Repository navigation
Conversation
Co-authored-by: uurcan7 <79050542+uurcan7@users.noreply.github.com>
Add Dependabot configuration for Rust and GitHub Actions updates
Bumps [actions/cache](https://github.com/actions/cache) from 4 to 6. - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@v4...v6) --- updated-dependencies: - dependency-name: actions/cache dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [serde_json](https://github.com/serde-rs/json) from 1.0.149 to 1.0.151. - [Release notes](https://github.com/serde-rs/json/releases) - [Commits](serde-rs/json@v1.0.149...v1.0.151) --- updated-dependencies: - dependency-name: serde_json dependency-version: 1.0.151 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [base64](https://github.com/marshallpierce/rust-base64) from 0.22.1 to 0.23.1. - [Changelog](https://github.com/marshallpierce/rust-base64/blob/master/RELEASE-NOTES.md) - [Commits](marshallpierce/rust-base64@v0.22.1...v0.23.1) --- updated-dependencies: - dependency-name: base64 dependency-version: 0.23.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 7. - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v4...v7) --- updated-dependencies: - dependency-name: actions/upload-artifact dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [rand](https://github.com/rust-random/rand) from 0.8.5 to 0.10.2. - [Release notes](https://github.com/rust-random/rand/releases) - [Changelog](https://github.com/rust-random/rand/blob/master/CHANGELOG.md) - [Commits](rust-random/rand@0.8.5...0.10.2) --- updated-dependencies: - dependency-name: rand dependency-version: 0.10.2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 8. - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@v4...v8) --- updated-dependencies: - dependency-name: actions/download-artifact dependency-version: '8' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…download-artifact-8 chore(deps): bump actions/download-artifact from 4 to 8
…upload-artifact-7 chore(deps): bump actions/upload-artifact from 4 to 7
chore(deps): bump base64 from 0.22.1 to 0.23.1 in /rust
…checkout-7 chore(deps): bump actions/checkout from 4 to 7
Bumps the cargo group with 1 update in the /rust directory: [rustls-webpki](https://github.com/rustls/webpki). Updates `rustls-webpki` from 0.103.9 to 0.103.15 - [Release notes](https://github.com/rustls/webpki/releases) - [Commits](rustls/webpki@v/0.103.9...v/0.103.15) --- updated-dependencies: - dependency-name: rustls-webpki dependency-version: 0.103.15 dependency-type: indirect dependency-group: cargo ... Signed-off-by: dependabot[bot] <support@github.com>
….0.151 chore(deps): bump serde_json from 1.0.149 to 1.0.151 in /rust
…cache-6 chore(deps): bump actions/cache from 4 to 6
Bumps [nix](https://github.com/nix-rust/nix) from 0.29.0 to 0.31.1. - [Changelog](https://github.com/nix-rust/nix/blob/master/CHANGELOG.md) - [Commits](nix-rust/nix@v0.29.0...v0.31.1) --- updated-dependencies: - dependency-name: nix dependency-version: 0.31.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
chore(deps): bump nix from 0.29.0 to 0.31.1 in /rust
…72ccb chore(deps): bump rustls-webpki from 0.103.9 to 0.103.15 in /rust in the cargo group across 1 directory
Bumps [rcgen](https://github.com/rustls/rcgen) from 0.12.1 to 0.14.10. - [Release notes](https://github.com/rustls/rcgen/releases) - [Commits](rustls/rcgen@v0.12.1...v0.14.10) --- updated-dependencies: - dependency-name: rcgen dependency-version: 0.14.10 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: uurcan7 <79050542+uurcan7@users.noreply.github.com>
Agent-Logs-Url: https://github.com/uurcan7/tricky-addon-enhanced/sessions/78871aec-e0d0-409b-a919-07d99b9e8af8 Co-authored-by: uurcan7 <79050542+uurcan7@users.noreply.github.com>
chore(deps): bump rand from 0.8.5 to 0.10.2 in /rust
chore(deps): bump rcgen from 0.12.1 to 0.14.10 in /rust
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 4 included reviews per hour; 2 remain after this review. 📝 WalkthroughWalkthroughThe pull request updates Rust dependencies, migrates ChangesDependency and CI maintenance
Estimated code review effort: 2 (Simple) | ~10 minutes Merge Risk: ⚪ Minimal · up to This updates dependency and CI maintenance and adjusts shutdown-handler registration compatibility. No concrete current-head issue remains that would block merge. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Warning Some tools did not complete. Review the errors below. 🔧 Clippy (1.98.0)Clippy execution failed Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
🔵 Needs a closer look
It upgrades multiple foundational dependencies (including crypto/cert tooling) and CI action major versions, which should be validated by a green CI run and any required runtime smoke checks.
Pull request overview
This pull request modernizes dependency management and CI for the project while updating Rust crypto/certificate code to match newer rcgen APIs.
Changes:
- Updated Rust crate dependencies (notably
rcgen,base64,nix,serde_json) and refreshedCargo.lock. - Refactored ECDSA P-256 self-signed certificate generation to use
rcgen::KeyPair+CertificateParams::self_signed. - Modernized GitHub Actions workflow action versions and added a weekly Dependabot configuration for Cargo and Actions.
File summaries
| File | Description |
|---|---|
| rust/src/keybox/validate.rs | Updates test certificate creation to the rcgen 0.14 KeyPair/self_signed API and adjusts DER handling accordingly. |
| rust/src/keybox/generate.rs | Refactors runtime key/cert generation to use KeyPair::generate_for + self_signed, and switches to new PEM accessors. |
| rust/Cargo.toml | Bumps key Rust dependencies (including rcgen 0.14, base64 0.23, nix 0.31, serde_json patch). |
| rust/Cargo.lock | Regenerates lockfile to reflect updated transitive dependency graph. |
| .github/workflows/build.yml | Updates checkout/cache/artifact actions to newer major versions. |
| .github/dependabot.yml | Adds weekly Dependabot updates for Cargo and GitHub Actions. |
Review details
- Files reviewed: 5/6 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Co-authored-by: uurcan7 <79050542+uurcan7@users.noreply.github.com>
Co-authored-by: uurcan7 <79050542+uurcan7@users.noreply.github.com>
Harden build workflow token scope to resolve CodeQL permissions alert
Harden build workflow token scope with explicit default permissions
Co-authored-by: uurcan7 <79050542+uurcan7@users.noreply.github.com>
Fix signal handler pointer cast warning in Rust platform layer
There was a problem hiding this comment.
🟡 Changes recommended
Three references to nonexistent actions/download-artifact@v8 will prevent packaging and release jobs from running.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review details
- Files reviewed: 6/7 changed files
- Comments generated: 0 new
- Review effort level: Balanced
This pull request updates dependencies and refactors certificate generation in the Rust codebase, while also modernizing the GitHub Actions workflows. The main goals are to keep dependencies up to date, improve compatibility with the latest APIs, and ensure CI stability.
Dependency Updates:
Cargo.toml, includingserde_json,base64,nix, andrcgen, to address potential security and compatibility issues.Certificate Generation Refactor:
generate.rsand related tests to use the newKeyPairandself_signedAPI fromrcgen, replacing the deprecated usage of thealgfield andCertificate::from_params. [1] [2] [3] [4] [5]CI/CD Workflow Modernization:
actions/checkout@v7,actions/cache@v6,actions/upload-artifact@v7,actions/download-artifact@v8) to benefit from the latest features and security patches. [1] [2] [3] [4] [5] [6]Dependabot Configuration:
.github/dependabot.ymlfile to automate dependency update PRs for both Rust (cargo) and GitHub Actions workflows, scheduled weekly.Summary by CodeRabbit
Chores
Tests