Skip to content

Bump the rustcrypto group across 1 directory with 4 updates - #290

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/rustcrypto-b19923ba84
Closed

Bump the rustcrypto group across 1 directory with 4 updates#290
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/rustcrypto-b19923ba84

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 2, 2026

Copy link
Copy Markdown
Contributor

Bumps the rustcrypto group with 4 updates in the / directory: argon2, sha2, sha1 and hmac.

Updates argon2 from 0.5.3 to 0.6.0

Commits
  • b1e0ad6 argon2 v0.6.0 (#931)
  • c0d2aca argon2: bump blake2 to v0.11 (#929)
  • d9c628b Cargo.lock: bump dependencies (#930)
  • 0b31c1c Cargo.toml: use password-hash crate release (#920)
  • 420cbc9 build(deps): bump rust-lang/crates-io-auth-action from 1.0.4 to 1.0.5 (#912)
  • 3a88540 build(deps): bump actions/checkout from 6 to 7 (#913)
  • 90b974f build(deps): bump the all-deps group with 5 updates (#914)
  • 82c688f build(deps): bump the all-deps group across 1 directory with 18 updates (#911)
  • b2cef17 build(deps): bump the all-deps group with 6 updates (#902)
  • 2c16e5a build(deps): bump the all-deps group with 7 updates (#901)
  • Additional commits viewable in compare view

Updates sha2 from 0.10.9 to 0.11.0

Commits

Updates sha1 from 0.10.7 to 0.11.0

Commits

Updates hmac from 0.12.1 to 0.13.0

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Sep 2, 2026
@hanthor-hive-agent

Copy link
Copy Markdown
Contributor

🛑 Fix loop escalated — human attention needed

This PR has failed CI on 1 distinct fix attempts (new commits, still red). The hive has stopped dispatching further automated fixes for it.

Failing checks: Rust quality gate, complement-readiness, complement-suite, protocol-fixtures, release-regression-gates

Raw failure evidence (from check-run annotations):

Rust quality gate: Process completed with exit code 101.

Remove the needs-human label after addressing the root cause to return the PR to the automated fix lane.

@hanthor-hive-agent

Copy link
Copy Markdown
Contributor

🛑 Fix loop escalated — human attention needed

This PR has failed CI on 1 distinct fix attempts (new commits, still red). The hive has stopped dispatching further automated fixes for it.

Failing checks: Rust quality gate, complement-readiness, complement-suite, protocol-fixtures, release-regression-gates

Raw failure evidence (from check-run annotations):

Rust quality gate: Process completed with exit code 101.

Remove the needs-human label after addressing the root cause to return the PR to the automated fix lane.

@dependabot dependabot Bot changed the title build(deps): bump the rustcrypto group across 1 directory with 4 updates Bump the rustcrypto group across 1 directory with 4 updates Sep 2, 2026
@dependabot
dependabot Bot force-pushed the dependabot/cargo/rustcrypto-b19923ba84 branch from 6189e5e to 4d73265 Compare September 2, 2026 18:17
@hanthor-hive-agent

Copy link
Copy Markdown
Contributor

🛑 Fix loop escalated — human attention needed

This PR has failed CI on 1 distinct fix attempts (new commits, still red). The hive has stopped dispatching further automated fixes for it.

Failing checks: Rust quality gate, complement-readiness, complement-suite, element-web-e2e, protocol-fixtures, release-regression-gates

Raw failure evidence (from check-run annotations):

Rust quality gate: Process completed with exit code 101.

Remove the needs-human label after addressing the root cause to return the PR to the automated fix lane.

@dependabot
dependabot Bot force-pushed the dependabot/cargo/rustcrypto-b19923ba84 branch from 4d73265 to 67e9190 Compare September 3, 2026 06:24
@hanthor-hive-agent

Copy link
Copy Markdown
Contributor

🛑 Fix loop escalated — human attention needed

This PR has failed CI on 1 distinct fix attempts (new commits, still red). The hive has stopped dispatching further automated fixes for it.

Failing checks: Rust quality gate, complement-readiness, complement-suite, element-web-e2e, protocol-fixtures, release-regression-gates

Raw failure evidence (from check-run annotations):

release-regression-gates: Process completed with exit code 101.

Remove the needs-human label after addressing the root cause to return the PR to the automated fix lane.

5 similar comments
@hanthor-hive-agent

Copy link
Copy Markdown
Contributor

🛑 Fix loop escalated — human attention needed

This PR has failed CI on 1 distinct fix attempts (new commits, still red). The hive has stopped dispatching further automated fixes for it.

Failing checks: Rust quality gate, complement-readiness, complement-suite, element-web-e2e, protocol-fixtures, release-regression-gates

Raw failure evidence (from check-run annotations):

release-regression-gates: Process completed with exit code 101.

Remove the needs-human label after addressing the root cause to return the PR to the automated fix lane.

@hanthor-hive-agent

Copy link
Copy Markdown
Contributor

🛑 Fix loop escalated — human attention needed

This PR has failed CI on 1 distinct fix attempts (new commits, still red). The hive has stopped dispatching further automated fixes for it.

Failing checks: Rust quality gate, complement-readiness, complement-suite, element-web-e2e, protocol-fixtures, release-regression-gates

Raw failure evidence (from check-run annotations):

release-regression-gates: Process completed with exit code 101.

Remove the needs-human label after addressing the root cause to return the PR to the automated fix lane.

@hanthor-hive-agent

Copy link
Copy Markdown
Contributor

🛑 Fix loop escalated — human attention needed

This PR has failed CI on 1 distinct fix attempts (new commits, still red). The hive has stopped dispatching further automated fixes for it.

Failing checks: Rust quality gate, complement-readiness, complement-suite, element-web-e2e, protocol-fixtures, release-regression-gates

Raw failure evidence (from check-run annotations):

release-regression-gates: Process completed with exit code 101.

Remove the needs-human label after addressing the root cause to return the PR to the automated fix lane.

@hanthor-hive-agent

Copy link
Copy Markdown
Contributor

🛑 Fix loop escalated — human attention needed

This PR has failed CI on 1 distinct fix attempts (new commits, still red). The hive has stopped dispatching further automated fixes for it.

Failing checks: Rust quality gate, complement-readiness, complement-suite, element-web-e2e, protocol-fixtures, release-regression-gates

Raw failure evidence (from check-run annotations):

release-regression-gates: Process completed with exit code 101.

Remove the needs-human label after addressing the root cause to return the PR to the automated fix lane.

@hanthor-hive-agent

Copy link
Copy Markdown
Contributor

🛑 Fix loop escalated — human attention needed

This PR has failed CI on 1 distinct fix attempts (new commits, still red). The hive has stopped dispatching further automated fixes for it.

Failing checks: Rust quality gate, complement-readiness, complement-suite, element-web-e2e, protocol-fixtures, release-regression-gates

Raw failure evidence (from check-run annotations):

release-regression-gates: Process completed with exit code 101.

Remove the needs-human label after addressing the root cause to return the PR to the automated fix lane.

Bumps the rustcrypto group with 4 updates in the / directory: [argon2](https://github.com/RustCrypto/password-hashes), [sha2](https://github.com/RustCrypto/hashes), [sha1](https://github.com/RustCrypto/hashes) and [hmac](https://github.com/RustCrypto/MACs).


Updates `argon2` from 0.5.3 to 0.6.0
- [Commits](RustCrypto/password-hashes@argon2-v0.5.3...argon2-v0.6.0)

Updates `sha2` from 0.10.9 to 0.11.0
- [Commits](RustCrypto/hashes@sha2-v0.10.9...sha2-v0.11.0)

Updates `sha1` from 0.10.7 to 0.11.0
- [Commits](RustCrypto/hashes@sha1-v0.10.7...sha1-v0.11.0)

Updates `hmac` from 0.12.1 to 0.13.0
- [Commits](RustCrypto/MACs@hmac-v0.12.1...hmac-v0.13.0)

---
updated-dependencies:
- dependency-name: argon2
  dependency-version: 0.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rustcrypto
- dependency-name: hmac
  dependency-version: 0.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rustcrypto
- dependency-name: sha1
  dependency-version: 0.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rustcrypto
- dependency-name: sha2
  dependency-version: 0.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: rustcrypto
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/cargo/rustcrypto-b19923ba84 branch from 67e9190 to a8ae054 Compare September 6, 2026 01:09
@hanthor

hanthor commented Sep 6, 2026

Copy link
Copy Markdown
Member

Closing in favour of a PR that carries this same bump together with the code migration it needs: argon2 0.6 / password-hash 0.6 changed hash_password to take no salt (and moved PasswordHash/Salt under password_hash::phc), and hmac 0.13 split new_from_slice out of Mac into KeyInit, which is why spindle-server failed to compile here (7 errors, Rust quality gate exit 101). The replacement also adds a test that a hash written by argon2 0.5.3 still verifies, so the bump cannot lock existing users out.


Generated by Claude Code

@hanthor hanthor closed this Sep 6, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 6, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/cargo/rustcrypto-b19923ba84 branch September 6, 2026 01:22
hanthor added a commit that referenced this pull request Sep 6, 2026
Carries dependabot #290's rustcrypto bump plus the code migration it needs: PHC types from argon2::password_hash::phc, hash_password_with_salt at both call sites, KeyInit imported beside Mac for hmac 0.13, and a test that a hash written by argon2 0.5 still verifies.

Claude-Session: https://claude.ai/code/session_017Yvi53t1j2jqo9LJAtUXjf
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file needs-human rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant