Repository navigation
chore #353: update dependencies to resolve Dependabot security alerts - #356
Conversation
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
📝 WalkthroughWalkthroughUpdated Go module metadata and bumped multiple Go dependency versions in Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🧹 Nitpick comments (1)
d-engine-proto/go/go.mod (1)
3-3: Add atoolchaindirective for consistency with other modules in this repository.The
d-engine-proto/go/go.modspecifies onlygo 1.25.0without an explicittoolchainpin, whileexamples/quick-start-standalone/go.modincludestoolchain go1.24.5. Since this module commits generated.pb.gofiles, aligning toolchain pins across modules ensures reproducible builds locally and across contributors.🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In `@d-engine-proto/go/go.mod` at line 3, The go.mod in d-engine-proto/go is missing a repository-standard toolchain pin; add a toolchain directive to that file to match the rest of the repo (e.g., the same toolchain used in examples/quick-start-standalone/go.mod such as go1.24.5) so builds are reproducible, ensuring the new line is placed alongside the existing "go 1.25.0" directive in d-engine-proto/go/go.mod.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@examples/client-usage-standalone/Cargo.toml`:
- Line 11: Remove the unused dependency declaration env_logger = "0.11" from the
Cargo.toml for the examples/client-usage-standalone crate; locate the env_logger
entry in the dependencies list and delete that line so the example's Cargo.toml
matches other examples and avoids adding an unnecessary dependency not
referenced by examples/client-usage-standalone/src/main.rs.
---
Nitpick comments:
In `@d-engine-proto/go/go.mod`:
- Line 3: The go.mod in d-engine-proto/go is missing a repository-standard
toolchain pin; add a toolchain directive to that file to match the rest of the
repo (e.g., the same toolchain used in examples/quick-start-standalone/go.mod
such as go1.24.5) so builds are reproducible, ensuring the new line is placed
alongside the existing "go 1.25.0" directive in d-engine-proto/go/go.mod.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: e7018ed6-8210-4f44-b4f6-56e8215296ee
⛔ Files ignored due to path filters (5)
Cargo.lockis excluded by!**/*.lockd-engine-proto/go/go.sumis excluded by!**/*.sumexamples/client-usage-standalone/Cargo.lockis excluded by!**/*.lockexamples/single-node-expansion/Cargo.lockis excluded by!**/*.lockexamples/three-nodes-embedded/Cargo.lockis excluded by!**/*.lock
📒 Files selected for processing (2)
d-engine-proto/go/go.modexamples/client-usage-standalone/Cargo.toml
- examples/single-node-expansion: aws-lc-sys 0.34→0.39.1 (5 high CVEs) - examples/client-usage-standalone: env_logger 0.9→0.11 (drops atty) - examples/*/Cargo.lock: rustls-webpki, bytes, time updated - d-engine-proto/go: grpc v1.64→v1.80, golang.org/x/net updated - Root Cargo.lock: general dependency updates
f3c509c to
3d0e6cf
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
What Does This PR Do?
Updates lock files and one direct dependency to resolve 20 open Dependabot
security alerts across examples and the proto tooling directory.
Type:
Why Is This Needed?
Dependabot reported 22 open alerts on the default branch. This PR addresses
all actionable ones:
google.golang.org/grpc(Go)aws-lc-sysatty(unmaintained)env_logger0.9 → 0.11 removes the dependency entirelygrpc-gotoken leakgoogle.golang.org/grpcv1.64 → v1.80 in proto toolingrustls-webpki,bytes,timecargo updateon affected lock filesAll
aws-lc-sysvulnerabilities are inexamples/single-node-expansion—a transitive dependency of
tonic's TLS feature. The main workspace wasalready on a clean version.
Checklist
Required:
make testpassesTesting
How tested:
cargo checkonexamples/client-usage-standaloneafterenv_loggerupgrade — no errorscargo updateon all affected example lock files — no version conflictsDoes This Follow d-engine's Principles?
Reviewer Notes
Lock file changes only (plus one
Cargo.tomlline forenv_logger). Nosource code changes. Safe to merge without deep review.
Estimated review complexity:
Summary by CodeRabbit