Skip to content

chore(deps): update rust-dev-deps - #94

Open
cachekit-renovate-bot[bot] wants to merge 1 commit into
mainfrom
renovate/rust-dev-deps
Open

cachekit-renovate-bot[bot] wants to merge 1 commit into
mainfrom
renovate/rust-dev-deps

Conversation

@cachekit-renovate-bot

@cachekit-renovate-bot cachekit-renovate-bot Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
serde_json dev-dependencies patch 1.0.149 → 1.0.151
serial_test dev-dependencies minor 3.4.0 → 3.5.0
tokio (source) dev-dependencies minor 1.50.0 → 1.53.1

Release Notes

serde-rs/json (serde_json)

v1.0.151

Compare Source

v1.0.150

Compare Source

palfrey/serial_test (serial_test)

v3.5.0

Compare Source

What's Changed

New Contributors

Full Changelog: palfrey/serial_test@v3.4.0...v3.5.0

tokio-rs/tokio (tokio)

v1.53.1: Tokio v1.53.1

Compare Source

1.53.1 (July 20th, 2026)

Fixed
  • signal: restore MSRV by removing OnceLock::wait from the Windows handler (#​8300)
Fixed (unstable)
  • time: fix alt timer cancellation and insertion race (#​8252)
Documented
  • runtime: remove dead link definition in Runtime::block_on (#​8301)

v1.53.0: Tokio v1.53.0

Compare Source

1.53.0 (July 17th, 2026)

Added
  • fs: implement From<OwnedFd> and From<OwnedHandle> for File (#​8266)
  • metrics: add task schedule latency metric (#​7986)
  • net: add SocketAddr methods to Unix sockets (#​8144)
Changed
  • io: add #[inline] to IO trait impls for in-memory types (#​8242)
  • net: implement UCred::pid on FreeBSD (#​8086)
  • net: support Nuttx target os (#​8259)
  • signal: refactor global variables on Windows (#​8231)
  • sync: mpsc::{Receiver,UnboundedReceiver} now drops waker on drop, even if there are still senders (#​8095)
  • taskdump: support taskdumps on s390x (#​8192)
  • time: add #[track_caller] to timeout_at() (#​8077)
  • time: consolidate mutex locks on spurious poll (#​8124)
  • time: defer waker clone on spurious poll (#​8107)
  • time: move lazy-registration state into Sleep (#​8132)
  • tracing: remove unnecessary span clone (#​8126)
Fixed
  • io: do not treat zero-length reads as EOF in Chain (#​8251)
  • net: use getpeereid for QNX peer credentials (#​8270)
  • runtime: avoid illegal state in FastRand (#​8078)
  • sync: wake mpsc receiver when a queued reserve[_many] returns permits (#​8260)
  • taskdump: skip double wake on Trace::capture/Trace::trace_with (#​8043)
  • time: avoid stack overflow in runtime constructor (#​8093)
  • time (alt timer): ensure timers stay in the same runtime after .reset() (#​8169)
IO uring (unstable)
  • fs: use io-uring for fs::try_exists (#​8080)
  • fs: use io-uring for renaming files (#​7800)
  • rt: flush io-uring CQE in case of CQE overflow (#​8277)
Documented
  • docs: clarify cancel safety wording (#​8181)
  • fs: clarify create_dir_all succeeds if path exists (#​8149)
  • io: add warning about stdout reordering with multiple handles (#​8276)
  • net: document pipe try_read*/try_write* readiness behavior (#​8032)
  • runtime: document interaction with fork() (#​8202)
  • sync: clarify broadcast lagging semantics (#​8239)
  • sync: document memory ordering guarantees for Semaphore (#​8119)
  • task: explain why yield_now defers its waker (#​8254)
  • time: add panic docs to timeout_at() (#​8077)
  • time: fix reversed poll order in timeout doc (#​8214)

v1.52.4: Tokio v1.52.4

Compare Source

1.52.4 (July 16th, 2026)

Fixed
  • runtime: don't skip the driver when before_park schedules work (#​8222)
Fixed (unstable)
  • taskdump: remove crate disambiguators from output (#​8264)

v1.52.3: Tokio v1.52.3

Compare Source

1.52.3 (May 8th, 2026)

Fixed
  • sync: fix underflow in mpsc channel len() (#​8062)
  • sync: notify receivers in mpsc OwnedPermit::release() method (#​8075)
  • sync: require that an RwLock has max_readers != 0 (#​8076)
  • sync: return Empty from try_recv() when mpsc is closed with outstanding permits (#​8074)

v1.52.2: Tokio v1.52.2

Compare Source

1.52.2 (May 4th, 2026)

This release reverts the LIFO slot stealing change introduced in 1.51.0 (#​7431), due to its performance impact. (#​8100)

v1.52.1: Tokio v1.52.1

Compare Source

1.52.1 (April 16th, 2026)

Fixed

v1.52.0: Tokio v1.52.0

Compare Source

1.52.0 (April 14th, 2026)

Added

  • io: AioSource::register_borrowed for I/O safety support (#​7992)
  • net: add try_io function to unix::pipe sender and receiver types (#​8030)

Added (unstable)

  • runtime: Builder::enable_eager_driver_handoff setting enable eager hand off of the I/O and time drivers before polling tasks (#​8010)
  • taskdump: add trace_with() for customized task dumps (#​8025)
  • taskdump: allow impl FnMut() in trace_with instead of just fn() (#​8040)
  • fs: support io_uring in AsyncRead for File (#​7907)

Changed

  • runtime: improve spawn_blocking scalability with sharded queue (#​7757)
  • runtime: use compare_exchange_weak() in worker queue (#​8028)

Fixed

  • runtime: overflow second half of tasks when local queue is filled instead of first half (#​8029)

Documented

  • docs: fix typo in oneshot::Sender::send docs (#​8026)
  • docs: hide #[tokio::main] attribute in the docs of sync::watch (#​8035)
  • net: add docs on ConnectionRefused errors with UDP sockets (#​7870)

v1.51.4: Tokio v1.51.4

Compare Source

1.51.4 (July 16th, 2026)

Fixed
  • runtime: don't skip the driver when before_park schedules work (#​8222)

v1.51.3: Tokio v1.51.3

Compare Source

1.51.3 (May 8th, 2026)

Fixed
  • sync: fix underflow in mpsc channel len() (#​8062)
  • sync: notify receivers in mpsc OwnedPermit::release() method (#​8075)
  • sync: require that an RwLock has max_readers != 0 (#​8076)
  • sync: return Empty from try_recv() when mpsc is closed with outstanding permits (#​8074)

v1.51.2: Tokio v1.51.1

Compare Source

1.51.2 (May 4th, 2026)

This release reverts the LIFO slot stealing change introduced in 1.51.0 (#​7431), due to its performance impact. (#​8100)

v1.51.1: Tokio v1.51.1

Compare Source

1.51.1 (April 8th, 2026)

Fixed
  • sync: fix semaphore reopens after forget (#​8021)
  • net: surface errors from SO_ERROR on recv for UDP sockets on Linux (#​8001)
Fixed (unstable)
  • metrics: fix worker_local_schedule_count test (#​8008)
  • rt: do not leak fd when cancelling io_uring open operation (#​7983)

v1.51.0: Tokio v1.51.0

Compare Source

1.51.0 (April 3rd, 2026)

Added
  • net: implement get_peer_cred on Hurd (#​7989)
  • runtime: add tokio::runtime::worker_index() (#​7921)
  • runtime: add runtime name (#​7924)
  • runtime: stabilize LocalRuntime (#​7557)
  • wasm: add wasm32-wasip2 networking support (#​7933)
Changed
  • runtime: steal tasks from the LIFO slot (#​7431)
Fixed
  • docs: do not show "Available on non-loom only." doc label (#​7977)
  • macros: improve overall macro hygiene (#​7997)
  • sync: fix notify_waiters priority in Notify (#​7996)
  • sync: fix panic in Chan::recv_many when called with non-empty vector on closed channel (#​7991)

Configuration

📅 Schedule: (in timezone Australia/Sydney)

  • Branch creation
    • "before 6am"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: cachekit-io/cachekit-rs/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 2274ef1d-ddbf-441a-8b1f-0773dba6ce5d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@kodus-27b

kodus-27b Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

Kody Code Review — 1 suggested fix.
Paste the prompt below to your agent and all review fixed at once!

🛠️ Open Agent Prompt
A code review identified the following issues in this pull request.
Each section describes what was found and includes a reference implementation where available.

Files involved:
- crates/cachekit/Cargo.toml:141

---

### [1/1] crates/cachekit/Cargo.toml:141
Issue identified during code review:
Version drift in crates/cachekit/Cargo.toml: bumping wasm-bindgen-test to =0.3.78 locks wasm-bindgen 0.2.128 in Cargo.lock, but .github/workflows/ci.yml:167 still pins WASM_BINDGEN_VERSION "0.2.121" and the old SHA256, even though the file's own comment requires the pin, lockfile, and ci.yml runner pin to be bumped together. On every CI run, the 'Guard wasm-bindgen lockfile drift' step (ci.yml:187-193) sees locked=0.2.128 != 0.2.121 and exits 1, so the wasm32 runtime test job always fails; without the guard, the 0.2.121 wasm-bindgen-test-runner would still reject binaries built against 0.2.128 due to their shared private ABI. Fix: in ci.yml, set WASM_BINDGEN_VERSION to "0.2.128" and WASM_BINDGEN_SHA256 to the checksum of the 0.2.128 x86_64-unknown-linux-musl release tarball in the same PR.
Reference implementation (from code review):

// crates/cachekit/Cargo.toml:141
wasm-bindgen-test = "=0.3.78"
# plus in .github/workflows/ci.yml:
#   WASM_BINDGEN_VERSION: "0.2.128"
#   WASM_BINDGEN_SHA256: "<sha256 of wasm-bindgen-0.2.128-x86_64-unknown-linux-musl.tar.gz>"

---

Review each issue in context, use the reference implementations as guidance, and apply fixes that are consistent with the surrounding codebase.

Comment thread crates/cachekit/Cargo.toml Outdated
@kodus-27b

This comment has been minimized.

Comment thread crates/cachekit/Cargo.toml Outdated
# byte-for-byte (bump this, the lockfile, and the runner pin in ci.yml together).
[target.'cfg(target_arch = "wasm32")'.dev-dependencies]
wasm-bindgen-test = "=0.3.71"
wasm-bindgen-test = "=0.3.78"

ghost Sep 30, 2026

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

WHAT: The wasm-bindgen-test dev-dependency is bumped from =0.3.71 to =0.3.78 without any vulnerability or supply-chain evidence. WHY: Dependency manifest changes must be checked for known CVEs. This crate is also tightly coupled to the locked wasm-bindgen version and the CI runner pin, so a partial bump can break CI or pull in unexpected transitive changes. HOW: Run cargo audit and/or an OSV query for wasm-bindgen-test 0.3.78 and link the results in the PR description. Confirm that Cargo.lock (wasm-bindgen) and the runner pin in ci.yml were updated together, as the comment above requires.

Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk

Prompt for LLM

File crates/cachekit/Cargo.toml:

Line 141:

WHAT: The wasm-bindgen-test dev-dependency is bumped from =0.3.71 to =0.3.78 without any vulnerability or supply-chain evidence. WHY: Dependency manifest changes must be checked for known CVEs. This crate is also tightly coupled to the locked wasm-bindgen version and the CI runner pin, so a partial bump can break CI or pull in unexpected transitive changes. HOW: Run `cargo audit` and/or an OSV query for wasm-bindgen-test 0.3.78 and link the results in the PR description. Confirm that Cargo.lock (wasm-bindgen) and the runner pin in ci.yml were updated together, as the comment above requires.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Comment thread crates/cachekit/Cargo.toml Outdated
Comment on lines +140 to +141
[target.'cfg(target_arch = "wasm32")'.dev-dependencies]
wasm-bindgen-test = "=0.3.71"
wasm-bindgen-test = "=0.3.78"

ghost Sep 30, 2026

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug medium

Version mismatch in crates/cachekit/Cargo.toml:141: bumping wasm-bindgen-test to =0.3.78 moves Cargo.lock to wasm-bindgen 0.2.128, but .github/workflows/ci.yml:167 still pins WASM_BINDGEN_VERSION "0.2.121" and the matching WASM_BINDGEN_SHA256, and this PR does not update ci.yml. When the 'Guard wasm-bindgen lockfile drift' step (ci.yml:189-195) runs cargo pkgid wasm-bindgen, it gets 0.2.128, compares it with 0.2.121, and exits 1, failing the wasm32 runtime-test job; even without the guard, the 0.2.121 runner cannot run 0.2.128 test binaries because of the ABI lockstep, which breaks the wasm32 runtime coverage added for LAB-1079. Fix: in the same PR, set WASM_BINDGEN_VERSION to "0.2.128" in ci.yml and set WASM_BINDGEN_SHA256 to the checksum of the 0.2.128 x86_64-unknown-linux-musl release tarball.

# crates/cachekit/Cargo.toml (unchanged)
wasm-bindgen-test = "=0.3.78"

# .github/workflows/ci.yml
      WASM_BINDGEN_VERSION: "0.2.128"
      WASM_BINDGEN_SHA256: "<sha256 of wasm-bindgen-0.2.128-x86_64-unknown-linux-musl.tar.gz>"
Prompt for LLM

File crates/cachekit/Cargo.toml:

Line 140 to 141:

Version mismatch in crates/cachekit/Cargo.toml:141: bumping wasm-bindgen-test to =0.3.78 moves Cargo.lock to wasm-bindgen 0.2.128, but .github/workflows/ci.yml:167 still pins WASM_BINDGEN_VERSION "0.2.121" and the matching WASM_BINDGEN_SHA256, and this PR does not update ci.yml. When the 'Guard wasm-bindgen lockfile drift' step (ci.yml:189-195) runs `cargo pkgid wasm-bindgen`, it gets 0.2.128, compares it with 0.2.121, and exits 1, failing the wasm32 runtime-test job; even without the guard, the 0.2.121 runner cannot run 0.2.128 test binaries because of the ABI lockstep, which breaks the wasm32 runtime coverage added for LAB-1079. Fix: in the same PR, set WASM_BINDGEN_VERSION to "0.2.128" in ci.yml and set WASM_BINDGEN_SHA256 to the checksum of the 0.2.128 x86_64-unknown-linux-musl release tarball.

Suggested Code:

# crates/cachekit/Cargo.toml (unchanged)
wasm-bindgen-test = "=0.3.78"

# .github/workflows/ci.yml
      WASM_BINDGEN_VERSION: "0.2.128"
      WASM_BINDGEN_SHA256: "<sha256 of wasm-bindgen-0.2.128-x86_64-unknown-linux-musl.tar.gz>"

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

@kodus-27b

ghost commented Sep 30, 2026

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

@cachekit-renovate-bot
cachekit-renovate-bot Bot force-pushed the renovate/rust-dev-deps branch 6 times, most recently from 4b9966e to 212161c Compare October 2, 2026 05:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant