chore(deps): update all non-major dependencies - #79
cachekit-renovate-bot[bot] wants to merge 1 commit into
Conversation
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: cachekit-io/cachekit-core/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
Kody Code Review — 4 suggested fixes. 🛠️ Open Agent Prompt |
|
|
||
| # wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets | ||
| getrandom = { version = "0.2", features = ["js"], optional = true } | ||
| getrandom = { version = "0.4", features = ["js"], optional = true } |
There was a problem hiding this comment.
Build break in the getrandom dependency in Cargo.toml: getrandom 0.4 has no js feature, which was renamed to wasm_js in 0.3, and it replaces getrandom::getrandom() with getrandom::fill(). When building with the encryption/wasm feature, Cargo rejects features = ["js"] during dependency resolution, and the wasm32 call getrandom::getrandom(&mut seed_bytes) at src/encryption/core.rs:92 no longer compiles. Fix: use features = ["wasm_js"], change core.rs:92 to getrandom::fill(&mut seed_bytes), and set the getrandom_backend="wasm_js" cfg flag for wasm32 targets, or keep getrandom at 0.2.
getrandom = { version = "0.4", features = ["wasm_js"], optional = true }Prompt for LLM
File Cargo.toml:
Line 49:
Build break in the getrandom dependency in Cargo.toml: getrandom 0.4 has no `js` feature, which was renamed to `wasm_js` in 0.3, and it replaces `getrandom::getrandom()` with `getrandom::fill()`. When building with the `encryption`/`wasm` feature, Cargo rejects `features = ["js"]` during dependency resolution, and the wasm32 call `getrandom::getrandom(&mut seed_bytes)` at src/encryption/core.rs:92 no longer compiles. Fix: use `features = ["wasm_js"]`, change core.rs:92 to `getrandom::fill(&mut seed_bytes)`, and set the `getrandom_backend="wasm_js"` cfg flag for wasm32 targets, or keep getrandom at 0.2.
Suggested Code:
getrandom = { version = "0.4", features = ["wasm_js"], optional = true }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
| aes-gcm = { version = "0.11", features = ["zeroize"], optional = true } | ||
| aes = { version = "0.9", features = ["zeroize"], optional = true } |
There was a problem hiding this comment.
API break in the aes-gcm/aes upgrade in Cargo.toml: aes-gcm 0.11 and aes 0.9 move from generic-array to hybrid-array, but src/encryption/core.rs:520 and :577 still call the 0.10 API AesGcmNonce::from_slice(...). Because these calls sit behind cfg(target_arch = "wasm32"), native CI passes while wasm32 builds fail on the encrypt and decrypt paths. Fix: keep aes-gcm at 0.10 and aes at 0.8, or construct the nonce with AesGcmNonce::try_from(&nonce_bytes[..]) in core.rs and add a wasm32 build to CI.
aes-gcm = { version = "0.10", features = ["zeroize"], optional = true }
aes = { version = "0.8", features = ["zeroize"], optional = true }Prompt for LLM
File Cargo.toml:
Line 52 to 53:
API break in the aes-gcm/aes upgrade in Cargo.toml: aes-gcm 0.11 and aes 0.9 move from generic-array to hybrid-array, but src/encryption/core.rs:520 and :577 still call the 0.10 API `AesGcmNonce::from_slice(...)`. Because these calls sit behind `cfg(target_arch = "wasm32")`, native CI passes while wasm32 builds fail on the encrypt and decrypt paths. Fix: keep aes-gcm at 0.10 and aes at 0.8, or construct the nonce with `AesGcmNonce::try_from(&nonce_bytes[..])` in core.rs and add a wasm32 build to CI.
Suggested Code:
aes-gcm = { version = "0.10", features = ["zeroize"], optional = true }
aes = { version = "0.8", features = ["zeroize"], optional = true }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
|
|
||
| # wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets | ||
| getrandom = { version = "0.2", features = ["js"], optional = true } | ||
| getrandom = { version = "0.4", features = ["js"], optional = true } |
There was a problem hiding this comment.
WHAT: getrandom jumps 0.2→0.4 while still enabling the "js" feature. WHY: getrandom 0.3+ removed the "js" feature in favor of "wasm_js" plus a cfg flag, so this may fail to build or silently break wasm RNG. The bump also has no audit evidence. HOW: verify the feature set against the 0.4 docs, attach cargo audit/OSV output, and update Cargo.lock.
Also found in:
Cargo.toml:43-43Cargo.toml:44-44Cargo.toml:33-33Cargo.toml:52-52Cargo.toml:53-53Cargo.toml:45-45
Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk
Prompt for LLM
File Cargo.toml:
Line 49:
WHAT: getrandom jumps 0.2→0.4 while still enabling the "js" feature. WHY: getrandom 0.3+ removed the "js" feature in favor of "wasm_js" plus a cfg flag, so this may fail to build or silently break wasm RNG. The bump also has no audit evidence. HOW: verify the feature set against the 0.4 docs, attach cargo audit/OSV output, and update Cargo.lock.
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
| sha2 = { version = "0.11", optional = true } | ||
| hmac = { version = "0.13", optional = true } | ||
| generic-array = { version = "0.14", optional = true } | ||
|
|
||
| # wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets | ||
| getrandom = { version = "0.2", features = ["js"], optional = true } | ||
| getrandom = { version = "0.4", features = ["js"], optional = true } | ||
|
|
||
| # RustCrypto: pure-Rust AES-256-GCM for wasm32 targets (ring requires clang + C asm) | ||
| aes-gcm = { version = "0.10", features = ["zeroize"], optional = true } | ||
| aes = { version = "0.8", features = ["zeroize"], optional = true } | ||
| aes-gcm = { version = "0.11", features = ["zeroize"], optional = true } |
There was a problem hiding this comment.
Version split between [dependencies] and [dev-dependencies] in Cargo.toml: sha2 and aes-gcm move to 0.11 in [dependencies], but [dev-dependencies] at lines 76-77 still pin sha2 = "0.10" and aes-gcm 0.10. When tests are built with --features encryption, the wire-format and cross-implementation tests run against a different major version than production uses. Fix: bump the dev-dependencies to sha2 = "0.11" and aes-gcm = { version = "0.11", features = ["zeroize"] }.
sha2 = { version = "0.11", optional = true }
# and in [dev-dependencies]:
# sha2 = "0.11"
# aes-gcm = { version = "0.11", features = ["zeroize"] }Prompt for LLM
File Cargo.toml:
Line 44 to 52:
Version split between [dependencies] and [dev-dependencies] in Cargo.toml: sha2 and aes-gcm move to 0.11 in [dependencies], but [dev-dependencies] at lines 76-77 still pin sha2 = "0.10" and aes-gcm 0.10. When tests are built with `--features encryption`, the wire-format and cross-implementation tests run against a different major version than production uses. Fix: bump the dev-dependencies to sha2 = "0.11" and aes-gcm = { version = "0.11", features = ["zeroize"] }.
Suggested Code:
sha2 = { version = "0.11", optional = true }
# and in [dev-dependencies]:
# sha2 = "0.11"
# aes-gcm = { version = "0.11", features = ["zeroize"] }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
This PR contains the following updates:
0.8→0.90.10→0.111.11.1→1.12.10.29.2→0.29.40.14.7→0.14.90.2→0.40.12→0.130.12→0.130.12→0.141.0.228→1.0.2290.10→0.112.0.18→2.0.210.8.15→0.8.180.8.191.8.2→1.9.0Release Notes
RustCrypto/block-ciphers (aes)
v0.9.3Compare Source
v0.9.2Compare Source
v0.9.1Compare Source
v0.9.0Compare Source
RustCrypto/AEADs (aes-gcm)
v0.11.1Compare Source
v0.11.0Compare Source
tokio-rs/bytes (bytes)
v1.12.1Compare Source
Fixed
Box::newpanics (#837)v1.12.0Compare Source
Added
BytesMut::extend_from_within()(#818)BytesMut::try_unsplit()(#746)Fixed
get_intifnbytesis zero (#806)Changed
Documented
BytesMut::{reserve,try_reserve}doesn't preserve unused capacity (#808)mozilla/cbindgen (cbindgen)
v0.29.4Compare Source
v0.29.3Compare Source
* Fix doc attribute parsing to properly handle block comments
* Check for CMSE ABI's as well
* ci: Add a meta job to block the merge queue on it.
* Allow
pubaccess toReprTypefields* In C23 mode, define sized enums as enums rather than typedefs.
rust-random/getrandom (getrandom)
v0.4.3Compare Source
Added
wasm64-unknown-unknowntarget support forwasm_jsbackend #848Changed
wasip2andwasip3dependencies in favor of manual bindings #830v0.4.2Compare Source
Changed
r-efidependency to v6 #814Fixed
errnoonly when it is set #810ProcessPrngon Windows #811v0.4.1Compare Source
Fixed
v0.4.0Compare Source
Added
RawOsErrortype alias #739SysRngbehind new featuresys_rng#751extern_implopt-in backend #786 #794Changed
v0.3.4Compare Source
Major change to
wasm_jsbackendNow, when the
wasm_jsfeature is enabled, thewasm_jsbackend will be usedby default. Users of
wasm32-unknown-unknowntargeting JavaScript environmentslike the Web and Node.js will no longer need to specify:
in
RUSTFLAGSfor the crate to compile. They can now simple enable a feature.Note: this should not affect non-JS users of the
wasm32-unknown-unknowntarget. Using
--cfg getrandom_backendwill still override the source ofrandomness even if the
wasm_jsfeature is enabled. This includes--cfg getrandom_backend=customand--cfg getrandom_backend=unsupported.For more information, see the discussions in #671, #675, and #730.
Added
unsupportedopt-in backend #667windows_legacyopt-in backend #724Changed
linux_rawopt-in backend on ARM targets #688getrandomsyscall on all RISC-V Linux targets #699wasidependency withwasip2#721wasm_jsbackend by default if thewasm_jsfeature is enabled #730Removed
rustc-dep-of-stdcrate feature #694v0.3.3Compare Source
Changed
compile_error!s #639Fixed
v0.3.2Compare Source
Added
efi_rngopt-in backend #570linux_rawopt-in backend #572.cargo/config.tomlexample in the crate-level docs #591getrandom_test_linux_without_fallbackconfiguration flag to test that file fallbackis not triggered in the
linux_android_with_fallbackbackend #605*-linux-nonetargets #618Changed
wasidependency to v0.14 #594#[inline]attribute to the inner functions #596dlsymon MUSL targets in thelinux_android_with_fallbackbackend #602linux_android.rsand usegetrandom.rsinstead #603RtlGenRandomon Windows targets when compiling with pre-1.78 Rust #610Errortype #614windows-targetsdependency and useraw-dylibdirectly #627Removed
Error::INTERNAL_STARTandError::CUSTOM_STARTassociated constants #614v0.3.1Compare Source
Fixed
v0.3.0Compare Source
Breaking Changes
Changed
getrandomandgetrandom_uninitfunctions tofillandfill_uninitrespectively #532Removed
wasm32-wasitarget support (usewasm32-wasip1orwasm32-wasip2instead) #499linux_disable_fallback,rdrand,js,test-in-browser, andcustomcrate featuresin favor of configuration flags #504
register_custom_getrandom!macro #504From<NonZeroU32>forErrorandError::codemethod #507Errorconstants #562Changed
ProcessPrngon Windows 10 and up, and useRtlGenRandomon older Windows versions #415strerror_rfor retrieving error code descriptions #440usizeis the native word size in therdrandbackend #442errnowhenlibcdid not indicate error on Solaris #448libpthread's mutex tofutexon Linux and tonanosleep-based wait loopon other targets in the
use_filebackend #490EAGAINwhile polling/dev/randomon Linux #522wasm_jsbackend(bumps minimum supported Node.js version to v19) #557
js_namespacein thewasm_jsbackend #559Added
wasm32-wasip1andwasm32-wasip2support #499getrandom_backendconfiguration flag for selection of opt-in backends #504Error::new_custommethod #507rndropt-in backend #512u32andu64functions for generating random values of the respective type #544wasm32v1-nonesupport in thewasm_jsbackend #560wasm_jscrate feature which allows users to enable thewasm_jsopt-in backend #574Fixed
KERN_ARND#555RustCrypto/KDFs (hkdf)
v0.13.0Compare Source
RustCrypto/MACs (hmac)
v0.13.0Compare Source
pseitz/lz4_flex (lz4_flex)
v0.14.0Compare Source
==================
Features
allocfeature to allowno_stdoperation without an allocator. Thestdfeature now impliesalloc. Withoutalloconly the_intovariants of the block API are available, e.g.compress_into; the compression hash table is placed on the stack or can be provided viacompress_into_with_table.v0.13.1Compare Source
==================
Fixes
From<io::Error>implementation forframe::Error#221 (thanks @phoerious)v0.13.0==================
Features
Fixes
get_maximum_output_sizeoverflow on 32-bit targets #205 (thanks @dglittle)serde-rs/serde (serde)
v1.0.229Compare Source
RustCrypto/hashes (sha2)
v0.11.0Compare Source
dtolnay/thiserror (thiserror)
v2.0.21Compare Source
v2.0.20Compare Source
v2.0.19Compare Source
RustCrypto/utils (zeroize)
v1.9.0Compare Source
Configuration
📅 Schedule: (in timezone Australia/Sydney)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.