docs(deps): triage report for held bincode/rand/hkdf bumps#672
Merged
Conversation
…dle landed Record why #559 (bincode 1->3), #558 (rand 0.8->0.10), and #555 (hkdf 0.12->0.13) are held rather than merged: bincode is the canonical signed+hashed event encoding (format break invalidates the DAG), hkdf 0.13 needs pre-release sha2 0.11, and rand 0.10 collides with rand_core 0.6 pinned by x25519-dalek 2 + chacha20poly1305 0.10. Also flip the relay-upgrade-bundle plan to [landed] (merged as #664). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Records why the three open Dependabot major bumps are held, not merged, after evaluating each against current
main(all three branches were 200–250 commits stale, so their CI red was partly noise):event.rs:600-602: SHA-256'd intoEventHash+ Ed25519-signed) and the wire/persistence format. 2/3 changes the encoding → breaks everyEventHash/signature/stored blob. Format-stability boundary, not a bump.sha20.11 (digest-0.11 gen); only0.11.0-rc.5exists. Pre-release crypto rejected.willow-cryptois pinned torand_core0.6 byx25519-dalek2 +chacha20poly13050.10.Full report + fix-paths:
docs/reports/2026-06-03-dependency-bump-triage.md. Also flips the relay-upgrade-bundle plan to[landed](merged as #664).Docs-only; no code change.
🤖 Generated with Claude Code