Skip to content

Add Dependabot configuration and update Rust dependencies - #41

Open
uurcan7 wants to merge 32 commits into
Enginex0:mainfrom
uurcan7:main
Open

uurcan7 wants to merge 32 commits into
Enginex0:mainfrom
uurcan7:main

Conversation

@uurcan7

@uurcan7 uurcan7 commented Sep 9, 2026 •

Copy link
Copy Markdown

This pull request updates dependencies and refactors certificate generation in the Rust codebase, while also modernizing the GitHub Actions workflows. The main goals are to keep dependencies up to date, improve compatibility with the latest APIs, and ensure CI stability.

Dependency Updates:

  • Updated several Rust crate dependencies to their latest versions in Cargo.toml, including serde_json, base64, nix, and rcgen, to address potential security and compatibility issues.

Certificate Generation Refactor:

  • Refactored ECDSA certificate generation in generate.rs and related tests to use the new KeyPair and self_signed API from rcgen, replacing the deprecated usage of the alg field and Certificate::from_params. [1] [2] [3] [4] [5]

CI/CD Workflow Modernization:

  • Updated GitHub Actions workflow files to use the latest major versions of actions (e.g., actions/checkout@v7, actions/cache@v6, actions/upload-artifact@v7, actions/download-artifact@v8) to benefit from the latest features and security patches. [1] [2] [3] [4] [5] [6]

Dependabot Configuration:

  • Added a .github/dependabot.yml file to automate dependency update PRs for both Rust (cargo) and GitHub Actions workflows, scheduled weekly.

Summary by CodeRabbit

  • Chores

    • Added automated weekly checks for dependency and workflow updates.
    • Updated project dependencies and build automation components to newer versions.
    • Refreshed certificate generation and validation compatibility with current libraries.
    • Improved build workflow security by applying read-only default repository permissions.
  • Tests

    • Updated certificate-related test coverage to use supported APIs while preserving existing validation behavior.

Copilot AI and others added 24 commits September 9, 2026 06:56
Co-authored-by: uurcan7 <79050542+uurcan7@users.noreply.github.com>
Add Dependabot configuration for Rust and GitHub Actions updates
Bumps [actions/cache](https://github.com/actions/cache) from 4 to 6.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v4...v6)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [serde_json](https://github.com/serde-rs/json) from 1.0.149 to 1.0.151.
- [Release notes](https://github.com/serde-rs/json/releases)
- [Commits](serde-rs/json@v1.0.149...v1.0.151)

---
updated-dependencies:
- dependency-name: serde_json
  dependency-version: 1.0.151
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [base64](https://github.com/marshallpierce/rust-base64) from 0.22.1 to 0.23.1.
- [Changelog](https://github.com/marshallpierce/rust-base64/blob/master/RELEASE-NOTES.md)
- [Commits](marshallpierce/rust-base64@v0.22.1...v0.23.1)

---
updated-dependencies:
- dependency-name: base64
  dependency-version: 0.23.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 7.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v4...v7)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [rand](https://github.com/rust-random/rand) from 0.8.5 to 0.10.2.
- [Release notes](https://github.com/rust-random/rand/releases)
- [Changelog](https://github.com/rust-random/rand/blob/master/CHANGELOG.md)
- [Commits](rust-random/rand@0.8.5...0.10.2)

---
updated-dependencies:
- dependency-name: rand
  dependency-version: 0.10.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 8.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@v4...v8)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: '8'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
…download-artifact-8

chore(deps): bump actions/download-artifact from 4 to 8
…upload-artifact-7

chore(deps): bump actions/upload-artifact from 4 to 7
chore(deps): bump base64 from 0.22.1 to 0.23.1 in /rust
…checkout-7

chore(deps): bump actions/checkout from 4 to 7
Bumps the cargo group with 1 update in the /rust directory: [rustls-webpki](https://github.com/rustls/webpki).


Updates `rustls-webpki` from 0.103.9 to 0.103.15
- [Release notes](https://github.com/rustls/webpki/releases)
- [Commits](rustls/webpki@v/0.103.9...v/0.103.15)

---
updated-dependencies:
- dependency-name: rustls-webpki
  dependency-version: 0.103.15
  dependency-type: indirect
  dependency-group: cargo
...

Signed-off-by: dependabot[bot] <support@github.com>
….0.151

chore(deps): bump serde_json from 1.0.149 to 1.0.151 in /rust
…cache-6

chore(deps): bump actions/cache from 4 to 6
Bumps [nix](https://github.com/nix-rust/nix) from 0.29.0 to 0.31.1.
- [Changelog](https://github.com/nix-rust/nix/blob/master/CHANGELOG.md)
- [Commits](nix-rust/nix@v0.29.0...v0.31.1)

---
updated-dependencies:
- dependency-name: nix
  dependency-version: 0.31.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
chore(deps): bump nix from 0.29.0 to 0.31.1 in /rust
…72ccb

chore(deps): bump rustls-webpki from 0.103.9 to 0.103.15 in /rust in the cargo group across 1 directory
Bumps [rcgen](https://github.com/rustls/rcgen) from 0.12.1 to 0.14.10.
- [Release notes](https://github.com/rustls/rcgen/releases)
- [Commits](rustls/rcgen@v0.12.1...v0.14.10)

---
updated-dependencies:
- dependency-name: rcgen
  dependency-version: 0.14.10
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: uurcan7 <79050542+uurcan7@users.noreply.github.com>
Agent-Logs-Url: https://github.com/uurcan7/tricky-addon-enhanced/sessions/78871aec-e0d0-409b-a919-07d99b9e8af8

Co-authored-by: uurcan7 <79050542+uurcan7@users.noreply.github.com>
chore(deps): bump rand from 0.8.5 to 0.10.2 in /rust
chore(deps): bump rcgen from 0.12.1 to 0.14.10 in /rust
Copilot AI lite review requested due to automatic review settings September 9, 2026 07:38
@coderabbitai

coderabbitai Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: a38cded2-caa4-40fc-a117-9332f8ea89f5

📥 Commits

Reviewing files that changed from the base of the PR and between 11e9b00 and 9a91d77.

📒 Files selected for processing (1)
  • rust/src/platform/signal.rs

Included review availability: Your plan provides up to 4 included reviews per hour; 2 remain after this review.


📝 Walkthrough

Walkthrough

The pull request updates Rust dependencies, migrates rcgen certificate generation and validation code to newer APIs, adjusts signal handler casting, upgrades GitHub Actions versions, and adds weekly Dependabot checks.

Changes

Dependency and CI maintenance

Layer / File(s) Summary
rcgen API migration
rust/Cargo.toml, rust/src/keybox/generate.rs
Updates dependency versions and changes production certificate generation to use KeyPair, self_signed, and certificate PEM APIs.
Validation test migration
rust/src/keybox/validate.rs
Updates three validation tests to use the new rcgen key-pair, self-signed certificate, and DER APIs.
Signal handler compatibility
rust/src/platform/signal.rs
Casts the shutdown handler through *const () before converting it to usize.
Automation update configuration
.github/dependabot.yml, .github/workflows/build.yml
Adds weekly Dependabot checks, restricts workflow contents permissions, and upgrades GitHub Actions versions.

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: ⚪ Minimal · up to 9a91d

This updates dependency and CI maintenance and adjusts shutdown-handler registration compatibility. No concrete current-head issue remains that would block merge.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 60.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 3 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately describes the main changes: adding Dependabot configuration and updating Rust dependencies. It does not mention the GitHub Actions upgrades or rcgen API refactor, but the title do…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Warning

Some tools did not complete. Review the errors below.

🔧 Clippy (1.98.0)

Clippy execution failed


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

It upgrades multiple foundational dependencies (including crypto/cert tooling) and CI action major versions, which should be validated by a green CI run and any required runtime smoke checks.

Pull request overview

This pull request modernizes dependency management and CI for the project while updating Rust crypto/certificate code to match newer rcgen APIs.

Changes:

  • Updated Rust crate dependencies (notably rcgen, base64, nix, serde_json) and refreshed Cargo.lock.
  • Refactored ECDSA P-256 self-signed certificate generation to use rcgen::KeyPair + CertificateParams::self_signed.
  • Modernized GitHub Actions workflow action versions and added a weekly Dependabot configuration for Cargo and Actions.
File summaries
File Description
rust/src/keybox/validate.rs Updates test certificate creation to the rcgen 0.14 KeyPair/self_signed API and adjusts DER handling accordingly.
rust/src/keybox/generate.rs Refactors runtime key/cert generation to use KeyPair::generate_for + self_signed, and switches to new PEM accessors.
rust/Cargo.toml Bumps key Rust dependencies (including rcgen 0.14, base64 0.23, nix 0.31, serde_json patch).
rust/Cargo.lock Regenerates lockfile to reflect updated transitive dependency graph.
.github/workflows/build.yml Updates checkout/cache/artifact actions to newer major versions.
.github/dependabot.yml Adds weekly Dependabot updates for Cargo and GitHub Actions.
Review details
  • Files reviewed: 5/6 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Copilot AI and others added 6 commits September 10, 2026 06:49
Co-authored-by: uurcan7 <79050542+uurcan7@users.noreply.github.com>
Co-authored-by: uurcan7 <79050542+uurcan7@users.noreply.github.com>
Harden build workflow token scope to resolve CodeQL permissions alert
Harden build workflow token scope with explicit default permissions
Co-authored-by: uurcan7 <79050542+uurcan7@users.noreply.github.com>
Fix signal handler pointer cast warning in Rust platform layer

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Three references to nonexistent actions/download-artifact@v8 will prevent packaging and release jobs from running.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Review details
  • Files reviewed: 6/7 changed files
  • Comments generated: 0 new
  • Review effort level: Balanced

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants