Repository navigation
build(deps): bump dig-rewards-coin to 0.11 (dig_ecosystem#3450) - #634
Conversation
Also raises the floors of the caret-compatible dig-* deps to their latest patch. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…tem#3450) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
MichaelTaylor3d
left a comment
There was a problem hiding this comment.
Verdict: PASS at a1a94a1 (independent review; no local build, CI green on this head).
- Lock: dig-rewards-coin 0.11.0 only (single entry, checksum changed); dig-mirror-collateral 0.3.1, dig-mirror-coin 0.9.1, dig-chainsource-interface 0.3.3, dig-cert 0.1.3, dig-logging 0.2.2, dig-urn-resolver 0.5.4, dig-constants 0.13.1 all resolve. chia-protocol entries unchanged (0.26.0, 0.36.1): no new major line. Only other lock churn is windows-sys/socket2 dependency-edge reshuffles, no new packages.
- Comments: chainsource "caret-matched" still true (single 0.3.3). Non-blocking drift: Cargo.toml dig-constants comment says "lockstep with dig-node-core's pin ... 0.11.2", but core pins "0.13.0" (crates/dig-node-core/Cargo.toml:390) vs service "0.13.1". The comment was already stale before this PR (0.11.2); both resolve to the one 0.13.1 lock entry, so no behavioural drift. Optional follow-up: refresh the comment or raise core to 0.13.1.
- MOOT ruling holds: withdraw_committed_incentives appears only in the absence guard test (chain_port.rs:570-580) and comments; reader_error_to_port_error has a wildcard
other => ChainPortError::Other(...)arm. - PR body accurate against the diff.
No blocking findings; no inline threads opened (0 open).
|
loop-security verdict: PASS at head a1a94a1 (dig-node#634, base develop f1e9f80).
Defence-in-depth, not gating: the lock also re-points ~20 dependency edges (windows-sys 0.61.2 -> 0.59/0.60/0.48; socket2 0.6.5 -> 0.5.10 in quinn/quinn-udp). All target versions already existed in the lock and are within each parent's declared range. They are Windows-only or socket-level, with no new package. Looks like resolver churn from the lock refresh. Worth knowing, no action. Not covered: no local build, no cargo-audit run, no source diff of the transitive dig-* floor bumps beyond the lock. |
* build(deps): bump dig-rewards-coin to 0.11 (dig_ecosystem#3450) (#634) * build(deps): bump dig-rewards-coin to 0.11 (dig_ecosystem#3450) Also raises the floors of the caret-compatible dig-* deps to their latest patch. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * build(deps): refresh Cargo.lock for dig-rewards-coin 0.11 (dig_ecosystem#3450) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * chore(release): v0.262.1 -- dig-rewards-coin 0.11 Refs DIG-Network/dig_ecosystem#3450 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
Refs DIG-Network/dig_ecosystem#3450
Bumps
dig-rewards-coin0.10 -> 0.11 and refreshes the caret-compatible dig-* floors (§2.4b):dig-mirror-collateral0.3.1,dig-mirror-coin0.9.1,dig-chainsource-interface0.3.3 (normal + dev),dig-cert0.1.3,dig-logging0.2.2,dig-urn-resolver0.5.4,dig-constants0.13.1. Cargo.lock refreshed. No version bump (lane PR intodevelop, §2.4).No source change. dig-rewards-coin 0.11's new
CommitmentEpochStartedvariant is returned only byclawback::withdraw_committed_incentives, which dig-node never calls (guarded by the existing absence test inrewards/chain_port.rs); the only match on the error enum (reader_error_to_port_error) has a wildcard arm. The not-recoverable state stays covered bytests/rewards_chain_port_a3.rs(an_epoch_started_commitment_is_reported_as_none_not_zero), green on this head. Mapping criterion ruled MOOT on the ticket.🤖 Generated with Claude Code