chore(deps): update all non-major dependencies - #91
cachekit-renovate-bot[bot] wants to merge 1 commit into
Conversation
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
Kody Code Review — 4 suggested fixes. 🛠️ Open Agent Prompt |
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: cachekit-io/cachekit-rs/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
| worker = { version = "0.8", optional = true } | ||
| js-sys = { version = "0.3", optional = true } | ||
| getrandom = { version = "0.2", optional = true, features = ["js"] } | ||
| getrandom = { version = "0.4", optional = true, features = ["js"] } |
There was a problem hiding this comment.
Broken dependency in crates/cachekit/Cargo.toml line 100: getrandom = { version = "0.4", optional = true, features = ["js"] } requests a js feature that no longer exists, because it was renamed to wasm_js in 0.3 and that backend also requires the getrandom_backend="wasm_js" cfg. When Cargo resolves any build with this dependency enabled, it fails on the missing feature. Even with a valid feature name, the direct 0.4 dependency would not enable the JS backend for the transitive getrandom 0.2 used by uuid/rand on wasm32, since features only unify within one semver-compatible version, so the workers build would trap when drawing entropy. Fix: keep getrandom = { version = "0.2", optional = true, features = ["js"] } until the transitive graph moves to the new version, then migrate to wasm_js and the required cfg together.
getrandom = { version = "0.2", optional = true, features = ["js"] }Prompt for LLM
File crates/cachekit/Cargo.toml:
Line 100:
Broken dependency in crates/cachekit/Cargo.toml line 100: `getrandom = { version = "0.4", optional = true, features = ["js"] }` requests a `js` feature that no longer exists, because it was renamed to `wasm_js` in 0.3 and that backend also requires the `getrandom_backend="wasm_js"` cfg. When Cargo resolves any build with this dependency enabled, it fails on the missing feature. Even with a valid feature name, the direct 0.4 dependency would not enable the JS backend for the transitive getrandom 0.2 used by uuid/rand on wasm32, since features only unify within one semver-compatible version, so the `workers` build would trap when drawing entropy. Fix: keep `getrandom = { version = "0.2", optional = true, features = ["js"] }` until the transitive graph moves to the new version, then migrate to `wasm_js` and the required cfg together.
Suggested Code:
getrandom = { version = "0.2", optional = true, features = ["js"] }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
|
|
||
| # Optional: HTTP backend (native) | ||
| reqwest = { version = "0.12", optional = true, default-features = false, features = ["rustls-tls", "json"] } | ||
| reqwest = { version = "0.13", optional = true, default-features = false, features = ["rustls-tls", "json"] } |
There was a problem hiding this comment.
Feature mismatch in crates/cachekit/Cargo.toml line 80: the reqwest requirement moves to 0.13 but keeps the 0.12 feature name rustls-tls, and 0.13 renamed its TLS features around rustls. Because cachekitio is a default feature, every default build fails dependency resolution on the missing rustls-tls feature. Fix: replace rustls-tls with rustls, or stay on 0.12.
reqwest = { version = "0.13", optional = true, default-features = false, features = ["rustls", "json"] }Prompt for LLM
File crates/cachekit/Cargo.toml:
Line 80:
Feature mismatch in crates/cachekit/Cargo.toml line 80: the reqwest requirement moves to 0.13 but keeps the 0.12 feature name `rustls-tls`, and 0.13 renamed its TLS features around `rustls`. Because `cachekitio` is a default feature, every default build fails dependency resolution on the missing `rustls-tls` feature. Fix: replace `rustls-tls` with `rustls`, or stay on 0.12.
Suggested Code:
reqwest = { version = "0.13", optional = true, default-features = false, features = ["rustls", "json"] }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
| thiserror = "2.0" | ||
| async-trait = "0.1" | ||
| blake2 = "0.10" | ||
| blake2 = "0.11" |
There was a problem hiding this comment.
WHAT: blake2 has a minor-version bump (0.10 -> 0.11) with no SCA or audit evidence. WHY: A dependency change without vulnerability review and an updated lockfile adds supply-chain risk. The 0.11 line also changes the digest/crypto trait APIs. HOW: Attach cargo audit or OSV results to the PR, confirm Cargo.lock is updated, and verify API compatibility.
Also found in:
crates/cachekit/Cargo.toml:80-80crates/cachekit/Cargo.toml:100-100crates/cachekit/Cargo.toml:92-92crates/cachekit/Cargo.toml:98-98
Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk
Prompt for LLM
File crates/cachekit/Cargo.toml:
Line 66:
WHAT: blake2 has a minor-version bump (0.10 -> 0.11) with no SCA or audit evidence. WHY: A dependency change without vulnerability review and an updated lockfile adds supply-chain risk. The 0.11 line also changes the digest/crypto trait APIs. HOW: Attach `cargo audit` or OSV results to the PR, confirm Cargo.lock is updated, and verify API compatibility.
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
| # used async-memcached 0.6 shipped toxiproxy_rust/openssl as runtime deps, | ||
| # which is why it was dropped — expert panel, LAB-429). Held at 0.19: 0.20.0 | ||
| # uses `is_multiple_of`/let-chains and breaks this workspace's 1.85 MSRV. | ||
| memcache = { version = "0.19", optional = true, default-features = false } | ||
| memcache = { version = "0.21", optional = true, default-features = false } |
There was a problem hiding this comment.
MSRV break in crates/cachekit/Cargo.toml line 92: memcache moves to 0.21, even though the comment directly above pins it at 0.19 because 0.20+ uses is_multiple_of and let-chains, which are unavailable under the workspace's declared rust-version = "1.85". Building with --features memcached on the 1.85 toolchain fails to compile the memcache dependency. Fix: revert to 0.19, or raise the workspace rust-version and update the comment in the same change.
memcache = { version = "0.19", optional = true, default-features = false }Prompt for LLM
File crates/cachekit/Cargo.toml:
Line 89 to 92:
MSRV break in crates/cachekit/Cargo.toml line 92: memcache moves to 0.21, even though the comment directly above pins it at 0.19 because 0.20+ uses `is_multiple_of` and let-chains, which are unavailable under the workspace's declared `rust-version = "1.85"`. Building with `--features memcached` on the 1.85 toolchain fails to compile the memcache dependency. Fix: revert to `0.19`, or raise the workspace rust-version and update the comment in the same change.
Suggested Code:
memcache = { version = "0.19", optional = true, default-features = false }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
c37e29c to
3340373
Compare
| worker = { version = "0.8", optional = true } | ||
| js-sys = { version = "0.3", optional = true } | ||
| getrandom = { version = "0.2", optional = true, features = ["js"] } | ||
| getrandom = { version = "0.4", optional = true, features = ["js"] } |
There was a problem hiding this comment.
Build break in the workers feature (Cargo.toml:100): getrandom 0.4 has no js feature because it was renamed to wasm_js in 0.3, and the direct dependency no longer matches the getrandom 0.2.17 that cachekit-core, ring and rand_core 0.6 still use (Cargo.lock lines 200, 1538, 1451). Dependency resolution fails, and even with the feature renamed, those transitive 0.2 copies lose js and hit getrandom's unsupported-target compile_error on wasm32-unknown-unknown, the only target where workers is used. Fix: keep getrandom = { version = "0.2", optional = true, features = ["js"] }, and add any needed 0.4 entry under a different name with features = ["wasm_js"].
getrandom = { version = "0.2", optional = true, features = ["js"] }Prompt for LLM
File crates/cachekit/Cargo.toml:
Line 100:
Build break in the `workers` feature (Cargo.toml:100): getrandom 0.4 has no `js` feature because it was renamed to `wasm_js` in 0.3, and the direct dependency no longer matches the getrandom 0.2.17 that cachekit-core, ring and rand_core 0.6 still use (Cargo.lock lines 200, 1538, 1451). Dependency resolution fails, and even with the feature renamed, those transitive 0.2 copies lose `js` and hit getrandom's unsupported-target compile_error on wasm32-unknown-unknown, the only target where `workers` is used. Fix: keep `getrandom = { version = "0.2", optional = true, features = ["js"] }`, and add any needed 0.4 entry under a different name with `features = ["wasm_js"]`.
Suggested Code:
getrandom = { version = "0.2", optional = true, features = ["js"] }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
|
|
||
| # Optional: Cloudflare Workers | ||
| worker = { version = "0.4", optional = true } | ||
| worker = { version = "0.8", optional = true } |
There was a problem hiding this comment.
Breaking upgrade in the Workers backend (Cargo.toml:98): worker jumps from 0.4 to 0.8, four breaking releases, with no matching changes to workers.rs, which depends on RequestInit::with_method/with_headers/with_body, Request::new_with_init and Fetch::Request(..).send(). worker 0.8 requires a newer wasm-bindgen than the one the exact-pinned wasm-bindgen-test = "=0.3.71" matches (Cargo.toml:136-139), so resolution fails or the wasm32 test runner diverges from the resolved wasm-bindgen, and --locked builds fail because Cargo.lock still pins worker 0.4.2. Fix: hold worker at 0.4, or bump worker, the wasm-bindgen-test pin, the lockfile and the CI runner together and adapt workers.rs.
worker = { version = "0.4", optional = true }Prompt for LLM
File crates/cachekit/Cargo.toml:
Line 98:
Breaking upgrade in the Workers backend (Cargo.toml:98): worker jumps from 0.4 to 0.8, four breaking releases, with no matching changes to workers.rs, which depends on RequestInit::with_method/with_headers/with_body, Request::new_with_init and Fetch::Request(..).send(). worker 0.8 requires a newer wasm-bindgen than the one the exact-pinned `wasm-bindgen-test = "=0.3.71"` matches (Cargo.toml:136-139), so resolution fails or the wasm32 test runner diverges from the resolved wasm-bindgen, and `--locked` builds fail because Cargo.lock still pins worker 0.4.2. Fix: hold worker at 0.4, or bump worker, the wasm-bindgen-test pin, the lockfile and the CI runner together and adapt workers.rs.
Suggested Code:
worker = { version = "0.4", optional = true }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
|
|
||
| # Optional: HTTP backend (native) | ||
| reqwest = { version = "0.12", optional = true, default-features = false, features = ["rustls-tls", "json"] } | ||
| reqwest = { version = "0.13", optional = true, default-features = false, features = ["rustls-tls", "json"] } |
There was a problem hiding this comment.
Feature-flag break in the reqwest dependency (Cargo.toml:80): reqwest is bumped to 0.13, which reorganized its TLS features around rustls, but the entry still requests rustls-tls, and Cargo.lock still pins reqwest 0.12.28. --locked builds of the default cachekitio feature fail, and without a valid rustls feature the client has no TLS backend for HTTPS requests to cachekit.io. Fix: switch to the 0.13 rustls feature name and update Cargo.lock, or hold at 0.12.
reqwest = { version = "0.12", optional = true, default-features = false, features = ["rustls-tls", "json"] }Prompt for LLM
File crates/cachekit/Cargo.toml:
Line 80:
Feature-flag break in the reqwest dependency (Cargo.toml:80): reqwest is bumped to 0.13, which reorganized its TLS features around `rustls`, but the entry still requests `rustls-tls`, and Cargo.lock still pins reqwest 0.12.28. `--locked` builds of the default `cachekitio` feature fail, and without a valid rustls feature the client has no TLS backend for HTTPS requests to cachekit.io. Fix: switch to the 0.13 rustls feature name and update Cargo.lock, or hold at 0.12.
Suggested Code:
reqwest = { version = "0.12", optional = true, default-features = false, features = ["rustls-tls", "json"] }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
| # which is why it was dropped). Held at 0.19: 0.20.0 | ||
| # uses `is_multiple_of`/let-chains and breaks this workspace's 1.85 MSRV. | ||
| memcache = { version = "0.19", optional = true, default-features = false } | ||
| memcache = { version = "0.21", optional = true, default-features = false } |
There was a problem hiding this comment.
WHAT: memcache is bumped to 0.21, but the comment directly above says it is held at 0.19 because 0.20+ breaks the 1.85 MSRV. WHY: This is an unexpected version jump that contradicts the documented constraint. There is no audit evidence, and the transitive dependencies may change. HOW: Either keep 0.19, or raise the MSRV and update the comment. Also provide cargo audit / OSV output.
Also found in:
crates/cachekit/Cargo.toml:100-100crates/cachekit/Cargo.toml:66-66crates/cachekit/Cargo.toml:98-98crates/cachekit/Cargo.toml:80-80
Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk
Prompt for LLM
File crates/cachekit/Cargo.toml:
Line 92:
WHAT: memcache is bumped to 0.21, but the comment directly above says it is held at 0.19 because 0.20+ breaks the 1.85 MSRV. WHY: This is an unexpected version jump that contradicts the documented constraint. There is no audit evidence, and the transitive dependencies may change. HOW: Either keep 0.19, or raise the MSRV and update the comment. Also provide cargo audit / OSV output.
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
| # which is why it was dropped). Held at 0.19: 0.20.0 | ||
| # uses `is_multiple_of`/let-chains and breaks this workspace's 1.85 MSRV. | ||
| memcache = { version = "0.19", optional = true, default-features = false } | ||
| memcache = { version = "0.21", optional = true, default-features = false } |
There was a problem hiding this comment.
MSRV break in the memcached dependency (Cargo.toml:92): memcache is bumped to 0.21 even though the comment directly above says 0.20+ uses is_multiple_of/let-chains, and the workspace still declares rust-version = "1.85". Building with --features memcached on Rust 1.85, including in the MSRV CI job, fails to compile inside memcache, and --locked builds also fail because Cargo.lock still pins memcache 0.19.0. Fix: revert to 0.19, or raise the workspace rust-version and remove the stale comment.
memcache = { version = "0.19", optional = true, default-features = false }Prompt for LLM
File crates/cachekit/Cargo.toml:
Line 90 to 92:
MSRV break in the `memcached` dependency (Cargo.toml:92): memcache is bumped to 0.21 even though the comment directly above says 0.20+ uses `is_multiple_of`/let-chains, and the workspace still declares `rust-version = "1.85"`. Building with `--features memcached` on Rust 1.85, including in the MSRV CI job, fails to compile inside memcache, and `--locked` builds also fail because Cargo.lock still pins memcache 0.19.0. Fix: revert to 0.19, or raise the workspace rust-version and remove the stale comment.
Suggested Code:
memcache = { version = "0.19", optional = true, default-features = false }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
3340373 to
4260541
Compare
This comment has been minimized.
This comment has been minimized.
4260541 to
1f376d1
Compare
| worker = { version = "0.8", optional = true } | ||
| js-sys = { version = "0.3", optional = true } | ||
| getrandom = { version = "0.2", optional = true, features = ["js"] } | ||
| getrandom = { version = "0.4", optional = true, features = ["js"] } |
There was a problem hiding this comment.
Broken feature in the getrandom dependency: getrandom 0.3+ removed the js feature (the wasm backend is now wasm_js), so getrandom = { version = "0.4", features = ["js"] } does not resolve, and a 0.4 dep does not enable the JS backend for the getrandom 0.2 that other crates still use (Cargo.lock has both 0.2.17 and 0.4.2). Any build with --features workers fails at dependency resolution. Fix: keep getrandom = { version = "0.2", features = ["js"] }, or, if 0.4 is required, use wasm_js with its backend cfg and keep a 0.2 js entry.
getrandom = { version = "0.2", optional = true, features = ["js"] }Prompt for LLM
File crates/cachekit/Cargo.toml:
Line 100:
Broken feature in the getrandom dependency: getrandom 0.3+ removed the `js` feature (the wasm backend is now `wasm_js`), so `getrandom = { version = "0.4", features = ["js"] }` does not resolve, and a 0.4 dep does not enable the JS backend for the getrandom 0.2 that other crates still use (Cargo.lock has both 0.2.17 and 0.4.2). Any build with `--features workers` fails at dependency resolution. Fix: keep `getrandom = { version = "0.2", features = ["js"] }`, or, if 0.4 is required, use `wasm_js` with its backend cfg and keep a 0.2 `js` entry.
Suggested Code:
getrandom = { version = "0.2", optional = true, features = ["js"] }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
|
|
||
| # Optional: HTTP backend (native) | ||
| reqwest = { version = "0.12", optional = true, default-features = false, features = ["rustls-tls", "json"] } | ||
| reqwest = { version = "0.13", optional = true, default-features = false, features = ["rustls-tls", "json"] } |
There was a problem hiding this comment.
Removed feature in the reqwest dependency: reqwest 0.13 renamed rustls-tls to rustls, so features = ["rustls-tls", "json"] no longer resolves, and the lockfile still pins reqwest 0.12.28. Because cachekitio is a default feature, the default build fails for every consumer. Fix: stay on 0.12, or switch to the 0.13 rustls feature name and confirm the default-features = false TLS setup still excludes native-tls/openssl.
reqwest = { version = "0.12", optional = true, default-features = false, features = ["rustls-tls", "json"] }Prompt for LLM
File crates/cachekit/Cargo.toml:
Line 80:
Removed feature in the reqwest dependency: reqwest 0.13 renamed `rustls-tls` to `rustls`, so `features = ["rustls-tls", "json"]` no longer resolves, and the lockfile still pins reqwest 0.12.28. Because `cachekitio` is a default feature, the default build fails for every consumer. Fix: stay on 0.12, or switch to the 0.13 `rustls` feature name and confirm the `default-features = false` TLS setup still excludes native-tls/openssl.
Suggested Code:
reqwest = { version = "0.12", optional = true, default-features = false, features = ["rustls-tls", "json"] }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
| # which is why it was dropped). Held at 0.19: 0.20.0 | ||
| # uses `is_multiple_of`/let-chains and breaks this workspace's 1.85 MSRV. | ||
| memcache = { version = "0.19", optional = true, default-features = false } | ||
| memcache = { version = "0.21", optional = true, default-features = false } |
There was a problem hiding this comment.
MSRV break in the memcache dependency: the version is bumped to 0.21, contradicting the comment directly above that holds it at 0.19 because 0.20+ breaks the workspace's 1.85 MSRV. MSRV builds on Rust 1.85 with the memcached feature fail to compile. Fix: revert to 0.19, or raise the MSRV explicitly, update the comment, and commit the updated lockfile.
Also found in:
crates/cachekit/Cargo.toml:66-66crates/cachekit/Cargo.toml:100-100crates/cachekit/Cargo.toml:80-80crates/cachekit/Cargo.toml:98-98
Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk
Prompt for LLM
File crates/cachekit/Cargo.toml:
Line 92:
MSRV break in the memcache dependency: the version is bumped to 0.21, contradicting the comment directly above that holds it at 0.19 because 0.20+ breaks the workspace's 1.85 MSRV. MSRV builds on Rust 1.85 with the `memcached` feature fail to compile. Fix: revert to 0.19, or raise the MSRV explicitly, update the comment, and commit the updated lockfile.
**Also found in:**
- `crates/cachekit/Cargo.toml:66-66`
- `crates/cachekit/Cargo.toml:100-100`
- `crates/cachekit/Cargo.toml:80-80`
- `crates/cachekit/Cargo.toml:98-98`
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
| # which is why it was dropped). Held at 0.19: 0.20.0 | ||
| # uses `is_multiple_of`/let-chains and breaks this workspace's 1.85 MSRV. | ||
| memcache = { version = "0.19", optional = true, default-features = false } | ||
| memcache = { version = "0.21", optional = true, default-features = false } |
There was a problem hiding this comment.
MSRV break in the memcache dependency: the version moves to 0.21, but the comment above it pins 0.19 because 0.20+ uses is_multiple_of and let-chains, and the workspace still sets rust-version = "1.85". Running cargo +1.85 build --features memcached (MSRV CI and downstream users on 1.85) fails to compile. Fix: revert to version = "0.19", or raise the workspace rust-version to what memcache 0.21 requires and update the comment.
# Held at 0.19: 0.20.0
# uses `is_multiple_of`/let-chains and breaks this workspace's 1.85 MSRV.
memcache = { version = "0.19", optional = true, default-features = false }Prompt for LLM
File crates/cachekit/Cargo.toml:
Line 90 to 92:
MSRV break in the memcache dependency: the version moves to 0.21, but the comment above it pins 0.19 because 0.20+ uses `is_multiple_of` and let-chains, and the workspace still sets `rust-version = "1.85"`. Running `cargo +1.85 build --features memcached` (MSRV CI and downstream users on 1.85) fails to compile. Fix: revert to `version = "0.19"`, or raise the workspace `rust-version` to what memcache 0.21 requires and update the comment.
Suggested Code:
# Held at 0.19: 0.20.0
# uses `is_multiple_of`/let-chains and breaks this workspace's 1.85 MSRV.
memcache = { version = "0.19", optional = true, default-features = false }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
|
|
||
| # Optional: Cloudflare Workers | ||
| worker = { version = "0.4", optional = true } | ||
| worker = { version = "0.8", optional = true } |
There was a problem hiding this comment.
API break in the worker dependency: the version jumps from 0.4 to 0.8 (four breaking 0.x releases) while workers.rs uses RequestInit::new().with_method/with_headers/with_body, Request::new_with_init, Fetch::Request(..).send(), and Response::bytes/status_code, and the newer worker pulls a newer wasm-bindgen than the exact wasm-bindgen-test = "=0.3.71" pin allows. A --features workers build or the wasm test runner fails on the API or wasm-bindgen version mismatch. Fix: bump worker together with the matching wasm-bindgen-test pin and CI runner, and build with --features workers --target wasm32-unknown-unknown before merging.
worker = { version = "0.4", optional = true }Prompt for LLM
File crates/cachekit/Cargo.toml:
Line 98:
API break in the worker dependency: the version jumps from 0.4 to 0.8 (four breaking 0.x releases) while workers.rs uses `RequestInit::new().with_method/with_headers/with_body`, `Request::new_with_init`, `Fetch::Request(..).send()`, and `Response::bytes/status_code`, and the newer worker pulls a newer wasm-bindgen than the exact `wasm-bindgen-test = "=0.3.71"` pin allows. A `--features workers` build or the wasm test runner fails on the API or wasm-bindgen version mismatch. Fix: bump worker together with the matching wasm-bindgen-test pin and CI runner, and build with `--features workers --target wasm32-unknown-unknown` before merging.
Suggested Code:
worker = { version = "0.4", optional = true }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
1f376d1 to
aaa9218
Compare
This PR contains the following updates:
1.11.1→1.12.10.2.183→0.2.1890.12.14→0.12.161.0.106→1.0.1071.0.45→1.0.471.1.4→1.1.51.0.228→1.0.2291.0.149→1.0.1512.0.117→2.0.1192.0.18→2.0.211.50.0→1.53.11.22.0→1.26.11.8.2→1.9.0Release Notes
tokio-rs/bytes (bytes)
v1.12.1Compare Source
Fixed
Box::newpanics (#837)v1.12.0Compare Source
Added
BytesMut::extend_from_within()(#818)BytesMut::try_unsplit()(#746)Fixed
get_intifnbytesis zero (#806)Changed
Documented
BytesMut::{reserve,try_reserve}doesn't preserve unused capacity (#808)rust-lang/libc (libc)
v0.2.189Compare Source
Added
pthread_sigmask,sigwait,sigwaitinfo,sigtimedwait,faccessat, andpthread_kill(#5270)clone3syscall (#4980)CLOCK_PROCESS_CPUTIME_IDandCLOCK_THREAD_CPUTIME_ID(#5274)Deprecated
CLONE_INTO_CGROUPandCLONE_CLEAR_SIGHAND. These overflow their types and will be changed to a larger size in the future. (8c6e6710458d)Fixed
wchar_tdefinition under Arm (#5245)time-related symbols (#5300)v0.2.188Compare Source
Changed
SendandSyncforDIR(35b062263401)These were removed in 0.2.187 because
libcdoes not actually makeSendandSyncguarantees about
DIR(or other extern types), but this caused some crates to break.The traits are added back for now to allow time to migrate, but will be removed again
in the future; please make sure your crates are not relying on
libc::DIR: Sendorlibc::DIR: Sync.v0.2.187Compare Source
This release contains a number of improvements related to 64-bit
time_tconfiguration.Of note the existing
RUST_LIBC_UNSTABLE_*environment variables have been replacedwith configuration options. The new way to use these is:
Being able to set this via
RUSTFLAGSmakes it easier to only apply configuration tospecific targets (and notably, not the host if build scripts are used).
There are two other notable changes:
The 32-bit
windows-gnutargets now respectlibc_unstable_gnu_time_bitsuClibc now supports a similar configuration option:
RUSTFLAGS='--cfg=libc_unstable_uclibc_time64'As a reminder, these options are under active development and may change in the future
(hence the "unstable" in the name). It likely that we will harmonize everything under a
single configuration option before considering them stable.
Support
aarch64-unknown-linux-pauthtest(#5065)Added
POSIX_SPAWN_*constants (#5104)getpwent,setpwent, andendpwent(#5160)preadv2andpwritev2(#5157)seccomp_notif*structures (#5224)timer_[create, delete, getoverrun, gettime, settime](#5108)PROC_PIDT_SHORTBSDINFOandproc_bsdshortinfo(#5110)SIOC*constants fromsockio.h(#5263)_IOR,_IOW,_IOWR(#5264)bpf_programandbpf_insn(#5235)kqueueconstants (#5077)vm_statistics64with recently added fields (#5253)IN6_IFF_*andSIOCGIFAFLAG_IN6(#5239)O_*,POSIX_FADV_*,NI*, and a few other missing constants (#5116)fdatasync,dlvsym,reallocarray,qsort_r,pthread_*affinity_np,ftok,extattr_*, anddup3(#5116)in6_pktinfo(#5256)DLT_*constants (#5235)PROC_LOGSIGEXIT_*andPPROT_*(#4657)SO_RERROR(#5260)IN6_IFF_*,in6_ifreq, andSIOCGIFAFLAG_IN6(#5239)_IO*helpers fromsys/ioccom.h(#5239)PTHREAD_*_MUTEX_INITIALIZER_NPfor riscv64 (#5094)struct tcp_info(#5215)OPEN_TREE_NAMESPACE(#5145)SECCOMP_IOCTL_*constants (#5224)SO_DETACH_REUSEPORT_BPF(#5081)futex_waitv(#5125)fsopen,fsconfig,fsmount, andfspick(#5145)statxpresent since 6.16 (#4621)ifaddrmsgandrtattr(#5234)sockaddr_iucv(#5041)ENOTCAPABLE(#4925)renameat2(#5113)F_SETFD(#5258)POLLRD*andPOLLWR*constants (#5258)SO_KEEPALIVEand TCP keepalive constants (#5111)TCP_MAXSEG(#5258)eventfdandEFD_*constants (#5258)pipe2(#5258)strerror_r(#5258)netinetstructs and constants (#5258)*atanddirentfunctions (#5117)port_alertandPORT_ALERT*constants (#5203)Deprecated
CPUCTL_RSMSRandUTX_DB_LASTLOG(#5116)Fixed
tsfrom*const timespecto*mut timespecin _lwp_park` (#5169)PTRACE_*ET_SYSCALL_USER_DISPATCH_CONFIGconstants fromu8toc_uint(#4936)cpuset_ttypo inCPU_ZERO(#5098)ifaddrs, pthread barriers, process sizing fields, andmcontextalignment (#5116)CPUCTL_CPUID*,EV_HUP, andEV_SYSFLAGS(#5116)POLLOUT(#5090)EPIOC[GS]PARAMSwith nonstandard _IOC (#5188)unsafe(#3727)__getmntinfo13(#5251)PTHREAD_MUTEX_INITIALIZER(#5241)Changed
-> c_void(#5240)AIO_LISTIO_MAXto account for changes in macOS 27 (#5253)MS_NOUSER(#5215)SW_MAXandSW_CNT(#5215)swapped_counttovm_statistics64(#4926)libc_unstable_gnu_time_bitsfor 64-bittime_tconfig (#5062)Removed
Elf32_Lword,ip_mreq_source, andIP_constants (#5116)KERN_REALROOTDEVandVM_LAPTOP_MODE(#5177)Other
LIBC_BUILD_VERBOSEis set (#5272)*LASTconstants as potentially changing (#5120)*MAXconstants as potentially changing (#5122)ELASTconstants as potentially changing (#5118)RAND_MAXas potentially changing (#5119)*NUMconstants as potentially changing (#5123)*COUNTconstants as potentially changing (#5121)time_t(#5046)RUST_LIBC_UNSTABLE_LINUX_TIME_BITS64(#5197)RUST_LIBC_UNSTABLEenv withlibc_unstable*cfg (#4977)v0.2.186Compare Source
Added
KEVENT_FLAG_*constants (#5070)PR_SET_MEMORY_MERGEandPR_GET_MEMORY_MERGE(#5060)Changed
v0.2.185Compare Source
Added
espidf_picolibccfg for picolibcO_*flag values (#5035)sprintf,snprintf, and thescanffamily (#5024)Fixed
time64types from musl symbol redirects (#5040)POLLconstants fromc_shorttoc_int(#5045)v0.2.184Compare Source
MSRV
This release increases the MSRV of
libcto 1.65. With this update, you can now always use thecore::ffi::c_*types withlibcdefinitions, sincelibchas been changed to reexport fromcorerather than redefining them. (This usually worked before but had edge cases.)(#4972)
Added
IP_MINTTLto bsd (#5026)TIOCM_DSR(#5031)xfilestructe and file descriptor types (#5002)struct ethhdr(#4239)struct ifinfomsg(#5012)max_align_tfor riscv64 (#5029)CLOCK_constants (#5020)_SC_HOST_NAME_MAX(#5004)flockandF_*LCKconstants (#4043)_SC_*sysconf constants (#5023)Deprecated
The remaining fixed-width integer aliases,
__uint128_t,__uint128,__int128_t, and__int128,have been deprecated. Use
i128andu128instead. (#4343)Fixed
DT_*constants (#5034)RTLD_NOLOAD, some TCP constants (#5025)Padding::new(<zeroed>)rather thanPadding::uninit()(#5036)Changed
struct ptrace_syscall_info(#4966)core::ffiinteger types rather than redefining (#5015)F_DUPFD,IP, andTCPconstants to match relibc (#4990)moka-rs/moka (moka)
v0.12.16Compare Source
Fixed
configured with the non-default LRU eviction policy (
EvictionPolicy::lru())by a race between insert and remove operations on the same key
([#592][gh-pull-0592] by [@kim-jhyeon][gh-kim-jhyeon], reported in
[#590][gh-issue-0590]):
sync::Cache,sync::SegmentedCacheandfuture::Cache.removing that entry from the internal concurrent hash table could leave an
orphaned node at the front of the LRU queue. Once present, no entry was ever
evicted again and the cache grew unboundedly past
max_capacity.a milder symptom: each occurrence permanently leaked one phantom entry
slot, causing
entry_countandweighted_sizeto over-report and theusable capacity to shrink by one entry per occurrence. Fixed by the same
change.
Changed
fence(Acquire)in the internalMiniArc's droppath with an
Acquireload of the reference count, so that downstreamprojects can now run ThreadSanitizer on code using Moka without hitting
this false positive.
std::sync::Archas a similar workaround.crossbeam-epochcrate fromv0.9.18tov0.9.20to avoid the following advisory ([#603][gh-pull-0603]):fmt::PointerforAtomicandSharedpointer types. However, raising the minimum version prevents downstream
lockfiles from resolving to an affected
crossbeam-epochversion viaMoka.
v0.12.15Compare Source
Fixed
expiration time and remain in the cache indefinitely when using a custom
Expirypolicy with per-entry expiration. ([#582][gh-pull-0582] by [@jiangzhe][gh-jiangzhe],
[#581][gh-pull-0581] by [@atrocities][gh-atrocities], reported in
[#575][gh-issue-0575]):
re-inserted, and
expire_after_updatereturnedNone. This primarilyaffected users who only override
expire_after_create, since the defaultexpire_after_updatereturnsduration_until_expiry, which isNoneforexpired entries.
[#564][gh-pull-0564]).
so
Expiry::expire_after_updatewas called.so
Expiry::expire_after_createis called instead.your
Expirytrait implementation.cht::segment::tests::drop_many_valuesanddrop_many_values_concurrentthat were failing on high-core-count machines([#586][gh-pull-0586]):
bucket array shrinking behavior of the internal segmented hash map across
different machines.
Changed
run_flaky_testscfg([#584][gh-pull-0584]):
crossbeam-epoch) timingthat is not guaranteed, causing intermittent failures.
RUSTFLAGS='--cfg run_flaky_tests'.dtolnay/proc-macro2 (proc-macro2)
v1.0.107Compare Source
dtolnay/quote (quote)
v1.0.47Compare Source
v1.0.46Compare Source
get_spaninquote_spanned(#329, thanks @Noratrieb)bytecodealliance/rustix (rustix)
v1.1.5Compare Source
serde-rs/serde (serde)
v1.0.229Compare Source
serde-rs/json (serde_json)
v1.0.151Compare Source
v1.0.150Compare Source
dtolnay/syn (syn)
v2.0.119Compare Source
v2.0.118Compare Source
dtolnay/thiserror (thiserror)
v2.0.21Compare Source
v2.0.20Compare Source
v2.0.19Compare Source
tokio-rs/tokio (tokio)
v1.53.1: Tokio v1.53.1Compare Source
1.53.1 (July 20th, 2026)
Fixed
OnceLock::waitfrom the Windows handler (#8300)Fixed (unstable)
Documented
v1.53.0: Tokio v1.53.0Compare Source
1.53.0 (July 17th, 2026)
Added
From<OwnedFd>andFrom<OwnedHandle>forFile(#8266)SocketAddrmethods to Unix sockets (#8144)Changed
#[inline]to IO trait impls for in-memory types (#8242)mpsc::{Receiver,UnboundedReceiver}now drops waker on drop, even if there are still senders (#8095)#[track_caller]totimeout_at()(#8077)Sleep(#8132)Fixed
Chain(#8251)FastRand(#8078)reserve[_many]returns permits (#8260)Trace::capture/Trace::trace_with(#8043).reset()(#8169)IO uring (unstable)
fs::try_exists(#8080)Documented
create_dir_allsucceeds if path exists (#8149)try_read*/try_write*readiness behavior (#8032)yield_nowdefers its waker (#8254)timeout_at()(#8077)v1.52.4: Tokio v1.52.4Compare Source
1.52.4 (July 16th, 2026)
Fixed
before_parkschedules work (#8222)Fixed (unstable)
v1.52.3: Tokio v1.52.3Compare Source
1.52.3 (May 8th, 2026)
Fixed
len()(#8062)OwnedPermit::release()method (#8075)RwLockhasmax_readers != 0(#8076)Emptyfromtry_recv()when mpsc is closed with outstanding permits (#8074)v1.52.2: Tokio v1.52.2Compare Source
1.52.2 (May 4th, 2026)
This release reverts the LIFO slot stealing change introduced in 1.51.0 (#7431), due to its performance impact. (#8100)
v1.52.1: Tokio v1.52.1Compare Source
1.52.1 (April 16th, 2026)
Fixed
spawn_blockingto hang (#8057)v1.52.0: Tokio v1.52.0Compare Source
1.52.0 (April 14th, 2026)
Added
AioSource::register_borrowedfor I/O safety support (#7992)try_iofunction tounix::pipesender and receiver types (#8030)Added (unstable)
Builder::enable_eager_driver_handoffsetting enable eager hand off of the I/O and time drivers before polling tasks (#8010)trace_with()for customized task dumps (#8025)impl FnMut()intrace_withinstead of justfn()(#8040)io_uringinAsyncReadforFile(#7907)Changed
spawn_blockingscalability with sharded queue (#7757)compare_exchange_weak()in worker queue (#8028)Fixed
Documented
oneshot::Sender::senddocs (#8026)sync::watch(#8035)ConnectionRefusederrors with UDP sockets (#7870)v1.51.4: Tokio v1.51.4Compare Source
1.51.4 (July 16th, 2026)
Fixed
before_parkschedules work (#8222)v1.51.3: Tokio v1.51.3Compare Source
1.51.3 (May 8th, 2026)
Fixed
len()(#8062)OwnedPermit::release()method (#8075)RwLockhasmax_readers != 0(#8076)Emptyfromtry_recv()when mpsc is closed with outstanding permits (#8074)v1.51.2: Tokio v1.51.1Compare Source
1.51.2 (May 4th, 2026)
This release reverts the LIFO slot stealing change introduced in 1.51.0 (#7431), due to its performance impact. (#8100)
v1.51.1: Tokio v1.51.1Compare Source
1.51.1 (April 8th, 2026)
Fixed
SO_ERRORonrecvfor UDP sockets on Linux (#8001)Fixed (unstable)
worker_local_schedule_counttest (#8008)v1.51.0: Tokio v1.51.0Compare Source
1.51.0 (April 3rd, 2026)
Added
get_peer_credon Hurd (#7989)tokio::runtime::worker_index()(#7921)LocalRuntime(#7557)Changed
Fixed
notify_waiterspriority inNotify(#7996)Chan::recv_manywhen called with non-empty vector on closed channel (#7991)uuid-rs/uuid (uuid)
v1.26.1Compare Source
What's Changed
New Contributors
Full Changelog: uuid-rs/uuid@v1.26.0...v1.26.1
v1.26.0Compare Source
What's Changed
Full Changelog: uuid-rs/uuid@1.25.0...v1.26.0
v1.25.0Compare Source
What's Changed
New Contributors
Full Changelog: uuid-rs/uuid@v1.24.1...1.25.0
v1.24.1Compare Source
What's Changed
New Contributors
Full Changelog: uuid-rs/uuid@v1.24.0...v1.24.1
v1.24.0Compare Source
What's Changed
New Contributors
Full Changelog: uuid-rs/uuid@v1.23.5...v1.24.0
v1.23.5Compare Source
What's Changed
New Contributors
Full Changelog: uuid-rs/uuid@v1.23.4...v1.23.5
v1.23.4Compare Source
What's Changed
New Contributors
Full Changelog: uuid-rs/uuid@v1.23.3...v1.23.4
v1.23.3Compare Source
What's Changed
Full Changelog: uuid-rs/uuid@v1.23.2...v1.23.3
v1.23.2Compare Source
What's Changed
Full Changelog: uuid-rs/uuid@v1.23.1...v1.23.2
v1.23.1Compare Source
What's Changed
msrvfeature from wasm-bindgen dependency by @guybedford in #877New Contributors
Full Changelog: uuid-rs/uuid@v1.23.0...v1.23.1
v1.23.0Compare Source
What's Changed
New Contributors
Special thanks
@meng-xu-cs raised a series of bugs against the timestamp logic in
uuidusing automated tooling. The issues themselves were reasonably and responsibly presented and the end result is a betteruuidlibrary for everyone. Thanks!Deprecations
This release includes the following deprecations:
Context: Renamed toContextV1Timestamp::from_gregorian: Renamed toTimestamp::from_gregorian_timeChange to
Version::MaxVersion::Max'su8representation has changedConfiguration
📅 Schedule: (in timezone Australia/Sydney)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.