chore(deps): update rust-dev-deps - #94
cachekit-renovate-bot[bot] wants to merge 1 commit into
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: cachekit-io/cachekit-rs/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
Kody Code Review — 1 suggested fix. 🛠️ Open Agent Prompt |
4abf48e to
f380eda
Compare
This comment has been minimized.
This comment has been minimized.
f380eda to
4610c50
Compare
| # byte-for-byte (bump this, the lockfile, and the runner pin in ci.yml together). | ||
| [target.'cfg(target_arch = "wasm32")'.dev-dependencies] | ||
| wasm-bindgen-test = "=0.3.71" | ||
| wasm-bindgen-test = "=0.3.78" |
There was a problem hiding this comment.
WHAT: The wasm-bindgen-test dev-dependency is bumped from =0.3.71 to =0.3.78 without any vulnerability or supply-chain evidence. WHY: Dependency manifest changes must be checked for known CVEs. This crate is also tightly coupled to the locked wasm-bindgen version and the CI runner pin, so a partial bump can break CI or pull in unexpected transitive changes. HOW: Run cargo audit and/or an OSV query for wasm-bindgen-test 0.3.78 and link the results in the PR description. Confirm that Cargo.lock (wasm-bindgen) and the runner pin in ci.yml were updated together, as the comment above requires.
Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk
Prompt for LLM
File crates/cachekit/Cargo.toml:
Line 141:
WHAT: The wasm-bindgen-test dev-dependency is bumped from =0.3.71 to =0.3.78 without any vulnerability or supply-chain evidence. WHY: Dependency manifest changes must be checked for known CVEs. This crate is also tightly coupled to the locked wasm-bindgen version and the CI runner pin, so a partial bump can break CI or pull in unexpected transitive changes. HOW: Run `cargo audit` and/or an OSV query for wasm-bindgen-test 0.3.78 and link the results in the PR description. Confirm that Cargo.lock (wasm-bindgen) and the runner pin in ci.yml were updated together, as the comment above requires.
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
| [target.'cfg(target_arch = "wasm32")'.dev-dependencies] | ||
| wasm-bindgen-test = "=0.3.71" | ||
| wasm-bindgen-test = "=0.3.78" |
There was a problem hiding this comment.
Version mismatch in crates/cachekit/Cargo.toml:141: bumping wasm-bindgen-test to =0.3.78 moves Cargo.lock to wasm-bindgen 0.2.128, but .github/workflows/ci.yml:167 still pins WASM_BINDGEN_VERSION "0.2.121" and the matching WASM_BINDGEN_SHA256, and this PR does not update ci.yml. When the 'Guard wasm-bindgen lockfile drift' step (ci.yml:189-195) runs cargo pkgid wasm-bindgen, it gets 0.2.128, compares it with 0.2.121, and exits 1, failing the wasm32 runtime-test job; even without the guard, the 0.2.121 runner cannot run 0.2.128 test binaries because of the ABI lockstep, which breaks the wasm32 runtime coverage added for LAB-1079. Fix: in the same PR, set WASM_BINDGEN_VERSION to "0.2.128" in ci.yml and set WASM_BINDGEN_SHA256 to the checksum of the 0.2.128 x86_64-unknown-linux-musl release tarball.
# crates/cachekit/Cargo.toml (unchanged)
wasm-bindgen-test = "=0.3.78"
# .github/workflows/ci.yml
WASM_BINDGEN_VERSION: "0.2.128"
WASM_BINDGEN_SHA256: "<sha256 of wasm-bindgen-0.2.128-x86_64-unknown-linux-musl.tar.gz>"Prompt for LLM
File crates/cachekit/Cargo.toml:
Line 140 to 141:
Version mismatch in crates/cachekit/Cargo.toml:141: bumping wasm-bindgen-test to =0.3.78 moves Cargo.lock to wasm-bindgen 0.2.128, but .github/workflows/ci.yml:167 still pins WASM_BINDGEN_VERSION "0.2.121" and the matching WASM_BINDGEN_SHA256, and this PR does not update ci.yml. When the 'Guard wasm-bindgen lockfile drift' step (ci.yml:189-195) runs `cargo pkgid wasm-bindgen`, it gets 0.2.128, compares it with 0.2.121, and exits 1, failing the wasm32 runtime-test job; even without the guard, the 0.2.121 runner cannot run 0.2.128 test binaries because of the ABI lockstep, which breaks the wasm32 runtime coverage added for LAB-1079. Fix: in the same PR, set WASM_BINDGEN_VERSION to "0.2.128" in ci.yml and set WASM_BINDGEN_SHA256 to the checksum of the 0.2.128 x86_64-unknown-linux-musl release tarball.
Suggested Code:
# crates/cachekit/Cargo.toml (unchanged)
wasm-bindgen-test = "=0.3.78"
# .github/workflows/ci.yml
WASM_BINDGEN_VERSION: "0.2.128"
WASM_BINDGEN_SHA256: "<sha256 of wasm-bindgen-0.2.128-x86_64-unknown-linux-musl.tar.gz>"
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
commented
Sep 30, 2026
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
4b9966e to
212161c
Compare
212161c to
4caf0c3
Compare
This PR contains the following updates:
1.0.149→1.0.1513.4.0→3.5.01.50.0→1.53.1Release Notes
serde-rs/json (serde_json)
v1.0.151Compare Source
v1.0.150Compare Source
palfrey/serial_test (serial_test)
v3.5.0Compare Source
What's Changed
New Contributors
Full Changelog: palfrey/serial_test@v3.4.0...v3.5.0
tokio-rs/tokio (tokio)
v1.53.1: Tokio v1.53.1Compare Source
1.53.1 (July 20th, 2026)
Fixed
OnceLock::waitfrom the Windows handler (#8300)Fixed (unstable)
Documented
v1.53.0: Tokio v1.53.0Compare Source
1.53.0 (July 17th, 2026)
Added
From<OwnedFd>andFrom<OwnedHandle>forFile(#8266)SocketAddrmethods to Unix sockets (#8144)Changed
#[inline]to IO trait impls for in-memory types (#8242)mpsc::{Receiver,UnboundedReceiver}now drops waker on drop, even if there are still senders (#8095)#[track_caller]totimeout_at()(#8077)Sleep(#8132)Fixed
Chain(#8251)FastRand(#8078)reserve[_many]returns permits (#8260)Trace::capture/Trace::trace_with(#8043).reset()(#8169)IO uring (unstable)
fs::try_exists(#8080)Documented
create_dir_allsucceeds if path exists (#8149)try_read*/try_write*readiness behavior (#8032)yield_nowdefers its waker (#8254)timeout_at()(#8077)v1.52.4: Tokio v1.52.4Compare Source
1.52.4 (July 16th, 2026)
Fixed
before_parkschedules work (#8222)Fixed (unstable)
v1.52.3: Tokio v1.52.3Compare Source
1.52.3 (May 8th, 2026)
Fixed
len()(#8062)OwnedPermit::release()method (#8075)RwLockhasmax_readers != 0(#8076)Emptyfromtry_recv()when mpsc is closed with outstanding permits (#8074)v1.52.2: Tokio v1.52.2Compare Source
1.52.2 (May 4th, 2026)
This release reverts the LIFO slot stealing change introduced in 1.51.0 (#7431), due to its performance impact. (#8100)
v1.52.1: Tokio v1.52.1Compare Source
1.52.1 (April 16th, 2026)
Fixed
spawn_blockingto hang (#8057)v1.52.0: Tokio v1.52.0Compare Source
1.52.0 (April 14th, 2026)
Added
AioSource::register_borrowedfor I/O safety support (#7992)try_iofunction tounix::pipesender and receiver types (#8030)Added (unstable)
Builder::enable_eager_driver_handoffsetting enable eager hand off of the I/O and time drivers before polling tasks (#8010)trace_with()for customized task dumps (#8025)impl FnMut()intrace_withinstead of justfn()(#8040)io_uringinAsyncReadforFile(#7907)Changed
spawn_blockingscalability with sharded queue (#7757)compare_exchange_weak()in worker queue (#8028)Fixed
Documented
oneshot::Sender::senddocs (#8026)sync::watch(#8035)ConnectionRefusederrors with UDP sockets (#7870)v1.51.4: Tokio v1.51.4Compare Source
1.51.4 (July 16th, 2026)
Fixed
before_parkschedules work (#8222)v1.51.3: Tokio v1.51.3Compare Source
1.51.3 (May 8th, 2026)
Fixed
len()(#8062)OwnedPermit::release()method (#8075)RwLockhasmax_readers != 0(#8076)Emptyfromtry_recv()when mpsc is closed with outstanding permits (#8074)v1.51.2: Tokio v1.51.1Compare Source
1.51.2 (May 4th, 2026)
This release reverts the LIFO slot stealing change introduced in 1.51.0 (#7431), due to its performance impact. (#8100)
v1.51.1: Tokio v1.51.1Compare Source
1.51.1 (April 8th, 2026)
Fixed
SO_ERRORonrecvfor UDP sockets on Linux (#8001)Fixed (unstable)
worker_local_schedule_counttest (#8008)v1.51.0: Tokio v1.51.0Compare Source
1.51.0 (April 3rd, 2026)
Added
get_peer_credon Hurd (#7989)tokio::runtime::worker_index()(#7921)LocalRuntime(#7557)Changed
Fixed
notify_waiterspriority inNotify(#7996)Chan::recv_manywhen called with non-empty vector on closed channel (#7991)Configuration
📅 Schedule: (in timezone Australia/Sydney)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.