Skip to content

chore(deps): consolidate dependency bumps to latest stable releases (closes #15, #16) - #17

Merged
doublegate merged 3 commits into
mainfrom
chore/consolidated-dependency-bumps
Oct 10, 2026
Merged

doublegate merged 3 commits into
mainfrom
chore/consolidated-dependency-bumps

Conversation

@doublegate

Copy link
Copy Markdown
Owner

Summary

Consolidates 2 open dependabot dependency update PRs (#15, #16) into a single unified pull request.

Supersedes and closes #15, #16.

Dependency Migration

Package Ecosystem Previous Updated Type
sqlx Cargo 0.8 0.9 Cargo Dependency
sysinfo Cargo 0.38 0.39 Cargo Dependency

API Adaptations & Breaking Changes

  • Adapted sqlx::query to use sqlx::AssertSqlSafe for dynamically constructed SQLite batch queries.
  • Synchronized Cargo.lock and fuzz/Cargo.lock.
  • Verified workspace compilation under stable toolchain.

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 6571db95-a4bf-4569-81e4-5ff9456a3487

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Both upgraded dependencies exceed the enforced Rust 1.88 MSRV and will fail the dedicated MSRV build.

2 open findings
What changed in this PR

Consolidates SQLx and sysinfo upgrades, updates lockfiles, and adapts dynamic SQLite queries.

Changes:

  • Upgrades SQLx to 0.9 and sysinfo to 0.39.
  • Uses AssertSqlSafe for generated batch inserts.
  • Refreshes dependency locks and archives obsolete guidance.
File Description
Cargo.toml Upgrades sysinfo.
crates/​prtip-scanner/​Cargo.toml Upgrades SQLx.
crates/​prtip-scanner/​src/​storage.rs Adapts dynamic SQL construction.
Cargo.lock Updates workspace resolutions.
fuzz/​Cargo.lock Updates fuzzing resolutions.
docs/​history/​AGENTS-archive.md Archives historical project status.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread Cargo.toml
Comment thread crates/prtip-scanner/Cargo.toml
@socket-security

socket-security Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedsysinfo@​0.38.4 ⏵ 0.39.691100100100100
Updatedsqlx@​0.8.6 ⏵ 0.9.096 +1100100100100

View full report

@doublegate
doublegate merged commit f5631a0 into main Oct 10, 2026
16 checks passed
@doublegate
doublegate deleted the chore/consolidated-dependency-bumps branch October 10, 2026 04:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants