build(deps): bump curve25519-dalek from 4.1.3 to 5.0.0 - #600
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [curve25519-dalek](https://github.com/dalek-cryptography/curve25519-dalek) from 4.1.3 to 5.0.0. - [Release notes](https://github.com/dalek-cryptography/curve25519-dalek/releases) - [Commits](dalek-cryptography/curve25519-dalek@curve25519-4.1.3...curve25519-5.0.0) --- updated-dependencies: - dependency-name: curve25519-dalek dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Review: hold — green CI is hiding a duplicated curve implementation inside the TCBAll 66 checks pass, including What the lockfile actually does
So after this merge the graph carries both majors simultaneously, and the dependency split propagates downward:
Why that is a blocker here specifically, not a nitpick
RecommendationBlock until the dalek ecosystem catches up. The correct trigger to revisit is Concretely, I'd like to see one of:
Either way, please add a Not merging on a green checkmark here. |
Bumps curve25519-dalek from 4.1.3 to 5.0.0.
Commits
07bef73Prep v5.0 major release (#916)0cd94eaed: ImplementKeySizeUser,TryKeyInit, andGenerateforSigningKey. A...eeaf902perf(lizard): skip negative preimages in lizard_decode (#882)78abeaeFix running doc tests (#914)4cf8db2Support AVX512 on stable Rust (#913)d995cafPrep v5.0-rc.1 (#911)1c14d54curve: Bring backffandgroup(#909)58b331ccurve,x,ed: re-export rand_core (#908)70e82aaPrep v5.0-rc.0 (#906)13ac5e6curve: Remove ff/group features for now (#907)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)