Skip to content

chore(deps): take four pcai_core majors and the grouped ignore patch - #105

Merged
David-Martel merged 1 commit into
mainfrom
chore/deps-pcai-core-majors-20260908
Sep 9, 2026
Merged

David-Martel merged 1 commit into
mainfrom
chore/deps-pcai-core-majors-20260908

Conversation

@David-Martel

Copy link
Copy Markdown
Owner

Supersedes #99, #100, #101, #102 and #103 — five PRs against one workspace, resolved against a single lockfile and gated once rather than five times.

Crate From To PR
ignore 0.4.32 0.4.33 #99 (cargo-pcai-core group)
base64 0.22 0.23 #100
rand 0.9.3 0.10.2 #101
schemars 0.8.22 1.2.2 #102
winreg 0.55 0.56 #103

Every one of these is a breaking-version bump for Cargo purposes, which is why dependabot raised them individually rather than folding them into the minor/patch group. None turned out to need a code change — the workspace compiles, lints and tests clean as-is.

A note on #101's title

It says "rand from 0.8.6 to 0.10.2", but the manifest declared 0.9.3. The 0.8.6 is a transitive copy pulled in by third-party crates. The direct dependency moves 0.9.3 → 0.10.2, and 0.8.6 stays in the lockfile — as do older base64 and schemars copies, for the same reason. Not something this PR can consolidate.

Verification

Run rather than inferred from a green lockfile — the lesson from #83, where a lockfile-only bump reached a real API change:

cargo check   --workspace --all-targets                  exit 0
cargo clippy  --workspace --all-targets -- -D warnings   exit 0
cargo test    --workspace --features server,ffi --lib    exit 0
                                                         133 + 96 + 57 + 96 passed, 0 failed

Resolved directly to base64 0.23.1, rand 0.10.2, schemars 1.2.2, winreg 0.56.0, ignore 0.4.33.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Mu7jB5ysKe4DN5ovjVtX1t

Supersedes #99, #100, #101, #102 and #103 -- five PRs against one workspace,
resolved against a single lockfile and gated once rather than five times.

    ignore     0.4.32  -> 0.4.33    (#99, cargo-pcai-core group)
    base64     0.22    -> 0.23      (#100)
    rand       0.9.3   -> 0.10.2    (#101)
    schemars   0.8.22  -> 1.2.2     (#102)
    winreg     0.55    -> 0.56      (#103)

Every one of these is a breaking-version bump for Cargo purposes, which is why
dependabot raised them individually rather than folding them into the
minor/patch group. None of them turned out to need a code change: the workspace
compiles, lints and tests clean as-is.

Note #101's title says "rand from 0.8.6 to 0.10.2", but the manifest declared
0.9.3 -- 0.8.6 is a transitive copy pulled in by third-party crates. The direct
dependency moves 0.9.3 -> 0.10.2 and 0.8.6 remains in the lockfile, along with
older base64 and schemars copies, for the same reason. That is expected and not
something this PR can consolidate.

Verified, rather than merged on the strength of a green lockfile:

    cargo check   --workspace --all-targets                 exit 0
    cargo clippy  --workspace --all-targets -- -D warnings  exit 0
    cargo test    --workspace --features server,ffi --lib   exit 0
                                                            133 + 96 + 57 + 96 passed, 0 failed

Resolved directly to base64 0.23.1, rand 0.10.2, schemars 1.2.2, winreg 0.56.0,
ignore 0.4.33.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Mu7jB5ysKe4DN5ovjVtX1t
Copilot AI lite review requested due to automatic review settings September 8, 2026 16:36
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-08T16:42:15.574426Z 74b2b50 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The changes are constrained to dependency version/lockfile updates and the workspace MSRV is explicitly set to 1.85, aligning with the updated dependency requirements.

Pull request overview

This PR consolidates several Dependabot major (breaking-for-Cargo) dependency bumps for the Native/pcai_core Rust workspace into a single change, updating the manifests/lockfile without requiring code changes.

Changes:

  • Bump direct workspace dependencies: base64 (0.22 → 0.23), rand (0.9.3 → 0.10.2), schemars (0.8.22 → 1.2.2), winreg (0.55 → 0.56).
  • Refresh Cargo.lock to capture the resolved versions (including the ignore 0.4.32 → 0.4.33 patch-level resolution and updated transitive graph).
File summaries
File Description
Native/pcai_core/Cargo.toml Updates the direct dependency version requirements for the workspace.
Native/pcai_core/Cargo.lock Updates the resolved dependency graph to match the new requirements.
Review details
  • Files reviewed: 1/2 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@David-Martel
David-Martel merged commit 4a9e860 into main Sep 9, 2026
12 checks passed
@David-Martel
David-Martel deleted the chore/deps-pcai-core-majors-20260908 branch September 9, 2026 16:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants