deps: consolidate Dependabot updates (cargo + github-actions) - #10
Conversation
Supersedes #8 and #9. cargo: the full #9 group (green as filed). github-actions: - actions/checkout v4 -> v7 - actions/upload-artifact v4 -> v7 - actions/download-artifact v4 -> v8 - softprops/action-gh-release v2 -> v3 Drops #8's dtolnay/rust-toolchain 1.82.0 -> 1.100.0 hunk, which is what made #8 fail: Rust 1.100.0 does not exist. That pin is the MSRV from Cargo.toml (rust-version = 1.82), not an action release, so Dependabot must not touch it — now ignored.
|
Warning Review limit reachedYou’ve reached a temporary PR review limit under our Fair Usage Limits Policy. Next review available in: 41 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (8)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Newly published advisory on the same unfixable chain as RUSTSEC-2026-0192, already ignored just above it: rustybuzz is pinned by usvg 0.47, so there is nothing to upgrade to. Present on main too (rustybuzz 0.20.1 is identical there) — cargo-deny fetches the advisory DB live, so main would fail this today as well.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b55ec86168
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Consolidates both open Dependabot PRs into one, dropping the one hunk that was broken.
Supersedes #8 and #9.
cargo
The full #9 group, which was green as filed.
github-actions
actions/checkoutv4→v7,actions/upload-artifactv4→v7,actions/download-artifactv4→v8,softprops/action-gh-releasev2→v3.What was dropped, and why
#8 also bumped
dtolnay/rust-toolchain@1.82.0→@1.100.0, which is why its MSRV job failed:Rust 1.100.0 does not exist. That pin is not an action release — it is the MSRV, mirroring
rust-version = "1.82"inCargo.toml, and holding that floor is the entire purpose of theMSRV job. Dependabot reads it as a version tag and bumps it. Added an
ignorefordtolnay/rust-toolchainso it stops.Worth knowing:
MSRVis not in this repo's required-status-check list (ubuntu-latest,macos-latest,windows-latestare), so #8 was technically mergeable while broken.Verification
cargo test --workspace --all-featurespasses locally (22 tests).