Skip to content

build(deps): Bump rand from 0.8.6 to 0.10.1 - #85

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/rand-0.10.1
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/rand-0.10.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 29, 2026

Copy link
Copy Markdown
Contributor

Bumps rand from 0.8.6 to 0.10.1.

Changelog

Sourced from rand's changelog.

[0.10.1] — 2026-02-11

This release includes a fix for a soundness bug; see #1763.

Changes

  • Document panic behavior of make_rng and add #[track_caller] (#1761)
  • Deprecate feature log (#1763)

#1761: rust-random/rand#1761 #1763: rust-random/rand#1763

[0.10.0] - 2026-02-08

Changes

  • The dependency on rand_chacha has been replaced with a dependency on chacha20. This changes the implementation behind StdRng, but the output remains the same. There may be some API breakage when using the ChaCha-types directly as these are now the ones in chacha20 instead of rand_chacha (#1642).
  • Rename fns IndexedRandom::choose_multiple -> sample, choose_multiple_array -> sample_array, choose_multiple_weighted -> sample_weighted, struct SliceChooseIter -> IndexedSamples and fns IteratorRandom::choose_multiple -> sample, choose_multiple_fill -> sample_fill (#1632)
  • Use Edition 2024 and MSRV 1.85 (#1653)
  • Let Fill be implemented for element types, not sliceable types (#1652)
  • Fix OsError::raw_os_error on UEFI targets by returning Option<usize> (#1665)
  • Replace fn TryRngCore::read_adapter(..) -> RngReadAdapter with simpler struct RngReader (#1669)
  • Remove fns SeedableRng::from_os_rng, try_from_os_rng (#1674)
  • Remove Clone support for StdRng, ReseedingRng (#1677)
  • Use postcard instead of bincode to test the serde feature (#1693)
  • Avoid excessive allocation in IteratorRandom::sample when amount is much larger than iterator size (#1695)
  • Rename os_rng -> sys_rng, OsRng -> SysRng, OsError -> SysError (#1697)
  • Rename Rng -> RngExt as upstream rand_core has renamed RngCore -> Rng (#1717)

Additions

  • Add fns IndexedRandom::choose_iter, choose_weighted_iter (#1632)
  • Pub export Xoshiro128PlusPlus, Xoshiro256PlusPlus prngs (#1649)
  • Pub export ChaCha8Rng, ChaCha12Rng, ChaCha20Rng behind chacha feature (#1659)
  • Fn rand::make_rng() -> R where R: SeedableRng (#1734)

Removals

  • Removed ReseedingRng (#1722)
  • Removed unused feature "nightly" (#1732)
  • Removed feature small_rng (#1732)

#1632: rust-random/rand#1632 #1642: rust-random/rand#1642 #1649: rust-random/rand#1649 #1652: rust-random/rand#1652 #1653: rust-random/rand#1653 #1659: rust-random/rand#1659 #1665: rust-random/rand#1665 #1669: rust-random/rand#1669 #1674: rust-random/rand#1674 #1677: rust-random/rand#1677 #1693: rust-random/rand#1693 #1695: rust-random/rand#1695 #1697: rust-random/rand#1697

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [rand](https://github.com/rust-random/rand) from 0.8.6 to 0.10.1.
- [Release notes](https://github.com/rust-random/rand/releases)
- [Changelog](https://github.com/rust-random/rand/blob/master/CHANGELOG.md)
- [Commits](rust-random/rand@0.8.6...0.10.1)

---
updated-dependencies:
- dependency-name: rand
  dependency-version: 0.10.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels Jun 29, 2026
@github-project-automation github-project-automation Bot moved this to Todo in Driven Jun 29, 2026
@pmaxhogan

Copy link
Copy Markdown
Owner

Superseded by #107, which does the same rand 0.8 -> 0.10 bump plus the required SysRng/TryRng API migration in driven-crypto (dependabot's version-only bump cannot compile without it).

@pmaxhogan pmaxhogan closed this Jul 19, 2026
@github-project-automation github-project-automation Bot moved this from Todo to Done in Driven Jul 19, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jul 19, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/cargo/rand-0.10.1 branch July 19, 2026 16:06
pmaxhogan added a commit that referenced this pull request Jul 19, 2026
rand 0.8 -> 0.10 in driven-crypto (the only crate with a direct rand
dep). API migration per the rand 0.9/0.10 changelogs:

- `use rand::RngCore` -> `use rand::TryRng` (RngCore is a deprecated
  stub in rand_core 0.10; TryRng is the fallible base trait)
- `rand::rngs::OsRng.fill_bytes(buf)` ->
  `rand::rngs::SysRng.try_fill_bytes(buf).expect(...)` (OsRng was
  renamed SysRng and re-exported from getrandom 0.4; it only exposes
  the fallible TryRng surface, and .expect() preserves rand 0.8's
  behavior of panicking inside OsRng::fill_bytes on entropy failure)

Semantics preserved: every call site still fills raw byte buffers
straight from the OS CSPRNG (getrandom); no generator, seeding, or
distribution changes. chacha20poly1305 0.10 keeps its internal
rand_core 0.6 pin via aead 0.5, which is fine - driven-crypto never
passes an RNG into an aead API, so the two rand_core majors coexist.

Supersedes #85.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014fLmkjpFkiuky72eLBijL4
pmaxhogan added a commit that referenced this pull request Jul 19, 2026
rand 0.8 -> 0.10 in driven-crypto (the only crate with a direct rand
dep). API migration per the rand 0.9/0.10 changelogs:

- `use rand::RngCore` -> `use rand::TryRng` (RngCore is a deprecated
  stub in rand_core 0.10; TryRng is the fallible base trait)
- `rand::rngs::OsRng.fill_bytes(buf)` ->
  `rand::rngs::SysRng.try_fill_bytes(buf).expect(...)` (OsRng was
  renamed SysRng and re-exported from getrandom 0.4; it only exposes
  the fallible TryRng surface, and .expect() preserves rand 0.8's
  behavior of panicking inside OsRng::fill_bytes on entropy failure)

Semantics preserved: every call site still fills raw byte buffers
straight from the OS CSPRNG (getrandom); no generator, seeding, or
distribution changes. chacha20poly1305 0.10 keeps its internal
rand_core 0.6 pin via aead 0.5, which is fine - driven-crypto never
passes an RNG into an aead API, so the two rand_core majors coexist.

Supersedes #85.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014fLmkjpFkiuky72eLBijL4
pmaxhogan added a commit that referenced this pull request Jul 19, 2026
Bumps `rand` 0.8 -> 0.10 in `driven-crypto` (the only crate with a
direct `rand` dependency) and migrates the RNG API accordingly.

## API migration (per rand 0.9/0.10 changelogs)
- `use rand::RngCore` -> `use rand::TryRng` (RngCore is a deprecated
stub in rand_core 0.10; TryRng is the fallible base trait)
- `rand::rngs::OsRng.fill_bytes(buf)` ->
`rand::rngs::SysRng.try_fill_bytes(buf).expect(...)` (OsRng was renamed
SysRng and re-exported from getrandom 0.4; it only exposes the fallible
TryRng surface, and `.expect()` preserves rand 0.8's behavior of
panicking inside `OsRng::fill_bytes` on entropy failure)

Semantics preserved: every call site still fills raw byte buffers
straight from the OS CSPRNG (getrandom); no generator, seeding, or
distribution changes. `chacha20poly1305` 0.10 keeps its internal
rand_core 0.6 pin via aead 0.5, which is fine - driven-crypto never
passes an RNG into an aead API, so the two rand_core majors coexist.

## Verification
- `cargo check -p driven-crypto` clean
- `cargo test -p driven-crypto` - 41 passed, 0 failed (incl. crypto
round-trip + recovery-phrase tests)

Supersedes #85 (the plain dependabot lockfile bump, which does not
migrate the API and would fail to compile). Close #85 in favor of this.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant