Skip to content

chore(deps): bump libp2p-* and resolve RUSTSEC-2026-0002#6454

Merged
hanabi1224 merged 1 commit into
mainfrom
hm/bump-libp2p
Jan 21, 2026
Merged

chore(deps): bump libp2p-* and resolve RUSTSEC-2026-0002#6454
hanabi1224 merged 1 commit into
mainfrom
hm/bump-libp2p

Conversation

@hanabi1224

@hanabi1224 hanabi1224 commented Jan 21, 2026

Copy link
Copy Markdown
Contributor

Summary of changes

Changes introduced in this pull request:

Reference issue to close (if applicable)

Closes

Other information and links

Change checklist

  • I have performed a self-review of my own code,
  • I have made corresponding changes to the documentation. All new code adheres to the team's documentation standards,
  • I have added tests that prove my fix is effective or that my feature works (if possible),
  • I have made sure the CHANGELOG is up-to-date. All user-facing changes should be reflected in this document.

Summary by CodeRabbit

  • Chores
    • Removed an exemption from the security advisory checklist, enabling enforcement of an additional security advisory that was previously ignored.

✏️ Tip: You can customize this high-level summary in your review settings.

@coderabbitai

coderabbitai Bot commented Jan 21, 2026

Copy link
Copy Markdown
Contributor

Walkthrough

This PR removes a single advisory ignore entry ("RUSTSEC-2026-0002") from the deny.toml configuration file. The previously ignored advisory will now be actively scanned and considered by the dependency vulnerability checker.

Changes

Cohort / File(s) Summary
Configuration updates
deny.toml
Removed RUSTSEC-2026-0002 from the [advisories] ignore list (1 line deleted)

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

Suggested labels

dependencies, rust

Suggested reviewers

  • sudo-shashank
  • LesnyRumcajs
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title directly matches the primary change: bumping libp2p dependencies and resolving the RUSTSEC-2026-0002 security advisory, which is confirmed by removing the ignore entry from deny.toml.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

Comment thread Cargo.lock
]

[[package]]
name = "lru"

@hanabi1224 hanabi1224 Jan 21, 2026

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lru is gone.

@hanabi1224 hanabi1224 marked this pull request as ready for review January 21, 2026 08:49
@hanabi1224 hanabi1224 requested a review from a team as a code owner January 21, 2026 08:49
@hanabi1224 hanabi1224 requested review from LesnyRumcajs and akaladarshi and removed request for a team January 21, 2026 08:49

@LesnyRumcajs LesnyRumcajs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

libp2p bump is always welcome

@hanabi1224 hanabi1224 enabled auto-merge January 21, 2026 09:11
@hanabi1224 hanabi1224 added this pull request to the merge queue Jan 21, 2026
Merged via the queue into main with commit 5c13b17 Jan 21, 2026
47 checks passed
@hanabi1224 hanabi1224 deleted the hm/bump-libp2p branch January 21, 2026 10:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants