Skip to content

Refresh compatible runtime and release dependencies - #24

Merged
philippgerard merged 1 commit into
mainfrom
chore/dependency-refresh-2026-09-29
Sep 29, 2026
Merged

philippgerard merged 1 commit into
mainfrom
chore/dependency-refresh-2026-09-29

Conversation

@philippgerard

Copy link
Copy Markdown
Owner

Changes

  • Refresh all three Cargo lockfiles within existing manifest constraints; preserve the patched genai provider contracts.
  • Update FastEmbed 5.13.4 → 5.17.4 and ort 2.0.0-rc.12 → rc.13, plus compatible HTTP/TLS, compression, Unicode, and Arrow dependencies.
  • Refresh immutable GitHub Action pins and mold 2.41.0 → 2.42.1.
  • Document the refresh in the shipped changelog. Major Rust migrations and browser 9 are intentionally excluded from this maintenance release.

Verification

  • Baseline and updated cargo-audit: no known vulnerabilities, unsoundness, or yanked crates in any lockfile. Existing unmaintained upstream warnings remain visible (paste, serial; migrator also bincode and encoding).
  • cargo fmt --check; shell syntax; release-security, binary-attestation, and 77 shell-policy regressions passed.
  • cargo test --locked: 560 passed; focused memory suite: 39 passed.
  • Vendored genai locked library suite: 154 passed. Migrator locked suite: 3 passed.
  • Locked release binary built on macOS ARM64 using a fresh target directory (the old local cache contained Rust 1.97 artifacts).
  • Real isolated release-binary smoke: memory initialization, ONNX 768-dimensional embedding persisted and searched, API health 200, unauthorized request 401, authenticated request 200. No production state or provider credentials used.
  • Production health before rollout: HTTP 200 / ready. Committed runtime npm lock audit: zero vulnerabilities.

Rollout

After hosted verification and three-platform builds pass, merge and publish v0.28.0-pg11 through the attested release workflow. Update the separate lethe-stack release pin and ARM64 SHA-256, deploy via Dokploy, and verify production health and binary identity. Existing local user edits in both checkouts are excluded.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T12:30:37.391978Z b710695 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@philippgerard
philippgerard merged commit 3b53bd8 into main Sep 29, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant