chore(deps): update all non-major dependencies - #369
Conversation
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
Kody Code Review — 1 suggested fix. 🛠️ Open Agent Prompt |
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: cachekit-io/cachekit-py/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
| serde_json = "1.0" | ||
| bincode = "1.3" | ||
| numpy = "0.25" | ||
| numpy = "0.29" |
There was a problem hiding this comment.
WHAT: The numpy crate is bumped from 0.25 to 0.29 with no evidence of a vulnerability or supply-chain check. WHY: A dependency manifest change can introduce known CVEs or unexpected transitive changes. HOW: Run cargo audit (or an OSV/SCA scan) for numpy 0.29, attach the output to the PR, and commit the updated Cargo.lock.
Also found in:
Cargo.toml:15-15
Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk
Prompt for LLM
File Cargo.toml:
Line 11:
WHAT: The numpy crate is bumped from 0.25 to 0.29 with no evidence of a vulnerability or supply-chain check. WHY: A dependency manifest change can introduce known CVEs or unexpected transitive changes. HOW: Run cargo audit (or an OSV/SCA scan) for numpy 0.29, attach the output to the PR, and commit the updated Cargo.lock.
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
e1ab23b to
fe8beb0
Compare
This comment has been minimized.
This comment has been minimized.
fe8beb0 to
c0335d3
Compare
c0335d3 to
213287b
Compare
| serde_json = "1.0" | ||
| bincode = "1.3" | ||
| numpy = "0.25" | ||
| numpy = "0.29" |
There was a problem hiding this comment.
Unaudited dependency upgrade in Cargo.toml: the numpy crate jumps from 0.25 to 0.29 across several minor releases, and the PR includes no audit evidence. If 0.29 pulls in a transitive dependency with a known advisory, that dependency ships without review. Fix: run cargo audit/OSV against the new version, attach the output to the PR, and confirm Cargo.lock is updated.
Also found in:
Cargo.toml:15-15
Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk
Prompt for LLM
File Cargo.toml:
Line 11:
Unaudited dependency upgrade in Cargo.toml: the numpy crate jumps from 0.25 to 0.29 across several minor releases, and the PR includes no audit evidence. If 0.29 pulls in a transitive dependency with a known advisory, that dependency ships without review. Fix: run cargo audit/OSV against the new version, attach the output to the PR, and confirm Cargo.lock is updated.
**Also found in:**
- `Cargo.toml:15-15`
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This PR contains the following updates:
0.25→0.290.29.0→0.29.21.11.0→1.12.01.0.228→1.0.2291.0.149→1.0.1510.13→0.181.8.2→1.9.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
PyO3/rust-numpy (numpy)
v0.29.0Compare Source
What's Changed
New Contributors
Full Changelog: PyO3/rust-numpy@v0.28.0...v0.29.0
v0.28.0Compare Source
What's Changed
extension-modulefeature from docs and examples by @Icxolu in #519readonlyandreadwriteby @jakelishman in #524as_sliceby @jakelishman in #525numpyto 0.28.0 by @Icxolu in #531New Contributors
Full Changelog: PyO3/rust-numpy@v0.27.1...v0.28.0
v0.27.1Compare Source
What's Changed
New Contributors
Full Changelog: PyO3/rust-numpy@v0.27.0...v0.27.1
v0.27.0Compare Source
What's Changed
New Contributors
Full Changelog: PyO3/rust-numpy@v0.26.0...v0.27.0
v0.26.0: rust-numpy version 0.26.0Compare Source
Bumps to PyO3 0.26 and MSRV 1.74.
Thanks to @Icxolu for the update!
pyo3/pyo3 (pyo3)
v0.29.2Compare Source
Packaging
PYO3_USE_RAW_DYLIB=0opt-out ofraw-dyliblinking for Windows. #6185Fixed
#[pyo3(get)]) whenIntoPyObjectis only implemented on references of the field type. #6276#[classmethod]magic methods receiving the instance instead of its type when invoked through a type slot. #6283pyo3_build_config::add_libpython_rpath_link_argsemitting Unix-style rpath linker arguments on Windows and Cygwin. #6284#[pyclass]instances. #6294#[pyclass]docstrings. #6296#[classattr]values created fromfnitems. #6297v0.29.1Compare Source
Packaging
PYO3_USE_RAW_DYLIB=0opt-out ofraw-dyliblinking for Windows. #6185Fixed
#[pyo3(get)]) whenIntoPyObjectis only implemented on references of the field type. #6276#[classmethod]magic methods receiving the instance instead of its type when invoked through a type slot. #6283pyo3_build_config::add_libpython_rpath_link_argsemitting Unix-style rpath linker arguments on Windows and Cygwin. #6284#[pyclass]instances. #6294#[pyclass]docstrings. #6296#[classattr]values created fromfnitems. #6297rayon-rs/rayon (rayon)
v1.12.0Compare Source
Range<char>when the end is 0xE000, just past thesurrogate boundary, which was unsafely producing invalid
charvalues.ParallelSlice::par_array_windowsworks likepar_windowsbut with a constant length, producing
&[T; N]items.serde-rs/serde (serde)
v1.0.229Compare Source
serde-rs/json (serde_json)
v1.0.151Compare Source
v1.0.150Compare Source
simd-lite/simd-json (simd-json)
v0.18.1Compare Source
v0.18.0Compare Source
v0.17.3Compare Source
v0.17.2Compare Source
v0.17.1Compare Source
v0.17.0Compare Source
v0.16.0Compare Source
v0.15.1Compare Source
v0.15.0Compare Source
v0.14.3Compare Source
v0.14.2Compare Source
v0.14.1Compare Source
v0.14.0Compare Source
RustCrypto/utils (zeroize)
v1.9.0Compare Source
Configuration
📅 Schedule: (in timezone Australia/Sydney)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.
Summary
This PR updates two Rust dependencies in
Cargo.toml, as generated by Renovate.numpy0.250.29simd-json0.130.18Details
numpy(0.25 → 0.29): This version now matches thepyo3version already declared (0.29). Thenumpycrate typically trackspyo3releases, so this likely resolves a version mismatch between the two.simd-json(0.13 → 0.18): This updates the performance-oriented JSON parsing dependency by several minor versions.Notes
numpyorsimd-jsonmay need adjustments. Build and test results should be confirmed before merging.