Skip to content

chore(deps) #386: update sub-workspace Cargo.lock files to resolve Dependabot alerts - #387

Merged
JoshuaChi merged 1 commit into
mainfrom
fix/rustsec-dependency-audit
May 19, 2026
Merged

JoshuaChi merged 1 commit into
mainfrom
fix/rustsec-dependency-audit

Conversation

@JoshuaChi

Copy link
Copy Markdown
Contributor

What Does This PR Do?

Updates stale Cargo.lock files in three standalone example crates and removes
an orphaned lockfile from d-engine-client (workspace member, never used by Cargo)
to clear 30 open Dependabot alerts.

Type:


Why Is This Needed?

30 Dependabot alerts were open against sub-directory Cargo.lock files. The main
workspace Cargo.lock was already clean — the alerts came from stale pinned versions
in standalone example crates and one orphaned lockfile in d-engine-client/.

Packages updated: astral-tokio-tar 0.6.0→0.6.2, rustls-webpki →0.103.13,
openssl →0.10.80, rand →0.8.6.


Checklist

Required:

  • make test passes
  • Added tests for new code — N/A (lockfile-only changes)
  • Commits squashed to 1-2 logical units

Testing

How tested:

  • make test passes clean (advisory + fmt + clippy + all examples + benchmarks)
  • cargo deny check advisories clean on all affected directories
  • Dependabot alerts verified via GitHub API before and after

Does This Follow d-engine's Principles?

  • Solves a real problem for most users (not just my edge case)
  • Keeps implementation simple
  • Doesn't bloat the API surface

Reviewer Notes

Pure lockfile updates — no production code changed. d-engine-client/Cargo.lock
removal is safe: the file was never used (Cargo workspace members share the root
lockfile; the sub-directory one was an orphan from initial scaffolding).

Estimated review complexity:

  • Quick (< 100 lines)

…pendabot alerts

Three standalone example crates had stale pinned dependencies; one orphaned
workspace-member lockfile was removed (d-engine-client/Cargo.lock is unused
since the crate builds under the parent workspace).
@coderabbitai

coderabbitai Bot commented May 19, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Review was skipped due to path filters

⛔ Files ignored due to path filters (5)
  • Cargo.lock is excluded by !**/*.lock
  • d-engine-client/Cargo.lock is excluded by !**/*.lock
  • examples/client-usage-standalone/Cargo.lock is excluded by !**/*.lock
  • examples/single-node-expansion/Cargo.lock is excluded by !**/*.lock
  • examples/three-nodes-embedded/Cargo.lock is excluded by !**/*.lock

CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including **/dist/** will override the default block on the dist directory, by removing the pattern from both the lists.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 625ecc05-87c2-42bd-8219-86ab54a69bfa

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • ✅ Review completed - (🔄 Check again to review again)
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/rustsec-dependency-audit

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@codecov

codecov Bot commented May 19, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@JoshuaChi
JoshuaChi merged commit a5f92b8 into main May 19, 2026
9 checks passed
@JoshuaChi
JoshuaChi deleted the fix/rustsec-dependency-audit branch May 19, 2026 10:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant