Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 7 additions & 7 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@ serde_bytes = "0.11"
rmp-serde = { version = "1.3", optional = true }

# High-performance LZ4 compression (optional)
lz4_flex = { version = "0.12", features = ["frame", "std"], optional = true }
lz4_flex = { version = "0.14", features = ["frame", "std"], optional = true }

# Fast non-cryptographic hashing for data integrity (optional)
# xxHash3-64: ~36 GB/s, sufficient for corruption detection (security via AES-GCM auth tag)
Expand All @@ -40,17 +40,17 @@ xxhash-rust = { version = "0.8", features = ["xxh3"], optional = true }
# Uses HKDF-SHA256 for key derivation (NOT Blake2b - that's only for Python cache keys)
# ring is native-only (see [target.'cfg(not(target_arch = "wasm32"))'.dependencies])
zeroize = { version = "1.8", features = ["derive"], optional = true }
hkdf = { version = "0.12", optional = true }
sha2 = { version = "0.10", optional = true }
hmac = { version = "0.12", optional = true }
hkdf = { version = "0.13", optional = true }
sha2 = { version = "0.11", optional = true }
hmac = { version = "0.13", optional = true }
generic-array = { version = "0.14", optional = true }

# wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets
getrandom = { version = "0.2", features = ["js"], optional = true }
getrandom = { version = "0.4", features = ["js"], optional = true }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug high

Build break in the getrandom dependency in Cargo.toml: getrandom 0.4 has no js feature, which was renamed to wasm_js in 0.3, and it replaces getrandom::getrandom() with getrandom::fill(). When building with the encryption/wasm feature, Cargo rejects features = ["js"] during dependency resolution, and the wasm32 call getrandom::getrandom(&mut seed_bytes) at src/encryption/core.rs:92 no longer compiles. Fix: use features = ["wasm_js"], change core.rs:92 to getrandom::fill(&mut seed_bytes), and set the getrandom_backend="wasm_js" cfg flag for wasm32 targets, or keep getrandom at 0.2.

getrandom = { version = "0.4", features = ["wasm_js"], optional = true }
Prompt for LLM

File Cargo.toml:

Line 49:

Build break in the getrandom dependency in Cargo.toml: getrandom 0.4 has no `js` feature, which was renamed to `wasm_js` in 0.3, and it replaces `getrandom::getrandom()` with `getrandom::fill()`. When building with the `encryption`/`wasm` feature, Cargo rejects `features = ["js"]` during dependency resolution, and the wasm32 call `getrandom::getrandom(&mut seed_bytes)` at src/encryption/core.rs:92 no longer compiles. Fix: use `features = ["wasm_js"]`, change core.rs:92 to `getrandom::fill(&mut seed_bytes)`, and set the `getrandom_backend="wasm_js"` cfg flag for wasm32 targets, or keep getrandom at 0.2.

Suggested Code:

getrandom = { version = "0.4", features = ["wasm_js"], optional = true }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

WHAT: getrandom jumps 0.2→0.4 while still enabling the "js" feature. WHY: getrandom 0.3+ removed the "js" feature in favor of "wasm_js" plus a cfg flag, so this may fail to build or silently break wasm RNG. The bump also has no audit evidence. HOW: verify the feature set against the 0.4 docs, attach cargo audit/OSV output, and update Cargo.lock.

Also found in:

  • Cargo.toml:43-43
  • Cargo.toml:44-44
  • Cargo.toml:33-33
  • Cargo.toml:52-52
  • Cargo.toml:53-53
  • Cargo.toml:45-45

Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk

Prompt for LLM

File Cargo.toml:

Line 49:

WHAT: getrandom jumps 0.2→0.4 while still enabling the "js" feature. WHY: getrandom 0.3+ removed the "js" feature in favor of "wasm_js" plus a cfg flag, so this may fail to build or silently break wasm RNG. The bump also has no audit evidence. HOW: verify the feature set against the 0.4 docs, attach cargo audit/OSV output, and update Cargo.lock.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​


# RustCrypto: pure-Rust AES-256-GCM for wasm32 targets (ring requires clang + C asm)
aes-gcm = { version = "0.10", features = ["zeroize"], optional = true }
aes = { version = "0.8", features = ["zeroize"], optional = true }
aes-gcm = { version = "0.11", features = ["zeroize"], optional = true }
Comment on lines +44 to +52

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug medium

Version split between [dependencies] and [dev-dependencies] in Cargo.toml: sha2 and aes-gcm move to 0.11 in [dependencies], but [dev-dependencies] at lines 76-77 still pin sha2 = "0.10" and aes-gcm 0.10. When tests are built with --features encryption, the wire-format and cross-implementation tests run against a different major version than production uses. Fix: bump the dev-dependencies to sha2 = "0.11" and aes-gcm = { version = "0.11", features = ["zeroize"] }.

sha2 = { version = "0.11", optional = true }
# and in [dev-dependencies]:
# sha2 = "0.11"
# aes-gcm = { version = "0.11", features = ["zeroize"] }
Prompt for LLM

File Cargo.toml:

Line 44 to 52:

Version split between [dependencies] and [dev-dependencies] in Cargo.toml: sha2 and aes-gcm move to 0.11 in [dependencies], but [dev-dependencies] at lines 76-77 still pin sha2 = "0.10" and aes-gcm 0.10. When tests are built with `--features encryption`, the wire-format and cross-implementation tests run against a different major version than production uses. Fix: bump the dev-dependencies to sha2 = "0.11" and aes-gcm = { version = "0.11", features = ["zeroize"] }.

Suggested Code:

sha2 = { version = "0.11", optional = true }
# and in [dev-dependencies]:
# sha2 = "0.11"
# aes-gcm = { version = "0.11", features = ["zeroize"] }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

aes = { version = "0.9", features = ["zeroize"], optional = true }
Comment on lines +52 to +53

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug high

API break in the aes-gcm/aes upgrade in Cargo.toml: aes-gcm 0.11 and aes 0.9 move from generic-array to hybrid-array, but src/encryption/core.rs:520 and :577 still call the 0.10 API AesGcmNonce::from_slice(...). Because these calls sit behind cfg(target_arch = "wasm32"), native CI passes while wasm32 builds fail on the encrypt and decrypt paths. Fix: keep aes-gcm at 0.10 and aes at 0.8, or construct the nonce with AesGcmNonce::try_from(&nonce_bytes[..]) in core.rs and add a wasm32 build to CI.

aes-gcm = { version = "0.10", features = ["zeroize"], optional = true }
aes = { version = "0.8", features = ["zeroize"], optional = true }
Prompt for LLM

File Cargo.toml:

Line 52 to 53:

API break in the aes-gcm/aes upgrade in Cargo.toml: aes-gcm 0.11 and aes 0.9 move from generic-array to hybrid-array, but src/encryption/core.rs:520 and :577 still call the 0.10 API `AesGcmNonce::from_slice(...)`. Because these calls sit behind `cfg(target_arch = "wasm32")`, native CI passes while wasm32 builds fail on the encrypt and decrypt paths. Fix: keep aes-gcm at 0.10 and aes at 0.8, or construct the nonce with `AesGcmNonce::try_from(&nonce_bytes[..])` in core.rs and add a wasm32 build to CI.

Suggested Code:

aes-gcm = { version = "0.10", features = ["zeroize"], optional = true }
aes = { version = "0.8", features = ["zeroize"], optional = true }

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​


# Byte utilities
bytes = "1.5"
Expand Down
Loading