Repository navigation
chore(deps): bump jsonwebtoken from 9.3.1 to 10.3.0 in the cargo group across 1 directory - #1
Merged
Merged
Conversation
Bumps the cargo group with 1 update in the / directory: [jsonwebtoken](https://github.com/Keats/jsonwebtoken). Updates `jsonwebtoken` from 9.3.1 to 10.3.0 - [Changelog](https://github.com/Keats/jsonwebtoken/blob/master/CHANGELOG.md) - [Commits](Keats/jsonwebtoken@v9.3.1...v10.3.0) --- updated-dependencies: - dependency-name: jsonwebtoken dependency-version: 10.3.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/cargo/cargo-faef625f8c
branch
from
September 9, 2026 10:15
696c9b9 to
09a6276
Compare
vheins
self-requested a review
September 10, 2026 12:35
- Domain: dependency bump jsonwebtoken 9.3.1 -> 10.4.0 (rustasea-auth JWT guard) - Findings: 1 CRITICAL, 0 HIGH, 1 MEDIUM, 0 LOW - Blocker: jsonwebtoken 10 requires an explicit crypto backend; no rust_crypto/aws_lc_rs feature -> JWT encode/decode panic at runtime
vheins
requested changes
Sep 10, 2026
vheins
left a comment
Collaborator
There was a problem hiding this comment.
@dependabot[bot] 1 blocker + 1 compatibility violation, details in the inline comments.
- CRITICAL —
jsonwebtoken10 needs an explicit crypto backend; withoutrust_crypto/aws_lc_rsevery JWT sign/verify panics at runtime. Fix: addfeatures = ["rust_crypto"]on Cargo.toml:25. - MEDIUM —
jsonwebtoken10.x is edition 2024 (MSRV 1.85; 10.4.0 requires 1.88), violating documented constraint C-01 (Rust 1.80+, edition 2021). Fix: raise MSRV in[workspace.package], update C-01/architecture docs, add ADR.
- Add sqlx 0.8 (postgres/mysql/sqlite) + config 0.14 workspace deps - Introduce DbPool/DbRow/Database facade, DatabaseConfig/PoolConfig - Bind pool into foundation container (DATABASE_BINDING); load config/database.toml - Typed OrmError mapping incl. Connection (Io/Tls) and Value::Unsupported for non-null unmapped cells - compile_error! guard when no driver feature enabled - Tests: sqlite round-trip, typed DSN errors, container binding
- Replace stub_handler wiring with Handler/ActionFactory/BoundAction dispatch
- into_axum_router resolves explicit action -> controller registry -> stub
- Consume #[route] metadata at registration (macros: const -> pub const)
- Normalize HTTP methods; domain-aware resolution; Laravel {param} -> :param at axum boundary
- Tests: path/query/json extraction, 404/405, domain precedence, resource actions
…parity map - Add docs/milestones.md: evidence-backed done/partial/missing per M0–M6 + P0 progress (GAP-001/002 done, GAP-003 backlog) - Add docs/laravel-parity.md: Laravel 13.x namespace + interface/trait adoption mapping (5 api.laravel.com sources) - README: link both docs; correct stale status (object_store wired, HttpClient::throw implemented, M4 driver state)
…rgo-faef625f8c # Conflicts: # Cargo.lock # crates/rustasea-orm/Cargo.toml # crates/rustasea-orm/src/builder/ext.rs # crates/rustasea-orm/src/error.rs # crates/rustasea-orm/src/lib.rs
Collaborator
|
Resolved both review findings and merged. Fix applied (
Also in this branch: Verification: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the cargo group with 1 update in the / directory: jsonwebtoken.
Updates
jsonwebtokenfrom 9.3.1 to 10.3.0Changelog
Sourced from jsonwebtoken's changelog.
Commits
abbc307Fix type confusione99740dfix: bump minimal version requirements (#481)50d15e0Use try_sign to avoid panics (#479)245858fBump some dep122c2edBump action number in CI72e0c7fExpose cryptography backends via CryptoProvider (#452)53a3fc2Do not fail for clippy3226cfcPrepare for releasedfe58f9Remove unnecessary Clone bounds from decode functions (#458)9b3e19cFix function names in README (#457)