Skip to content

chore #353: update dependencies to resolve Dependabot security alerts - #356

Merged
JoshuaChi merged 3 commits into
mainfrom
chore/security-aws-lc-sys
Apr 12, 2026
Merged

JoshuaChi merged 3 commits into
mainfrom
chore/security-aws-lc-sys

Conversation

@JoshuaChi

@JoshuaChi JoshuaChi commented Apr 12, 2026 •

Copy link
Copy Markdown
Contributor

What Does This PR Do?

Updates lock files and one direct dependency to resolve 20 open Dependabot
security alerts across examples and the proto tooling directory.

Type:

  • Bug Fix (with test)

Why Is This Needed?

Dependabot reported 22 open alerts on the default branch. This PR addresses
all actionable ones:

Severity Package Fix
🔴 Critical (2) google.golang.org/grpc (Go) Dismissed — proto codegen tool only, not runtime
🟠 High (5) aws-lc-sys 0.34 → 0.39.1 (CRL bypass, name constraint bypass, PKCS7 signature bypass, timing side-channel, cert chain bypass)
🔵 Low atty (unmaintained) env_logger 0.9 → 0.11 removes the dependency entirely
🔵 Low grpc-go token leak google.golang.org/grpc v1.64 → v1.80 in proto tooling
🟡 Moderate (13) rustls-webpki, bytes, time Covered by cargo update on affected lock files

All aws-lc-sys vulnerabilities are in examples/single-node-expansion —
a transitive dependency of tonic's TLS feature. The main workspace was
already on a clean version.


Checklist

Required:

  • make test passes
  • Added tests for new code
  • Commits squashed to 1-2 logical units

Testing

How tested:

  • cargo check on examples/client-usage-standalone after env_logger upgrade — no errors
  • cargo update on all affected example lock files — no version conflicts

Does This Follow d-engine's Principles?

  • Solves a real problem for most users (not just my edge case)
  • Keeps implementation simple
  • Doesn't bloat the API surface

Reviewer Notes

Lock file changes only (plus one Cargo.toml line for env_logger). No
source code changes. Safe to merge without deep review.

Estimated review complexity:

  • Quick (< 100 lines)

Summary by CodeRabbit

  • Chores
    • Updated multiple backend dependencies to newer stable releases to improve security, compatibility, and reliability.
    • Refreshed the Go toolchain directive to align with current tooling standards.
    • Removed an unused example dependency from a sample project to simplify example setup.

@coderabbitai

coderabbitai Bot commented Apr 12, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Review was skipped due to path filters

⛔ Files ignored due to path filters (1)
  • examples/client-usage-standalone/Cargo.lock is excluded by !**/*.lock

CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including **/dist/** will override the default block on the dist directory, by removing the pattern from both the lists.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 25f0800a-1716-4bbb-8c5f-2f3850f193a2

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • ✅ Review completed - (🔄 Check again to review again)
📝 Walkthrough

Walkthrough

Updated Go module metadata and bumped multiple Go dependency versions in d-engine-proto/go/go.mod. Removed an env_logger dependency line from the Rust example examples/client-usage-standalone/Cargo.toml.

Changes

Cohort / File(s) Summary
Go module & deps
d-engine-proto/go/go.mod
Removed explicit toolchain directive and set go 1.25.0; upgraded google.golang.org/grpc (v1.64.0 → v1.80.0), google.golang.org/protobuf (v1.36.0 → v1.36.11), and updated indirect deps (golang.org/x/net, golang.org/x/sys, golang.org/x/text, google.golang.org/genproto).
Rust example Cargo
examples/client-usage-standalone/Cargo.toml
Removed the env_logger = "0.9.0" dependency entry (no replacement added in this diff).

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Poem

🐰 I hopped through modules, neat and spry,
Bumped versions up toward the sky,
Removed a logger, trimmed the line,
New gRPC steps in tidy time,
Tiny changes — a joyful sigh. 🥕

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The PR title accurately reflects the primary objective: updating dependencies to address Dependabot security alerts, which is the main focus of all changes shown in the raw summary.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/security-aws-lc-sys

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
d-engine-proto/go/go.mod (1)

3-3: Add a toolchain directive for consistency with other modules in this repository.

The d-engine-proto/go/go.mod specifies only go 1.25.0 without an explicit toolchain pin, while examples/quick-start-standalone/go.mod includes toolchain go1.24.5. Since this module commits generated .pb.go files, aligning toolchain pins across modules ensures reproducible builds locally and across contributors.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@d-engine-proto/go/go.mod` at line 3, The go.mod in d-engine-proto/go is
missing a repository-standard toolchain pin; add a toolchain directive to that
file to match the rest of the repo (e.g., the same toolchain used in
examples/quick-start-standalone/go.mod such as go1.24.5) so builds are
reproducible, ensuring the new line is placed alongside the existing "go 1.25.0"
directive in d-engine-proto/go/go.mod.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In `@examples/client-usage-standalone/Cargo.toml`:
- Line 11: Remove the unused dependency declaration env_logger = "0.11" from the
Cargo.toml for the examples/client-usage-standalone crate; locate the env_logger
entry in the dependencies list and delete that line so the example's Cargo.toml
matches other examples and avoids adding an unnecessary dependency not
referenced by examples/client-usage-standalone/src/main.rs.

---

Nitpick comments:
In `@d-engine-proto/go/go.mod`:
- Line 3: The go.mod in d-engine-proto/go is missing a repository-standard
toolchain pin; add a toolchain directive to that file to match the rest of the
repo (e.g., the same toolchain used in examples/quick-start-standalone/go.mod
such as go1.24.5) so builds are reproducible, ensuring the new line is placed
alongside the existing "go 1.25.0" directive in d-engine-proto/go/go.mod.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: e7018ed6-8210-4f44-b4f6-56e8215296ee

📥 Commits

Reviewing files that changed from the base of the PR and between 9d6388b and f3c509c.

⛔ Files ignored due to path filters (5)
  • Cargo.lock is excluded by !**/*.lock
  • d-engine-proto/go/go.sum is excluded by !**/*.sum
  • examples/client-usage-standalone/Cargo.lock is excluded by !**/*.lock
  • examples/single-node-expansion/Cargo.lock is excluded by !**/*.lock
  • examples/three-nodes-embedded/Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (2)
  • d-engine-proto/go/go.mod
  • examples/client-usage-standalone/Cargo.toml

Comment thread examples/client-usage-standalone/Cargo.toml Outdated
- examples/single-node-expansion: aws-lc-sys 0.34→0.39.1 (5 high CVEs)
- examples/client-usage-standalone: env_logger 0.9→0.11 (drops atty)
- examples/*/Cargo.lock: rustls-webpki, bytes, time updated
- d-engine-proto/go: grpc v1.64→v1.80, golang.org/x/net updated
- Root Cargo.lock: general dependency updates
@JoshuaChi
JoshuaChi force-pushed the chore/security-aws-lc-sys branch from f3c509c to 3d0e6cf Compare April 12, 2026 13:53
@codecov

codecov Bot commented Apr 12, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@JoshuaChi
JoshuaChi merged commit 484cda0 into main Apr 12, 2026
10 of 11 checks passed
@JoshuaChi
JoshuaChi deleted the chore/security-aws-lc-sys branch April 12, 2026 14:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant