0.4.2. Fix: hold worker at 0.4, or bump worker, the wasm-bindgen-test pin, the lockfile and the CI runner together and adapt workers.rs.

Suggested Code:

worker = { version = "0.4", optional = true }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread crates/cachekit/Cargo.toml Outdated

# Optional: HTTP backend (native)
reqwest = { version = "0.12", optional = true, default-features = false, features = ["rustls-tls", "json"] }
reqwest = { version = "0.13", optional = true, default-features = false, features = ["rustls-tls", "json"] }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug high

Feature-flag break in the reqwest dependency (Cargo.toml:80): reqwest is bumped to 0.13, which reorganized its TLS features around rustls, but the entry still requests rustls-tls, and Cargo.lock still pins reqwest 0.12.28. --locked builds of the default cachekitio feature fail, and without a valid rustls feature the client has no TLS backend for HTTPS requests to cachekit.io. Fix: switch to the 0.13 rustls feature name and update Cargo.lock, or hold at 0.12.

reqwest = { version = "0.12", optional = true, default-features = false, features = ["rustls-tls", "json"] }
Prompt for LLM

File crates/cachekit/Cargo.toml:

Line 80:

Feature-flag break in the reqwest dependency (Cargo.toml:80): reqwest is bumped to 0.13, which reorganized its TLS features around `rustls`, but the entry still requests `rustls-tls`, and Cargo.lock still pins reqwest 0.12.28. `--locked` builds of the default `cachekitio` feature fail, and without a valid rustls feature the client has no TLS backend for HTTPS requests to cachekit.io. Fix: switch to the 0.13 rustls feature name and update Cargo.lock, or hold at 0.12.

Suggested Code:

reqwest = { version = "0.12", optional = true, default-features = false, features = ["rustls-tls", "json"] }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread crates/cachekit/Cargo.toml Outdated
# which is why it was dropped). Held at 0.19: 0.20.0
# uses `is_multiple_of`/let-chains and breaks this workspace's 1.85 MSRV.
memcache = { version = "0.19", optional = true, default-features = false }
memcache = { version = "0.21", optional = true, default-features = false }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

WHAT: memcache is bumped to 0.21, but the comment directly above says it is held at 0.19 because 0.20+ breaks the 1.85 MSRV. WHY: This is an unexpected version jump that contradicts the documented constraint. There is no audit evidence, and the transitive dependencies may change. HOW: Either keep 0.19, or raise the MSRV and update the comment. Also provide cargo audit / OSV output.

Also found in:

  • crates/cachekit/Cargo.toml:100-100
  • crates/cachekit/Cargo.toml:66-66
  • crates/cachekit/Cargo.toml:98-98
  • crates/cachekit/Cargo.toml:80-80

Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk

Prompt for LLM

File crates/cachekit/Cargo.toml:

Line 92:

WHAT: memcache is bumped to 0.21, but the comment directly above says it is held at 0.19 because 0.20+ breaks the 1.85 MSRV. WHY: This is an unexpected version jump that contradicts the documented constraint. There is no audit evidence, and the transitive dependencies may change. HOW: Either keep 0.19, or raise the MSRV and update the comment. Also provide cargo audit / OSV output.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread crates/cachekit/Cargo.toml Outdated
Comment on lines +90 to +92
# which is why it was dropped). Held at 0.19: 0.20.0
# uses `is_multiple_of`/let-chains and breaks this workspace's 1.85 MSRV.
memcache = { version = "0.19", optional = true, default-features = false }
memcache = { version = "0.21", optional = true, default-features = false }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug medium

MSRV break in the memcached dependency (Cargo.toml:92): memcache is bumped to 0.21 even though the comment directly above says 0.20+ uses is_multiple_of/let-chains, and the workspace still declares rust-version = "1.85". Building with --features memcached on Rust 1.85, including in the MSRV CI job, fails to compile inside memcache, and --locked builds also fail because Cargo.lock still pins memcache 0.19.0. Fix: revert to 0.19, or raise the workspace rust-version and remove the stale comment.

memcache = { version = "0.19", optional = true, default-features = false }
Prompt for LLM

File crates/cachekit/Cargo.toml:

Line 90 to 92:

MSRV break in the `memcached` dependency (Cargo.toml:92): memcache is bumped to 0.21 even though the comment directly above says 0.20+ uses `is_multiple_of`/let-chains, and the workspace still declares `rust-version = "1.85"`. Building with `--features memcached` on Rust 1.85, including in the MSRV CI job, fails to compile inside memcache, and `--locked` builds also fail because Cargo.lock still pins memcache 0.19.0. Fix: revert to 0.19, or raise the workspace rust-version and remove the stale comment.

Suggested Code:

memcache = { version = "0.19", optional = true, default-features = false }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

@kodus-27b

kodus-27b Bot commented Sep 29, 2026

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

@kodus-27b

This comment has been minimized.

Comment thread crates/cachekit/Cargo.toml Outdated
worker = { version = "0.8", optional = true }
js-sys = { version = "0.3", optional = true }
getrandom = { version = "0.2", optional = true, features = ["js"] }
getrandom = { version = "0.4", optional = true, features = ["js"] }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug high

Broken feature in the getrandom dependency: getrandom 0.3+ removed the js feature (the wasm backend is now wasm_js), so getrandom = { version = "0.4", features = ["js"] } does not resolve, and a 0.4 dep does not enable the JS backend for the getrandom 0.2 that other crates still use (Cargo.lock has both 0.2.17 and 0.4.2). Any build with --features workers fails at dependency resolution. Fix: keep getrandom = { version = "0.2", features = ["js"] }, or, if 0.4 is required, use wasm_js with its backend cfg and keep a 0.2 js entry.

getrandom = { version = "0.2", optional = true, features = ["js"] }
Prompt for LLM

File crates/cachekit/Cargo.toml:

Line 100:

Broken feature in the getrandom dependency: getrandom 0.3+ removed the `js` feature (the wasm backend is now `wasm_js`), so `getrandom = { version = "0.4", features = ["js"] }` does not resolve, and a 0.4 dep does not enable the JS backend for the getrandom 0.2 that other crates still use (Cargo.lock has both 0.2.17 and 0.4.2). Any build with `--features workers` fails at dependency resolution. Fix: keep `getrandom = { version = "0.2", features = ["js"] }`, or, if 0.4 is required, use `wasm_js` with its backend cfg and keep a 0.2 `js` entry.

Suggested Code:

getrandom = { version = "0.2", optional = true, features = ["js"] }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread crates/cachekit/Cargo.toml Outdated

# Optional: HTTP backend (native)
reqwest = { version = "0.12", optional = true, default-features = false, features = ["rustls-tls", "json"] }
reqwest = { version = "0.13", optional = true, default-features = false, features = ["rustls-tls", "json"] }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug high

Removed feature in the reqwest dependency: reqwest 0.13 renamed rustls-tls to rustls, so features = ["rustls-tls", "json"] no longer resolves, and the lockfile still pins reqwest 0.12.28. Because cachekitio is a default feature, the default build fails for every consumer. Fix: stay on 0.12, or switch to the 0.13 rustls feature name and confirm the default-features = false TLS setup still excludes native-tls/openssl.

reqwest = { version = "0.12", optional = true, default-features = false, features = ["rustls-tls", "json"] }
Prompt for LLM

File crates/cachekit/Cargo.toml:

Line 80:

Removed feature in the reqwest dependency: reqwest 0.13 renamed `rustls-tls` to `rustls`, so `features = ["rustls-tls", "json"]` no longer resolves, and the lockfile still pins reqwest 0.12.28. Because `cachekitio` is a default feature, the default build fails for every consumer. Fix: stay on 0.12, or switch to the 0.13 `rustls` feature name and confirm the `default-features = false` TLS setup still excludes native-tls/openssl.

Suggested Code:

reqwest = { version = "0.12", optional = true, default-features = false, features = ["rustls-tls", "json"] }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread crates/cachekit/Cargo.toml Outdated
# which is why it was dropped). Held at 0.19: 0.20.0
# uses `is_multiple_of`/let-chains and breaks this workspace's 1.85 MSRV.
memcache = { version = "0.19", optional = true, default-features = false }
memcache = { version = "0.21", optional = true, default-features = false }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

MSRV break in the memcache dependency: the version is bumped to 0.21, contradicting the comment directly above that holds it at 0.19 because 0.20+ breaks the workspace's 1.85 MSRV. MSRV builds on Rust 1.85 with the memcached feature fail to compile. Fix: revert to 0.19, or raise the MSRV explicitly, update the comment, and commit the updated lockfile.

Also found in:

  • crates/cachekit/Cargo.toml:66-66
  • crates/cachekit/Cargo.toml:100-100
  • crates/cachekit/Cargo.toml:80-80
  • crates/cachekit/Cargo.toml:98-98

Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk

Prompt for LLM

File crates/cachekit/Cargo.toml:

Line 92:

MSRV break in the memcache dependency: the version is bumped to 0.21, contradicting the comment directly above that holds it at 0.19 because 0.20+ breaks the workspace's 1.85 MSRV. MSRV builds on Rust 1.85 with the `memcached` feature fail to compile. Fix: revert to 0.19, or raise the MSRV explicitly, update the comment, and commit the updated lockfile.

**Also found in:**
- `crates/cachekit/Cargo.toml:66-66`
- `crates/cachekit/Cargo.toml:100-100`
- `crates/cachekit/Cargo.toml:80-80`
- `crates/cachekit/Cargo.toml:98-98`

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread crates/cachekit/Cargo.toml Outdated
Comment on lines +90 to +92
# which is why it was dropped). Held at 0.19: 0.20.0
# uses `is_multiple_of`/let-chains and breaks this workspace's 1.85 MSRV.
memcache = { version = "0.19", optional = true, default-features = false }
memcache = { version = "0.21", optional = true, default-features = false }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug medium

MSRV break in the memcache dependency: the version moves to 0.21, but the comment above it pins 0.19 because 0.20+ uses is_multiple_of and let-chains, and the workspace still sets rust-version = "1.85". Running cargo +1.85 build --features memcached (MSRV CI and downstream users on 1.85) fails to compile. Fix: revert to version = "0.19", or raise the workspace rust-version to what memcache 0.21 requires and update the comment.

# Held at 0.19: 0.20.0
# uses `is_multiple_of`/let-chains and breaks this workspace's 1.85 MSRV.
memcache = { version = "0.19", optional = true, default-features = false }
Prompt for LLM

File crates/cachekit/Cargo.toml:

Line 90 to 92:

MSRV break in the memcache dependency: the version moves to 0.21, but the comment above it pins 0.19 because 0.20+ uses `is_multiple_of` and let-chains, and the workspace still sets `rust-version = "1.85"`. Running `cargo +1.85 build --features memcached` (MSRV CI and downstream users on 1.85) fails to compile. Fix: revert to `version = "0.19"`, or raise the workspace `rust-version` to what memcache 0.21 requires and update the comment.

Suggested Code:

# Held at 0.19: 0.20.0
# uses `is_multiple_of`/let-chains and breaks this workspace's 1.85 MSRV.
memcache = { version = "0.19", optional = true, default-features = false }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread crates/cachekit/Cargo.toml Outdated

# Optional: Cloudflare Workers
worker = { version = "0.4", optional = true }
worker = { version = "0.8", optional = true }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug medium

API break in the worker dependency: the version jumps from 0.4 to 0.8 (four breaking 0.x releases) while workers.rs uses RequestInit::new().with_method/with_headers/with_body, Request::new_with_init, Fetch::Request(..).send(), and Response::bytes/status_code, and the newer worker pulls a newer wasm-bindgen than the exact wasm-bindgen-test = "=0.3.71" pin allows. A --features workers build or the wasm test runner fails on the API or wasm-bindgen version mismatch. Fix: bump worker together with the matching wasm-bindgen-test pin and CI runner, and build with --features workers --target wasm32-unknown-unknown before merging.

worker = { version = "0.4", optional = true }
Prompt for LLM

File crates/cachekit/Cargo.toml:

Line 98:

API break in the worker dependency: the version jumps from 0.4 to 0.8 (four breaking 0.x releases) while workers.rs uses `RequestInit::new().with_method/with_headers/with_body`, `Request::new_with_init`, `Fetch::Request(..).send()`, and `Response::bytes/status_code`, and the newer worker pulls a newer wasm-bindgen than the exact `wasm-bindgen-test = "=0.3.71"` pin allows. A `--features workers` build or the wasm test runner fails on the API or wasm-bindgen version mismatch. Fix: bump worker together with the matching wasm-bindgen-test pin and CI runner, and build with `--features workers --target wasm32-unknown-unknown` before merging.

Suggested Code:

worker = { version = "0.4", optional = true }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

@kodus-27b

kodus-27b Bot commented Sep 30, 2026

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant