chore(deps): take four pcai_core majors and the grouped ignore patch - #105
Conversation
Supersedes #99, #100, #101, #102 and #103 -- five PRs against one workspace, resolved against a single lockfile and gated once rather than five times. ignore 0.4.32 -> 0.4.33 (#99, cargo-pcai-core group) base64 0.22 -> 0.23 (#100) rand 0.9.3 -> 0.10.2 (#101) schemars 0.8.22 -> 1.2.2 (#102) winreg 0.55 -> 0.56 (#103) Every one of these is a breaking-version bump for Cargo purposes, which is why dependabot raised them individually rather than folding them into the minor/patch group. None of them turned out to need a code change: the workspace compiles, lints and tests clean as-is. Note #101's title says "rand from 0.8.6 to 0.10.2", but the manifest declared 0.9.3 -- 0.8.6 is a transitive copy pulled in by third-party crates. The direct dependency moves 0.9.3 -> 0.10.2 and 0.8.6 remains in the lockfile, along with older base64 and schemars copies, for the same reason. That is expected and not something this PR can consolidate. Verified, rather than merged on the strength of a green lockfile: cargo check --workspace --all-targets exit 0 cargo clippy --workspace --all-targets -- -D warnings exit 0 cargo test --workspace --features server,ffi --lib exit 0 133 + 96 + 57 + 96 passed, 0 failed Resolved directly to base64 0.23.1, rand 0.10.2, schemars 1.2.2, winreg 0.56.0, ignore 0.4.33. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Mu7jB5ysKe4DN5ovjVtX1t
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
🟢 Approval recommended
The changes are constrained to dependency version/lockfile updates and the workspace MSRV is explicitly set to 1.85, aligning with the updated dependency requirements.
Pull request overview
This PR consolidates several Dependabot major (breaking-for-Cargo) dependency bumps for the Native/pcai_core Rust workspace into a single change, updating the manifests/lockfile without requiring code changes.
Changes:
- Bump direct workspace dependencies:
base64(0.22 → 0.23),rand(0.9.3 → 0.10.2),schemars(0.8.22 → 1.2.2),winreg(0.55 → 0.56). - Refresh
Cargo.lockto capture the resolved versions (including theignore0.4.32 → 0.4.33 patch-level resolution and updated transitive graph).
File summaries
| File | Description |
|---|---|
| Native/pcai_core/Cargo.toml | Updates the direct dependency version requirements for the workspace. |
| Native/pcai_core/Cargo.lock | Updates the resolved dependency graph to match the new requirements. |
Review details
- Files reviewed: 1/2 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Supersedes #99, #100, #101, #102 and #103 — five PRs against one workspace, resolved against a single lockfile and gated once rather than five times.
ignorebase64randschemarswinregEvery one of these is a breaking-version bump for Cargo purposes, which is why dependabot raised them individually rather than folding them into the minor/patch group. None turned out to need a code change — the workspace compiles, lints and tests clean as-is.
A note on #101's title
It says "rand from 0.8.6 to 0.10.2", but the manifest declared
0.9.3. The 0.8.6 is a transitive copy pulled in by third-party crates. The direct dependency moves 0.9.3 → 0.10.2, and 0.8.6 stays in the lockfile — as do olderbase64andschemarscopies, for the same reason. Not something this PR can consolidate.Verification
Run rather than inferred from a green lockfile — the lesson from #83, where a lockfile-only bump reached a real API change:
Resolved directly to
base640.23.1,rand0.10.2,schemars1.2.2,winreg0.56.0,ignore0.4.33.🤖 Generated with Claude Code
https://claude.ai/code/session_01Mu7jB5ysKe4DN5ovjVtX1t