Skip to content

build(deps): bump ed25519-dalek from 2.2.0 to 3.0.0 - #79

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/ed25519-dalek-3.0.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/ed25519-dalek-3.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 16, 2026

Copy link
Copy Markdown
Contributor

Bumps ed25519-dalek from 2.2.0 to 3.0.0.

Changelog

Sourced from ed25519-dalek's changelog.

3.0.0

  • Update the digest dependency to 0.9. This requires a major version because the digest traits are part of the public API, but there are otherwise no changes to the API.

2.1.0

  • Make Scalar::from_bits a const fn, allowing its use in const contexts.

2.0.0

  • Fix a data modeling error in the serde feature pointed out by Trevor Perrin which caused points and scalars to be serialized with length fields rather than as fixed-size 32-byte arrays. This is a breaking change, but it fixes compatibility with serde-json and ensures that the serde-bincode encoding matches the conventional encoding for X/Ed25519.
  • Update rand_core to 0.5, allowing use with new rand versions.
  • Switch from clear_on_drop to zeroize (by Tony Arcieri).
  • Require subtle = ^2.2.1 and remove the note advising nightly Rust, which is no longer required as of that version of subtle. See the subtle changelog for more details.
  • Update README.md for 2.x series.
  • Remove the build.rs hack which loaded the entire crate into its own build.rs to generate constants, and keep the constants in the source code.

The only significant change is the data model change to the serde feature; besides the rand_core version bump, there are no other user-visible changes.

1.2.4

  • Specify a semver bound for clear_on_drop rather than an exact version, addressing an issue where changes to inline assembly in rustc prevented clear_on_drop from working without an update.

1.2.3

  • Fix an issue identified by a Quarkslab audit (and Jack Grigg), where manually constructing unreduced Scalar values, as needed for X/Ed25519, and then performing scalar/scalar arithmetic could compute incorrect results.
  • Switch to upstream Rust intrinsics for the IFMA backend now that they exist in Rust and don't need to be defined locally.
  • Ensure that the NAF computation works correctly, even for parameters never used elsewhere in the codebase.
  • Minor refactoring to EdwardsPoint decompression.
  • Fix broken links in documentation.
  • Fix compilation on nightly broken due to changes to the #[doc(include)] path root (not quite correctly done in 1.2.2).

1.2.2

... (truncated)

Commits
  • 6d96eb7 Bump version to 3.0.0.
  • c68b30f Merge pull request #330 from isislovecruft/fix/move-coc
  • 2ee6193 Merge pull request #327 from huitseeker/digests-0.9
  • 91a0fae Move CoC section from CONTRIBUTING.md to new file.
  • 5038fcf Merge pull request #308 from isislovecruft/fix/pippenger-typo
  • 6afd8ff Update sha2, digest to 0.9
  • 3cc13a7 Merge branch 'master' into develop
  • c4824e1 Merge branch 'release/2.1.0'
  • 3fc47ef Bump version to 2.1.0
  • f04b830 Merge branch 'master' into develop
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [ed25519-dalek](https://github.com/dalek-cryptography/curve25519-dalek) from 2.2.0 to 3.0.0.
- [Release notes](https://github.com/dalek-cryptography/curve25519-dalek/releases)
- [Changelog](https://github.com/dalek-cryptography/curve25519-dalek/blob/3.0.0/CHANGELOG.md)
- [Commits](dalek-cryptography/curve25519-dalek@ed25519-2.2.0...3.0.0)

---
updated-dependencies:
- dependency-name: ed25519-dalek
  dependency-version: 3.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added area:build Build, dependencies, tests, and CI dependencies Pull requests that update a dependency file labels Sep 16, 2026
@dependabot
dependabot Bot requested a review from echobt as a code owner September 16, 2026 19:07
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file area:build Build, dependencies, tests, and CI labels Sep 16, 2026
@greptile-apps

greptile-apps Bot commented Sep 16, 2026

Copy link
Copy Markdown

Greptile Summary

The ed25519-dalek 3.0 dependency upgrade is compatible with the plugin verifier’s successful trusted-signature path, but the repository does not retain a regression test for that path. Adding the captured sign-then-verify test would protect the primary acceptance behavior against future dependency changes.

Confidence Score: 4/5

Safe to merge, with a non-blocking recommendation to add coverage for accepting valid signatures from trusted keys.

The focused contract check exercised successful verification with ed25519-dalek 3.0 and confirmed the behavior works. The remaining concern is a single regression-test gap.

Files Needing Attention: src/cortex-plugins/src/signing.rs needs a committed success-path test; src/cortex-plugins/Cargo.toml is the upgraded dependency declaration.

T-Rex T-Rex Logs

What T-Rex did

  • T-Rex produced a proof for a posted P2 finding and referenced the corresponding review comment.
  • T-Rex produced a second proof for another posted P2 finding and referenced its corresponding review comment.
  • Contract validation and test execution were performed, including pre- and post-capture signing tests and a temporary integration test that passed, followed by cleanup of the temporary test file.

View all artifacts

T-Rex Ran code and verified through T-Rex

Comments Outside Diff (1)
  1. General comment

    P2 No regression test covers successful trusted Ed25519 plugin verification

    • Bug
      • The current signing tests do not create an Ed25519 signature with ed25519-dalek 3.0, trust its matching public key, and assert that PluginSigner::verify_plugin returns Ok(true). A temporary contract test demonstrates that this untested success path currently works.
    • Cause
      • Existing tests focus on configuration, malformed inputs, and rejection paths. Although verify_plugin has its successful branch at src/cortex-plugins/src/signing.rs:115-119, no committed test drives that branch using a real valid signature.
    • Fix
      • Add the focused test captured in trex-artifacts/plugin-signer-valid-signature-02-after.rs to the repository test suite (or equivalent), retaining fixed data, a deterministic SigningKey, its matching trusted verifying key, and an assertion that verify_plugin returns true.

    T-Rex Ran code and verified through T-Rex

Reviews (1): Last reviewed commit: "build(deps): bump ed25519-dalek from 2.2..." | Re-trigger Greptile


# Cryptographic signing
ed25519-dalek = "2.1"
ed25519-dalek = "3.0"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Cover Valid Signature Verification

This upgrade has no committed test that signs plugin bytes with ed25519-dalek 3.0, trusts the matching public key, and verifies that PluginSigner::verify_plugin returns true. The currently untested success branch accepts authentic plugins, so a future compatibility regression could pass the suite unnoticed. Please add a fixed-vector or sign-then-verify regression test. This is non-blocking, but it leaves the upgrade’s central behavior without coverage.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

Artifacts

Command output from the check

  • Ran the existing PluginSigner unit-test scope and captured all 12 passing tests, which cover only setup, invalid input, no-key, and checksum cases; the valid trusted-signature success path is absent.

Evidence from the check

  • Authored the focused integration test that signs fixed plugin bytes with ed25519-dalek 3.0, trusts the matching verifying key, and asserts `verify_plugin` returns true; it is the missing regression coverage.

Command output from the check

  • Ran the authored integration test against the public PluginSigner contract and captured `verify_plugin returned Ok(true)` with 1 passed and 0 failed; the success path works but was previously untested.

View artifacts

T-Rex Ran code and verified through T-Rex

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:build Build, dependencies, tests, and CI dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants