Skip to content

chore(deps): bump lz4_flex and rustls-webpki (partial #26)#40

Merged
saagpatel merged 1 commit into
masterfrom
codex/chore/deps-cargo-patches
Apr 21, 2026
Merged

chore(deps): bump lz4_flex and rustls-webpki (partial #26)#40
saagpatel merged 1 commit into
masterfrom
codex/chore/deps-cargo-patches

Conversation

@saagpatel
Copy link
Copy Markdown
Owner

What

Two patch-level bumps in src-tauri/Cargo.lock:

  • lz4_flex 0.11.5 → 0.11.6
  • rustls-webpki 0.103.9 → 0.103.13

Why

Partial replacement for #26 — the Dependabot cargo-group PR bundled three updates:

  • rand 0.8.5 → 0.9.2 — major API break, carved off to its own follow-up PR (requires thread_rng()rng() rename in src-tauri/src/security.rs)
  • lz4_flex patch ← this PR
  • rustls-webpki patch ← this PR

Splitting lets the two low-risk patches land immediately while the rand migration gets isolated review.

Wave 4 (remainder, pre-Wave 5) of the audit remediation plan.

How

cd src-tauri && cargo update -p lz4_flex@0.11.5 -p rustls-webpki. Targeted update; no other crate moves. 10-line Cargo.lock diff, no code changes.

Testing

  • Commands run: cd src-tauri && cargo check
  • Results: clean build (38s, no warnings from the bump)

Performance impact

  • Bundle delta: N/A (Rust lockfile change)
  • Build time delta: negligible
  • Lighthouse delta: none
  • API latency delta: none
  • DB query delta: none

Risk / Notes

Screenshots (UI only)

  • N/A

Lockfile rationale (if lockfile changed)

  • src-tauri/Cargo.lock touched: only lz4_flex and rustls-webpki version lines changed, everything else identical.

🤖 Generated with Claude Code

Partial replacement for #26 — Dependabot cargo-group PR blocked by
branch-name governance. The Dependabot PR bundled three updates:

- rand 0.8.5 → 0.9.2 (MAJOR API break — carved off to its own PR)
- lz4_flex 0.11.5 → 0.11.6 (patch — this PR)
- rustls-webpki 0.103.9 → 0.103.13 (patch — this PR)

Splitting the group keeps the rand migration reviewable in isolation
and lets these two low-risk patch bumps land immediately.

`cargo update -p lz4_flex@0.11.5 -p rustls-webpki` pinpoints the two
versions and leaves the rest of the lockfile untouched. Ten lines
changed in Cargo.lock, no code changes.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@saagpatel saagpatel merged commit ce063dd into master Apr 21, 2026
23 of 26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants