Skip to content

chore(deps): bump rustls-webpki from 0.103.10 to 0.103.12 in /tools/lumina-latency-monitor#7151

Merged
rootulp merged 1 commit intomainfrom
worktree-misty-herding-sutherland
Apr 21, 2026
Merged

chore(deps): bump rustls-webpki from 0.103.10 to 0.103.12 in /tools/lumina-latency-monitor#7151
rootulp merged 1 commit intomainfrom
worktree-misty-herding-sutherland

Conversation

@rootulp
Copy link
Copy Markdown
Collaborator

@rootulp rootulp commented Apr 20, 2026

Summary

  • Bumps rustls-webpki 0.103.10 → 0.103.12 in tools/lumina-latency-monitor/Cargo.lock (transitive dep via celestia-grpc tls-ring).
  • Resolves two open Dependabot alerts:
  • Cargo.lock-only change; no Cargo.toml edits needed.
  • Includes a benign Cargo resolver re-association for data-encoding-macro-internal's syn proc-macro dep (2.0.111 → 1.0.109); the crate's version and checksum are unchanged and both syn majors remain in the tree.

Closes PROTOCO-1549

Test plan

  • cargo fmt --all -- --check passes locally
  • cargo test --workspace passes locally
  • cargo build --release passes locally
  • CI job rust-lumina-latency-monitor green on PR (clippy runs against newer stable in CI; local Homebrew clippy 1.88 is stale)

Open in Devin Review

…umina-latency-monitor

Resolves Dependabot alerts GHSA-xgp8-3hg3-c2mh and GHSA-965h-392x-2mh5
(both low severity, both addressed in rustls-webpki 0.103.12).

rustls-webpki is a transitive dependency via celestia-grpc's tls-ring
feature. This is a Cargo.lock-only change. The commit also includes a
benign Cargo resolver deduplication for data-encoding-macro-internal's
syn proc-macro dependency (syn 2.0.111 -> syn 1.0.109); the
data-encoding-macro-internal package version and checksum are unchanged.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@rootulp rootulp added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Apr 20, 2026
@rootulp rootulp requested a review from a team as a code owner April 20, 2026 22:48
@rootulp rootulp added the dependencies Pull requests that update a dependency file label Apr 20, 2026
@rootulp rootulp removed the request for review from a team April 20, 2026 22:48
@rootulp rootulp added the rust Pull requests that update rust code label Apr 20, 2026
@rootulp rootulp requested a review from ninabarbakadze April 20, 2026 22:48
@rootulp rootulp self-assigned this Apr 20, 2026
Copy link
Copy Markdown

@claude claude Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Code Review

This repository is configured for manual code reviews. Comment @claude review to trigger a review and subscribe this PR to future pushes, or @claude review once for a one-time review.

Tip: disable this comment in your organization's Code Review settings.

@rootulp rootulp enabled auto-merge April 20, 2026 22:48
Copy link
Copy Markdown
Contributor

@devin-ai-integration devin-ai-integration Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no potential bugs to report.

View in Devin Review to see 1 additional finding.

Open in Devin Review

@rootulp rootulp added this pull request to the merge queue Apr 21, 2026
Merged via the queue into main with commit 1e8c960 Apr 21, 2026
34 checks passed
@rootulp rootulp deleted the worktree-misty-herding-sutherland branch April 21, 2026 08:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants