Skip to content

chore(deps): update all non-major dependencies - #369

Merged
27Bslash6 merged 1 commit into
mainfrom
renovate/all-minor-patch
Sep 30, 2026
Merged

27Bslash6 merged 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@cachekit-renovate-bot

@cachekit-renovate-bot cachekit-renovate-bot Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
numpy workspace.dependencies minor 0.25 → 0.29
pyo3 workspace.dependencies patch 0.29.0 → 0.29.2
rayon workspace.dependencies minor 1.11.0 → 1.12.0
serde (source) workspace.dependencies patch 1.0.228 → 1.0.229
serde_json workspace.dependencies patch 1.0.149 → 1.0.151
simd-json workspace.dependencies minor 0.13 → 0.18
zeroize dependencies minor 1.8.2 → 1.9.0

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

PyO3/rust-numpy (numpy)

v0.29.0

Compare Source

What's Changed

New Contributors

Full Changelog: PyO3/rust-numpy@v0.28.0...v0.29.0

v0.28.0

Compare Source

What's Changed

New Contributors

Full Changelog: PyO3/rust-numpy@v0.27.1...v0.28.0

v0.27.1

Compare Source

What's Changed

New Contributors

Full Changelog: PyO3/rust-numpy@v0.27.0...v0.27.1

v0.27.0

Compare Source

What's Changed

New Contributors

Full Changelog: PyO3/rust-numpy@v0.26.0...v0.27.0

v0.26.0: rust-numpy version 0.26.0

Compare Source

Bumps to PyO3 0.26 and MSRV 1.74.

Thanks to @​Icxolu for the update!

pyo3/pyo3 (pyo3)

v0.29.2

Compare Source

Packaging
  • Add PYO3_USE_RAW_DYLIB=0 opt-out of raw-dylib linking for Windows. #​6185
Fixed
  • Fix PyO3 0.29 regression with failure to link under Cygwin / MSYS2. #​6185
  • Fix stubs generation for field getters (#[pyo3(get)]) when IntoPyObject is only implemented on references of the field type. #​6276
  • Fix #[classmethod] magic methods receiving the instance instead of its type when invoked through a type slot. #​6283
  • Fix pyo3_build_config::add_libpython_rpath_link_args emitting Unix-style rpath linker arguments on Windows and Cygwin. #​6284
  • Fix PyO3 0.29.1 regression on PyPy causing crashes when deallocating #[pyclass] instances. #​6294
  • Fix missing trailing nul in Python 3.9 #[pyclass] docstrings. #​6296
  • Fix reference count leak of #[classattr] values created from fn items. #​6297

v0.29.1

Compare Source

Packaging
  • Add PYO3_USE_RAW_DYLIB=0 opt-out of raw-dylib linking for Windows. #​6185
Fixed
  • Fix PyO3 0.29 regression with failure to link under Cygwin / MSYS2. #​6185
  • Fix stubs generation for field getters (#[pyo3(get)]) when IntoPyObject is only implemented on references of the field type. #​6276
  • Fix #[classmethod] magic methods receiving the instance instead of its type when invoked through a type slot. #​6283
  • Fix pyo3_build_config::add_libpython_rpath_link_args emitting Unix-style rpath linker arguments on Windows and Cygwin. #​6284
  • Fix PyO3 0.29.1 regression on PyPy causing crashes when deallocating #[pyclass] instances. #​6294
  • Fix missing trailing nul in Python 3.9 #[pyclass] docstrings. #​6296
  • Fix reference count leak of #[classattr] values created from fn items. #​6297
rayon-rs/rayon (rayon)

v1.12.0

Compare Source

  • Fixed a bug in parallel Range<char> when the end is 0xE000, just past the
    surrogate boundary, which was unsafely producing invalid char values.
  • The new method ParallelSlice::par_array_windows works like par_windows
    but with a constant length, producing &[T; N] items.
serde-rs/serde (serde)

v1.0.229

Compare Source

  • Update to syn 3
serde-rs/json (serde_json)

v1.0.151

Compare Source

v1.0.150

Compare Source

simd-lite/simd-json (simd-json)

v0.18.1

Compare Source

v0.18.0

Compare Source

v0.17.3

Compare Source

v0.17.2

Compare Source

v0.17.1

Compare Source

v0.17.0

Compare Source

v0.16.0

Compare Source

v0.15.1

Compare Source

v0.15.0

Compare Source

v0.14.3

Compare Source

v0.14.2

Compare Source

v0.14.1

Compare Source

v0.14.0

Compare Source

RustCrypto/utils (zeroize)

v1.9.0

Compare Source


Configuration

📅 Schedule: (in timezone Australia/Sydney)

  • Branch creation
    • "before 6am"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

Summary

This PR updates two Rust dependencies in Cargo.toml, as generated by Renovate.

Crate Previous Updated
numpy 0.25 0.29
simd-json 0.13 0.18

Details

  • numpy (0.25 → 0.29): This version now matches the pyo3 version already declared (0.29). The numpy crate typically tracks pyo3 releases, so this likely resolves a version mismatch between the two.
  • simd-json (0.13 → 0.18): This updates the performance-oriented JSON parsing dependency by several minor versions.

Notes

  • No public APIs of this project change in this diff. Only dependency version constraints are modified.
  • Both crates are pre-1.0, so under Cargo's semver rules these minor bumps may contain breaking API changes, despite the "non-major" label. Code that uses numpy or simd-json may need adjustments. Build and test results should be confirmed before merging.

@cachekit-renovate-bot cachekit-renovate-bot Bot added the dependencies Pull requests that update a dependency file label Sep 29, 2026
@kodus-27b

kodus-27b Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

Kody Code Review — 1 suggested fix.
Paste the prompt below to your agent and all review fixed at once!

🛠️ Open Agent Prompt
A code review identified the following issues in this pull request.
Each section describes what was found and includes a reference implementation where available.

Files involved:
- Cargo.toml:11

---

### [1/1] Cargo.toml:11
Issue identified during code review:
WHAT: The numpy crate is bumped from 0.25 to 0.29 with no evidence of a vulnerability or supply-chain check. WHY: A dependency manifest change can introduce known CVEs or unexpected transitive changes. HOW: Run cargo audit (or an OSV/SCA scan) for numpy 0.29, attach the output to the PR, and commit the updated Cargo.lock.

---

Review each issue in context, use the reference implementations as guidance, and apply fixes that are consistent with the surrounding codebase.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: cachekit-io/cachekit-py/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: c4be495e-e4d5-4180-9fae-67608847838a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread Cargo.toml
serde_json = "1.0"
bincode = "1.3"
numpy = "0.25"
numpy = "0.29"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

WHAT: The numpy crate is bumped from 0.25 to 0.29 with no evidence of a vulnerability or supply-chain check. WHY: A dependency manifest change can introduce known CVEs or unexpected transitive changes. HOW: Run cargo audit (or an OSV/SCA scan) for numpy 0.29, attach the output to the PR, and commit the updated Cargo.lock.

Also found in:

  • Cargo.toml:15-15

Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk

Prompt for LLM

File Cargo.toml:

Line 11:

WHAT: The numpy crate is bumped from 0.25 to 0.29 with no evidence of a vulnerability or supply-chain check. WHY: A dependency manifest change can introduce known CVEs or unexpected transitive changes. HOW: Run cargo audit (or an OSV/SCA scan) for numpy 0.29, attach the output to the PR, and commit the updated Cargo.lock.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

@kodus-27b

This comment has been minimized.

Comment thread Cargo.toml
serde_json = "1.0"
bincode = "1.3"
numpy = "0.25"
numpy = "0.29"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

Unaudited dependency upgrade in Cargo.toml: the numpy crate jumps from 0.25 to 0.29 across several minor releases, and the PR includes no audit evidence. If 0.29 pulls in a transitive dependency with a known advisory, that dependency ships without review. Fix: run cargo audit/OSV against the new version, attach the output to the PR, and confirm Cargo.lock is updated.

Also found in:

  • Cargo.toml:15-15

Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk

Prompt for LLM

File Cargo.toml:

Line 11:

Unaudited dependency upgrade in Cargo.toml: the numpy crate jumps from 0.25 to 0.29 across several minor releases, and the PR includes no audit evidence. If 0.29 pulls in a transitive dependency with a known advisory, that dependency ships without review. Fix: run cargo audit/OSV against the new version, attach the output to the PR, and confirm Cargo.lock is updated.

**Also found in:**
- `Cargo.toml:15-15`

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

@kodus-27b

kodus-27b Bot commented Sep 30, 2026

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

@codecov

codecov Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

@27Bslash6
27Bslash6 merged commit 85cee3e into main Sep 30, 2026
38 checks passed
@27Bslash6
27Bslash6 deleted the renovate/all-minor-patch branch September 30, 2026 09:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant