Skip to content

v1.8.1 — dependency maintenance

Choose a tag to compare

@Rayrsn Rayrsn released this 26 Sep 08:15
· 33 commits to main since this release

Dependency maintenance release — no behavior changes, no new flags.

Dependency updates

  • rcgen 0.13 → 0.14 — the only one that required code. rcgen 0.14 made the
    signing identity explicit: CertificateParams::signed_by now takes
    (public_key, &Issuer) instead of (public_key, &ca_cert, &ca_key), with the
    issuer's distinguished name, key identifier, usages, and signing key
    travelling together. The mutual-TLS client PKI was migrated to the new model,
    building the Issuer directly instead of round-tripping the self-signed CA
    through PEM. The wire format and the generated certificates are unchanged, and
    the mTLS e2e test (client certificate required and verified) passes
    unmodified.
  • webpki-roots 0.26 → 1.0 — this also collapsed a duplicate that the
    lockfile had been carrying, so the matching deny.toml skip entry is gone:
    the dependency policy is green with one fewer exemption.
  • zstd 0.13 → 0.14, criterion 0.5 → 0.8, clap 4.6.6 → 4.6.7.
  • actions/checkout v4 → v7 and actions/upload-artifact v4 → v7, each pinned
    SHA verified against its tag before merging.

Fixed

  • A concurrency test no longer relies on a 100 ms sleep. The
    project-locking test waited a fixed interval for the first client to take the
    workspace lock; on Windows that was occasionally not enough, and the test
    failed reading Need where it expected Queued. It now polls the running
    agent's actual lock — the manager is Clone over an Arc, so the test holds
    a handle to it — leaving no timing assumption behind.

Dependabot is now scoped to what CI actually exercises

Three action bumps are ignored, each with its reason recorded:

  • dtolnay/rust-toolchain — pinned three times for three different
    toolchains (stable, the 1.88 MSRV job, nightly). Dependabot models it as one
    requirement, so an update collapses all three pins to the stable commit
    while the version comments keep claiming 1.88.0/nightly. Merging that
    would have compiled the MSRV job with current stable, leaving the gate green
    and meaningless.
  • codecov/codecov-action — there is no CODECOV_TOKEN, so uploads are
    tokenless, and v5+ changed that path. Because the job sets
    fail_ci_if_error: false, an action that quietly stopped uploading would
    leave CI green and the coverage badge frozen. Revisit once a token exists.
  • softprops/action-gh-release — runs only in the Release workflow, which
    fires on a tag, so no PR check ever exercises it. It will be validated
    during a real release, where a failure is loud.

Upgrading is a drop-in replacement: no flags, wire format, or configuration
changed in this release.