Skip to content

Update rust compiler - #2007

Open
Neopallium wants to merge 9 commits into
developfrom
update_rust_compiler
Open

Neopallium wants to merge 9 commits into
developfrom
update_rust_compiler

Conversation

@Neopallium

@Neopallium Neopallium commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

changelog

other

  • Update to Rust nightly-2026-09-01.
  • Update all dependencies.
  • Use the dart-v0.1.0 branch for DART dependencies (this matches the version used before).
  • Fixed compile errors/warnings caused by using the newer Rust compiler.

@socket-security

socket-security Bot commented Sep 15, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: cargo openssl is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: integration/Cargo.lockcargo/polymesh-api-tester@0.11.0cargo/openssl@0.10.81

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/openssl@0.10.81. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo alloy-chains published 4 days ago

Location: Package overview

From: integration/Cargo.lockcargo/alloy@2.1.1cargo/alloy-chains@0.2.38

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/alloy-chains@0.2.38. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo alloy-core published 5 days ago

Location: Package overview

From: Cargo.lockcargo/alloy-core@1.7.3

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/alloy-core@1.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo alloy-dyn-abi published 5 days ago

Location: Package overview

From: Cargo.lockcargo/alloy@2.1.1cargo/alloy-core@1.7.3cargo/alloy-dyn-abi@1.7.3

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/alloy-dyn-abi@1.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo alloy-eip7928 published yesterday

Location: Package overview

From: integration/Cargo.lockcargo/alloy@2.1.1cargo/alloy-eip7928@0.4.10

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/alloy-eip7928@0.4.10. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo alloy-json-abi published 5 days ago

Location: Package overview

From: Cargo.lockcargo/alloy@2.1.1cargo/alloy-core@1.7.3cargo/alloy-json-abi@1.7.3

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/alloy-json-abi@1.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo alloy-primitives published 5 days ago

Location: Package overview

From: Cargo.lockcargo/alloy@2.1.1cargo/alloy-core@1.7.3cargo/alloy-primitives@1.7.3

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/alloy-primitives@1.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo alloy-sol-macro-expander published 5 days ago

Location: Package overview

From: Cargo.lockcargo/alloy@2.1.1cargo/alloy-core@1.7.3cargo/alloy-sol-macro-expander@1.7.3

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/alloy-sol-macro-expander@1.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo alloy-sol-macro-input published 5 days ago

Location: Package overview

From: Cargo.lockcargo/alloy@2.1.1cargo/alloy-core@1.7.3cargo/alloy-sol-macro-input@1.7.3

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/alloy-sol-macro-input@1.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo alloy-sol-macro published 5 days ago

Location: Package overview

From: Cargo.lockcargo/alloy@2.1.1cargo/alloy-core@1.7.3cargo/alloy-sol-macro@1.7.3

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/alloy-sol-macro@1.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo alloy-sol-type-parser published 5 days ago

Location: Package overview

From: Cargo.lockcargo/alloy@2.1.1cargo/alloy-core@1.7.3cargo/alloy-sol-type-parser@1.7.3

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/alloy-sol-type-parser@1.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo alloy-sol-types published 5 days ago

Location: Package overview

From: Cargo.lockcargo/alloy@2.1.1cargo/alloy-core@1.7.3cargo/alloy-sol-types@1.7.3

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/alloy-sol-types@1.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo camino published 14 hours ago

Location: Package overview

From: Cargo.lockcargo/camino@1.2.6

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/camino@1.2.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo cc published 2 days ago

Location: Package overview

From: Cargo.lockcargo/polkavm-derive@0.31.0cargo/polkavm@0.31.0cargo/sp-core@40.0.0cargo/wasmer@7.1.0cargo/wasmer-compiler-cranelift@7.1.0cargo/wasmer-compiler-llvm@7.1.0cargo/sp-runtime@46.0.0cargo/ark-serialize@0.6.0cargo/wasmtime@43.0.2cargo/polymesh-api@3.14.0cargo/polymesh-api-tester@0.11.0cargo/jsonrpsee@0.24.11cargo/chrono@0.4.45cargo/alloy@2.1.1cargo/alloy-core@1.7.3cargo/wasmtime@35.0.0cargo/schnorrkel@0.11.5cargo/sp-version@35.0.0cargo/cc@1.4.6

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/cc@1.4.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo clap_builder published 23 hours ago

Location: Package overview

From: Cargo.lockcargo/clap@4.6.7cargo/clap_builder@4.6.7

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/clap_builder@4.6.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo clap_derive published 23 hours ago

Location: Package overview

From: Cargo.lockcargo/clap@4.6.7cargo/clap_derive@4.6.7

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/clap_derive@4.6.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo clap_lex published 23 hours ago

Location: Package overview

From: Cargo.lockcargo/clap@4.6.7cargo/clap_lex@1.1.1

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/clap_lex@1.1.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo clap published 23 hours ago

Location: Package overview

From: Cargo.lockcargo/clap@4.6.7

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/clap@4.6.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo const-hex published 3 hours ago

Location: Package overview

From: Cargo.lockcargo/alloy@2.1.1cargo/alloy-core@1.7.3cargo/const-hex@1.19.2

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/const-hex@1.19.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo crc32fast published 3 days ago

Location: Package overview

From: Cargo.lockcargo/wasmer@7.1.0cargo/wasmer-compiler-cranelift@7.1.0cargo/wasmer-compiler-llvm@7.1.0cargo/wasmtime@43.0.2cargo/wasmtime@35.0.0cargo/crc32fast@1.5.2

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/crc32fast@1.5.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo cxx-build published 4 days ago

Location: Package overview

From: Cargo.lockcargo/cxx-build@1.0.202

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/cxx-build@1.0.202. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo cxx published 4 days ago

Location: Package overview

From: Cargo.lockcargo/cxx@1.0.202

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/cxx@1.0.202. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo cxxbridge-cmd published 4 days ago

Location: Package overview

From: Cargo.lockcargo/cxxbridge-cmd@1.0.202

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/cxxbridge-cmd@1.0.202. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo cxxbridge-flags published 4 days ago

Location: Package overview

From: Cargo.lockcargo/cxxbridge-flags@1.0.202

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/cxxbridge-flags@1.0.202. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo cxxbridge-macro published 4 days ago

Location: Package overview

From: Cargo.lockcargo/cxxbridge-macro@1.0.202

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/cxxbridge-macro@1.0.202. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Recently published: cargo jiff-core published 3 days ago

Location: Package overview

From: Cargo.lockcargo/ark-serialize@0.6.0cargo/env_logger@0.11.11cargo/alloy@2.1.1cargo/jiff-core@0.1.1

ℹ Read more on: This package | This alert | What are recently published artifacts?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should either be allowlisted to allow recently-published versions, or an older version should be used instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/jiff-core@0.1.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

See 16 more rows in the dashboard

View full report

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Critical unresolved DART source changes and moderate toolchain/Wasmer compatibility issues must be addressed.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Updates the repository to Rust nightly 2026-09-01 with compatibility changes across runtime, worker, RPC, and integration workspaces.

Changes:

  • Updates toolchain pins, CI images, and coverage commands.
  • Adds recursion limits and modernizes deprecated numeric APIs.
  • Updates dependency features, DART branches, Wasmer constraints, and lockfiles.
File summaries
File Summary
worker/protocol/dart-v1/src/lib.rs Adds recursion limit.
worker/Cargo.toml Adjusts Wasmer constraints. Moderate (1 vote): <=7.1.0 permits older releases; use exact or explicit bounds.
src/lib.rs Adds recursion limit.
scripts/coverage.sh Updates nightly toolchain commands.
rust-toolchain.toml Pins nightly 2026-09-01. Moderate (1 vote): the eth-rpc Docker builder remains on a stale compiler image.
pallets/validators/src/tests.rs Modernizes maximum-value APIs.
pallets/runtime/tests/src/transaction_payment_test.rs Modernizes maximum-value constants.
pallets/runtime/tests/src/storage.rs Modernizes priority constants.
pallets/runtime/tests/src/committee_test.rs Applies formatting compatibility fix.
pallets/runtime/tests/Cargo.toml Enables default test utility features.
pallets/runtime/testnet/src/runtime.rs Modernizes priority constant usage.
pallets/runtime/mainnet/src/runtime.rs Modernizes priority constant usage.
pallets/runtime/develop/src/runtime.rs Modernizes priority constant usage.
pallets/runtime/common/src/lib.rs Modernizes priority constant usage.
pallets/multisig/src/lib.rs Modernizes maximum-value constants.
pallets/confidential-assets/src/lib.rs Adds recursion limit.
node-rpc/Cargo.toml Enables default RPC dependency features.
metadata-tools/Cargo.lock Refreshes locked dependencies.
integration/tests/confidential_transfers.rs Adds recursion limit.
integration/tests/confidential_transfers_negative.rs Adds recursion limit.
integration/src/lib.rs Adds recursion limit.
integration/src/bin/tools.rs Adds recursion limit.
integration/rust-toolchain.toml Pins nightly 2026-09-01.
integration/Cargo.toml Switches DART sources to dart-v0.1.0. Critical (1 vote): this cryptographic source change requires reversion or separate explanation and validation.
Cargo.toml Switches runtime DART and cryptographic sources to dart-v0.1.0. Critical (2 votes): this protocol-affecting change requires reversion or separate documentation and validation.
.circleci/config.yml Updates CI compiler images.
Review details

Suppressed comments (3)

integration/Cargo.toml:44

  • The integration workspace is likewise switched from the main/polymesh-master dependency sources to dart-v0.1.0, which can change the cryptographic test client and generated proof behavior. This is not explained by the compiler-only PR description; please revert it or explicitly scope and validate the integration dependency migration.
polymesh-dart = { git = "https://github.com/PolymeshAssociation/polymesh-dart", branch = "dart-v0.1.0" }
polymesh-dart-bp = { git = "https://github.com/PolymeshAssociation/polymesh-dart", branch = "dart-v0.1.0" }
polymesh-dart-common = { git = "https://github.com/PolymeshAssociation/polymesh-dart", branch = "dart-v0.1.0" }

rust-toolchain.toml:2

  • This updates the repository toolchain, but .docker/eth-rpc/Dockerfile.local:1 still defaults to debian-nightly-2025-12-01. That Dockerfile copies this repository and runs a locked Cargo build, so local eth-rpc image builds now start from a stale compiler image (or require rustup to fetch the new one); update that builder image in the same change or derive it from this pin.
channel = "nightly-2026-09-01"

worker/Cargo.toml:31

  • <=7.1.0 permits Cargo to select any older Wasmer release, not just the 7.1.0 release currently recorded in the lockfile. If the lockfile is regenerated after a release is yanked or in another workspace, an older major/minor API may be selected and the backend can stop compiling; use an exact =7.1.0 requirement (or an explicit lower and upper bound) for the tested compatibility range.
wasmer = { version = "<=7.1.0", optional = true }
wasmer-compiler-cranelift = { version = "<=7.1.0", optional = true }
wasmer-compiler-llvm = { version = "<=7.1.0", optional = true }
  • Files reviewed: 25/28 changed files
  • Comments generated: 2
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread Cargo.toml
Comment thread integration/Cargo.toml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants