deps: refresh transitive lockfile dependencies (MSRV-aware) - #181
Merged
Merged
Conversation
Semver-compatible cargo update of transitive crates that Dependabot's direct-dependency groups do not cover, resolved against rust-version 1.90. Cargo.toml unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
The informational Outdated Dependencies job lists many semver-compatible transitive updates that Dependabot's grouped direct-dependency PRs never reach. This refreshes
Cargo.lockwithcargo updateunderCARGO_RESOLVER_INCOMPATIBLE_RUST_VERSIONS=fallback. The crate uses edition 2021 (resolver v2), which otherwise ignoresrust-version, so the fallback setting is what keeps every locked crate compatible with the 1.90 MSRV.Changes Made
Cargo.lock: 109 packages updated. Highlights:wgpu-core/wgpu-hal/wgpu-types/naga30.0.0 → 30.0.1,rand0.9.5 / 0.10.3,regex1.13,uuid1.26,tempfile3.27. Duplicatewindows-sys/windows-targetsversions are collapsed.CHANGELOG.md:[Unreleased]entry targeting 0.5.9.Cargo.tomlis unchanged, with no public API or feature-flag impact.Testing
./scripts/safe_local_test.sh --allow-network: 149 tests and 22 doctests passed (slow ESDF test skipped by default).cargo clippy --locked --all-targets --all-features -- -D warningsandcargo fmt --checkare clean.cargo deny check bans licenses sourcespasses. Local advisory parsing hits the known CVSS 4.0 limitation, so the hosted Cargo Deny/audit checks are authoritative.cargo auditfinds no vulnerabilities; only the knownpasteunmaintained warning remains.🤖 Generated with Claude Code