-
Notifications
You must be signed in to change notification settings - Fork 0
chore(deps): update all non-major dependencies #369
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -8,11 +8,11 @@ pyo3 = { version = "0.29", features = ["extension-module"] } | |
| serde = { version = "1.0", features = ["derive"] } | ||
| serde_json = "1.0" | ||
| bincode = "1.3" | ||
| numpy = "0.25" | ||
| numpy = "0.29" | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Unaudited dependency upgrade in Cargo.toml: the numpy crate jumps from 0.25 to 0.29 across several minor releases, and the PR includes no audit evidence. If 0.29 pulls in a transitive dependency with a known advisory, that dependency ships without review. Fix: run cargo audit/OSV against the new version, attach the output to the PR, and confirm Cargo.lock is updated. Also found in:
Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk Prompt for LLMTalk to Kody by mentioning @kody Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction. |
||
|
|
||
| # Performance dependencies | ||
| rayon = "1.8" | ||
| simd-json = "0.13" | ||
| simd-json = "0.18" | ||
| lz4 = "1.24" | ||
| memmap2 = "0.9" | ||
|
|
||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
WHAT: The numpy crate is bumped from 0.25 to 0.29 with no evidence of a vulnerability or supply-chain check. WHY: A dependency manifest change can introduce known CVEs or unexpected transitive changes. HOW: Run cargo audit (or an OSV/SCA scan) for numpy 0.29, attach the output to the PR, and commit the updated Cargo.lock.
Also found in:
Cargo.toml:15-15Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk
Prompt for LLM
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.