chore(deps): update rust-dev-deps - #85
cachekit-renovate-bot[bot] wants to merge 1 commit into
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: cachekit-io/cachekit-core/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
Kody Code Review — 2 suggested fixes. 🛠️ Open Agent Prompt |
| proptest = "1.4" | ||
| serde_json = "1.0" | ||
| blake2 = "0.10" | ||
| blake2 = "0.11" |
There was a problem hiding this comment.
Unverified breaking bump in Cargo.toml: blake2 moves from 0.10 to 0.11, a semver-breaking change, without CVE/supply-chain evidence or an updated Cargo.lock. When only pre-release 0.11 versions are published, as was long the case across the RustCrypto stack, the bare "0.11" requirement fails to resolve and the build breaks. Fix: confirm a stable 0.11 release exists, attach cargo-audit or OSV output to the PR, and commit the updated Cargo.lock.
Also found in:
Cargo.toml:73-73Cargo.toml:72-72Cargo.toml:74-74
Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk
Prompt for LLM
File Cargo.toml:
Line 68:
Unverified breaking bump in Cargo.toml: `blake2` moves from 0.10 to 0.11, a semver-breaking change, without CVE/supply-chain evidence or an updated Cargo.lock. When only pre-release 0.11 versions are published, as was long the case across the RustCrypto stack, the bare `"0.11"` requirement fails to resolve and the build breaks. Fix: confirm a stable 0.11 release exists, attach cargo-audit or OSV output to the PR, and commit the updated Cargo.lock.
**Also found in:**
- `Cargo.toml:73-73`
- `Cargo.toml:72-72`
- `Cargo.toml:74-74`
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
| sha2 = "0.11" | ||
| aes-gcm = { version = "0.11", features = ["zeroize"] } |
There was a problem hiding this comment.
Version conflict in Cargo.toml [dev-dependencies]: sha2 and aes-gcm are bumped to 0.11, but [dependencies] still declares sha2 = "0.10" (line 44) and aes-gcm = "0.10" (line 52), and Cargo unifies a same-named dependency and dev-dependency into one extern crate, so ^0.10 and ^0.11 conflict. Running cargo test --features encryption either fails dependency resolution or gives rustc two candidates for sha2/aes_gcm. If 0.11 wins, Hkdf::<Sha256> in src/encryption/key_derivation.rs:109 breaks because hkdf 0.12 is built on digest 0.10, and tests/wasm32_compat_tests.rs:72-113 breaks on the 0.10 GenericArray Nonce::from_slice API. Fix: pin the dev-dependency versions to match production (0.10), or bump sha2/aes-gcm/aes/hkdf/hmac/generic-array together in [dependencies] and migrate the code.
sha2 = "0.10"
aes-gcm = { version = "0.10", features = ["zeroize"] }Prompt for LLM
File Cargo.toml:
Line 72 to 73:
Version conflict in Cargo.toml [dev-dependencies]: `sha2` and `aes-gcm` are bumped to 0.11, but [dependencies] still declares `sha2 = "0.10"` (line 44) and `aes-gcm = "0.10"` (line 52), and Cargo unifies a same-named dependency and dev-dependency into one extern crate, so ^0.10 and ^0.11 conflict. Running `cargo test --features encryption` either fails dependency resolution or gives rustc two candidates for `sha2`/`aes_gcm`. If 0.11 wins, `Hkdf::<Sha256>` in src/encryption/key_derivation.rs:109 breaks because hkdf 0.12 is built on digest 0.10, and tests/wasm32_compat_tests.rs:72-113 breaks on the 0.10 GenericArray `Nonce::from_slice` API. Fix: pin the dev-dependency versions to match production (0.10), or bump sha2/aes-gcm/aes/hkdf/hmac/generic-array together in [dependencies] and migrate the code.
Suggested Code:
sha2 = "0.10"
aes-gcm = { version = "0.10", features = ["zeroize"] }
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
Summary
Updates Rust dev-dependencies in
Cargo.toml. Only the[dev-dependencies]section is modified. No library source, public APIs, FFI bindings (cbindgen), or feature flags are changed.Changes
blake20.100.11sha20.100.11aes-gcm0.100.11zeroizefeature retainedcriterion0.50.8html_reportsfeature retainedserde_json1.01.01.0.151is lockfile-onlyImpact and Review Notes
cachekit-coreare not affected.sha2versions: The comment in the manifest distinguishes this dev-dependency from the optionalsha2gated behind theencryptionfeature. That optional dependency is outside this diff. If it remains on0.10, test builds withencryptionenabled will compile bothsha2 0.10and0.11. Any test comparing digest types across the two versions could fail to type-check.aes-gcm0.11 and the RustCrypto 0.11 hash crates move to neweraead/digesttrait generations. Test code that uses key/nonce construction or digest traits may need adjustment.criterion0.6+ deprecatescriterion::black_boxin favor ofstd::hint::black_box, and 0.8 raises its MSRV to 1.86. The benchmark toolchain must meet that MSRV.