Skip to content

chore(core): drop unused bytes and byteorder dependencies (LAB-6345) - #82

Merged
27Bslash6 merged 3 commits into
mainfrom
agent/miss-huang/lab-6345-drop-unused-deps
Sep 29, 2026
Merged

27Bslash6 merged 3 commits into
mainfrom
agent/miss-huang/lab-6345-drop-unused-deps

Conversation

@27Bslash6

@27Bslash6 27Bslash6 commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Removes the unused bytes (1.5) and byteorder (1.5) crates from the unconditional [dependencies] section of Cargo.toml, along with the "Byte utilities" comment block. Neither crate is referenced by the crate's code, so the dependency tree gets smaller and the beta unused_dependencies lint no longer warns about them.

Changes

  • Cargo.toml: Deletes the bytes and byteorder entries. These were non-optional and applied to every target and feature set, so they are removed from all builds, including native, wasm32, and FFI.
  • supply-chain/config.toml: Removes the [[exemptions.bytes]] entry (version 1.11.1, safe-to-deploy). The crate is no longer in the dependency graph, so cargo vet does not need the exemption. No other vet exemptions or criteria change in this file.

Public API Impact

None. No exported types, functions, or feature flags change. The crypto dependencies (aes-gcm, aes, getrandom) and the native-only ring target dependency are untouched.

Notes

  • The diff shows only Cargo.toml and supply-chain/config.toml. The Cargo.lock update and the removal of the byteorder vet import described in the existing summary do not appear in the provided patches. Confirm that both are included in the final commit set.
  • Downstream consumers that relied on bytes or byteorder being pulled in transitively through this crate must now declare them directly. Nothing in the diff shows such a dependency.

This PR removes two unused dependencies from cachekit-core.

Changes

  • Cargo.toml: Removes bytes (1.5) and byteorder (1.5), along with their "Byte utilities" comment, from the general [dependencies] section.
  • supply-chain/config.toml: Removes the cargo-vet exemption for bytes version 1.11.1 (safe-to-deploy), since the crate is no longer a direct dependency. No byteorder exemption was present, so none is removed.

Impact

  • There are no public API changes. The PR modifies only dependency manifests and supply-chain configuration.
  • The dependency tree and supply-chain audit list are smaller.
  • Downstream consumers should see no functional change.

Summary by CodeRabbit

  • Chores
    • Removed unused package dependencies and an outdated supply-chain exemption.
    • No user-facing changes are included in this update.

Neither crate is referenced anywhere in the crate. Remove them from the
manifest and lockfile, along with the cargo-vet exemption and import
that only they used.
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: cachekit-io/cachekit-core/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 9cf26d2d-1933-41cc-affd-0840ff688f1b

📥 Commits

Reviewing files that changed from the base of the PR and between 9bd0f80 and 10b432f.

⛔ Files ignored due to path filters (2)
  • Cargo.lock is excluded by !**/*.lock
  • supply-chain/imports.lock is excluded by !**/*.lock
📒 Files selected for processing (2)
  • Cargo.toml
  • supply-chain/config.toml
💤 Files with no reviewable changes (2)
  • Cargo.toml
  • supply-chain/config.toml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

The manifest no longer lists the bytes and byteorder dependencies. The supply-chain configuration no longer exempts bytes version 1.11.1 under the safe-to-deploy criterion.

Changes

Dependency and supply-chain entries

Layer / File(s) Summary
Remove dependency and exemption entries
Cargo.toml, supply-chain/config.toml
Cargo.toml removes the bytes and byteorder dependencies. The supply-chain configuration removes the exemption for bytes version 1.11.1.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~5 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 10b43

This change removes two unused dependencies and a related supply-chain exemption. It should not change runtime behavior. Confirm that the lockfile update and vet import cleanup are in the final commit set, and that the build passes.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the removal of the unused bytes and byteorder dependencies. It matches the main change in the pull request.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@kodus-27b

kodus-27b Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

kodus-27b[bot]
kodus-27b Bot previously approved these changes Sep 29, 2026
Revert an unrelated crossbeam-epoch import that cargo vet added
while regenerating imports.lock.
@27Bslash6

Copy link
Copy Markdown
Contributor Author

@kody review --force

@kodus-27b

kodus-27b Bot commented Sep 29, 2026

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

@27Bslash6
27Bslash6 merged commit dba66c7 into main Sep 29, 2026
34 checks passed
@27Bslash6
27Bslash6 deleted the agent/miss-huang/lab-6345-drop-unused-deps branch September 29, 2026 15:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant