-
Notifications
You must be signed in to change notification settings - Fork 0
chore(deps): update all non-major dependencies #79
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -30,7 +30,7 @@ serde_bytes = "0.11" | |
| rmp-serde = { version = "1.3", optional = true } | ||
|
|
||
| # High-performance LZ4 compression (optional) | ||
| lz4_flex = { version = "0.12", features = ["frame", "std"], optional = true } | ||
| lz4_flex = { version = "0.14", features = ["frame", "std"], optional = true } | ||
|
|
||
| # Fast non-cryptographic hashing for data integrity (optional) | ||
| # xxHash3-64: ~36 GB/s, sufficient for corruption detection (security via AES-GCM auth tag) | ||
|
|
@@ -40,17 +40,17 @@ xxhash-rust = { version = "0.8", features = ["xxh3"], optional = true } | |
| # Uses HKDF-SHA256 for key derivation (NOT Blake2b - that's only for Python cache keys) | ||
| # ring is native-only (see [target.'cfg(not(target_arch = "wasm32"))'.dependencies]) | ||
| zeroize = { version = "1.8", features = ["derive"], optional = true } | ||
| hkdf = { version = "0.12", optional = true } | ||
| sha2 = { version = "0.10", optional = true } | ||
| hmac = { version = "0.12", optional = true } | ||
| hkdf = { version = "0.13", optional = true } | ||
| sha2 = { version = "0.11", optional = true } | ||
| hmac = { version = "0.13", optional = true } | ||
| generic-array = { version = "0.14", optional = true } | ||
|
|
||
| # wasm32 RNG: getrandom with JS feature for wasm32-unknown-unknown targets | ||
| getrandom = { version = "0.2", features = ["js"], optional = true } | ||
| getrandom = { version = "0.4", features = ["js"], optional = true } | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. WHAT: getrandom jumps 0.2→0.4 while still enabling the "js" feature. WHY: getrandom 0.3+ removed the "js" feature in favor of "wasm_js" plus a cfg flag, so this may fail to build or silently break wasm RNG. The bump also has no audit evidence. HOW: verify the feature set against the 0.4 docs, attach cargo audit/OSV output, and update Cargo.lock. Also found in:
Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk Prompt for LLMTalk to Kody by mentioning @kody Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction. |
||
|
|
||
| # RustCrypto: pure-Rust AES-256-GCM for wasm32 targets (ring requires clang + C asm) | ||
| aes-gcm = { version = "0.10", features = ["zeroize"], optional = true } | ||
| aes = { version = "0.8", features = ["zeroize"], optional = true } | ||
| aes-gcm = { version = "0.11", features = ["zeroize"], optional = true } | ||
|
Comment on lines
+44
to
+52
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Version split between [dependencies] and [dev-dependencies] in Cargo.toml: sha2 and aes-gcm move to 0.11 in [dependencies], but [dev-dependencies] at lines 76-77 still pin sha2 = "0.10" and aes-gcm 0.10. When tests are built with sha2 = { version = "0.11", optional = true }
# and in [dev-dependencies]:
# sha2 = "0.11"
# aes-gcm = { version = "0.11", features = ["zeroize"] }Prompt for LLMTalk to Kody by mentioning @kody Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction. |
||
| aes = { version = "0.9", features = ["zeroize"], optional = true } | ||
|
Comment on lines
+52
to
+53
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. API break in the aes-gcm/aes upgrade in Cargo.toml: aes-gcm 0.11 and aes 0.9 move from generic-array to hybrid-array, but src/encryption/core.rs:520 and :577 still call the 0.10 API aes-gcm = { version = "0.10", features = ["zeroize"], optional = true }
aes = { version = "0.8", features = ["zeroize"], optional = true }Prompt for LLMTalk to Kody by mentioning @kody Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction. |
||
|
|
||
| # Byte utilities | ||
| bytes = "1.5" | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Build break in the getrandom dependency in Cargo.toml: getrandom 0.4 has no
jsfeature, which was renamed towasm_jsin 0.3, and it replacesgetrandom::getrandom()withgetrandom::fill(). When building with theencryption/wasmfeature, Cargo rejectsfeatures = ["js"]during dependency resolution, and the wasm32 callgetrandom::getrandom(&mut seed_bytes)at src/encryption/core.rs:92 no longer compiles. Fix: usefeatures = ["wasm_js"], change core.rs:92 togetrandom::fill(&mut seed_bytes), and set thegetrandom_backend="wasm_js"cfg flag for wasm32 targets, or keep getrandom at 0.2.Prompt for LLM
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.