Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -8,11 +8,11 @@ pyo3 = { version = "0.29", features = ["extension-module"] }
serde = { version = "1.0", features = ["derive"] }
serde_json = "1.0"
bincode = "1.3"
numpy = "0.25"
numpy = "0.29"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

WHAT: The numpy crate is bumped from 0.25 to 0.29 with no evidence of a vulnerability or supply-chain check. WHY: A dependency manifest change can introduce known CVEs or unexpected transitive changes. HOW: Run cargo audit (or an OSV/SCA scan) for numpy 0.29, attach the output to the PR, and commit the updated Cargo.lock.

Also found in:

  • Cargo.toml:15-15

Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk

Prompt for LLM

File Cargo.toml:

Line 11:

WHAT: The numpy crate is bumped from 0.25 to 0.29 with no evidence of a vulnerability or supply-chain check. WHY: A dependency manifest change can introduce known CVEs or unexpected transitive changes. HOW: Run cargo audit (or an OSV/SCA scan) for numpy 0.29, attach the output to the PR, and commit the updated Cargo.lock.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules high

Unaudited dependency upgrade in Cargo.toml: the numpy crate jumps from 0.25 to 0.29 across several minor releases, and the PR includes no audit evidence. If 0.29 pulls in a transitive dependency with a known advisory, that dependency ships without review. Fix: run cargo audit/OSV against the new version, attach the output to the PR, and confirm Cargo.lock is updated.

Also found in:

  • Cargo.toml:15-15

Kody rule violation: Validate new/updated dependencies for CVEs and supply-chain risk

Prompt for LLM

File Cargo.toml:

Line 11:

Unaudited dependency upgrade in Cargo.toml: the numpy crate jumps from 0.25 to 0.29 across several minor releases, and the PR includes no audit evidence. If 0.29 pulls in a transitive dependency with a known advisory, that dependency ships without review. Fix: run cargo audit/OSV against the new version, attach the output to the PR, and confirm Cargo.lock is updated.

**Also found in:**
- `Cargo.toml:15-15`

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​


# Performance dependencies
rayon = "1.8"
simd-json = "0.13"
simd-json = "0.18"
lz4 = "1.24"
memmap2 = "0.9"

Expand Down
Loading