Skip to content

Bump dependencies, including the RustCrypto stack (supersedes #330 and #312) - #349

Open
ixcans wants to merge 10 commits into
eclipse-biscuit:mainfrom
ixcans:bump-deps-and-rustcrypto
Open

ixcans wants to merge 10 commits into
eclipse-biscuit:mainfrom
ixcans:bump-deps-and-rustcrypto

Conversation

@ixcans

@ixcans ixcans commented Sep 30, 2026

Copy link
Copy Markdown

Rebases #330 onto current main and stacks #312 on top, ported to the current
crypto traits layout. Original commits and authorship are preserved
(@avandecreme for #330, @baloo for #312).

What changes

  • From Bump dependencies #330: base64 0.22, prost/prost-types/prost-build 0.14, nom 8,
    thiserror 2, removal of outdated non-direct dependencies, and syn 2 for
    biscuit-quote (kept the full/extra-traits features, and manyhow, which
    main uses now).
  • From workspace: bump RustCrypto dependencies to new set of releases #312: ed25519-dalek 3, p256 0.14, rand 0.10, rand_core 0.10.
    RngCore becomes Rng, RNG parameters are ?Sized, OsRng becomes
    rand::rng(), and the direct ecdsa/elliptic-curve dependencies are dropped
    in favour of p256's re-exports. Ported onto the PrivateKey / Sign /
    Verify trait layout that main has now.

Things the dependency bumps required

  • prost-build 0.11+ no longer bundles protoc, so the format::tests::proto
    test needs it on the runner: the build and capi jobs now install
    protobuf-compiler.
  • schema.rs regenerated with prost-build 0.14 (formatting, Eq, Hash
    derives). No schema change.
  • biscuit-auth/samples/samples.json: the signature crate no longer appends
    "Verification equation was not satisfied" to InvalidSignature, so that
    message text in four samples changed. No change to tokens or verdicts.

Breaking

rand_core / rand are part of biscuit-auth's public API
(new_with_rng, build_with_rng), so this is a breaking change, as noted in
#312.

Testing

All three workflows (build, capi, coverage) green on a fork run of this exact
stack, including cargo test --features="serde-error,bwk", the trybuild
error-message tests, and the sample regeneration check (git diff --exit-code).

Antoine Vandecrème and others added 10 commits September 30, 2026 15:26
Signed-off-by: ixcans <78341771+ixcans@users.noreply.github.com>
Signed-off-by: ixcans <78341771+ixcans@users.noreply.github.com>
Signed-off-by: ixcans <78341771+ixcans@users.noreply.github.com>
Signed-off-by: ixcans <78341771+ixcans@users.noreply.github.com>
Signed-off-by: ixcans <78341771+ixcans@users.noreply.github.com>
Signed-off-by: ixcans <78341771+ixcans@users.noreply.github.com>
Move to the stable RustCrypto releases: ed25519-dalek 3, p256 0.14,
rand 0.10 and rand_core 0.10.

- RngCore is now Rng, and generic RNG parameters are ?Sized.
- OsRng is replaced by rand::rng().
- p256: SigningKey::generate_from_rng, SEC1 point encoding renamed,
  from_bytes takes a fixed-size array, and the direct ecdsa and
  elliptic-curve dependencies are dropped in favour of p256's re-exports.

Originally proposed in eclipse-biscuit#312; ported onto the current crypto traits
layout.

Signed-off-by: ixcans <78341771+ixcans@users.noreply.github.com>
prost-build no longer bundles protoc, so the test that regenerates the
protobuf bindings and compares them with the committed schema.rs needs
a protoc binary on the runner.

Signed-off-by: ixcans <78341771+ixcans@users.noreply.github.com>
The signature crate no longer includes the underlying cause in the
InvalidSignature message, so regenerate the samples.

Signed-off-by: ixcans <78341771+ixcans@users.noreply.github.com>
Signed-off-by: ixcans <78341771+ixcans@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants