Skip to content

deps: bump every Soldeer dependency to its latest published release - #35

Merged
thedavidmeister merged 2 commits into
mainfrom
bump-soldeer-deps-latest
Oct 1, 2026
Merged

thedavidmeister merged 2 commits into
mainfrom
bump-soldeer-deps-latest

Conversation

@thedavidmeister

Copy link
Copy Markdown
Contributor

What

Bumps every Soldeer dependency to the latest revision the registry reports (https://api.soldeer.xyz/api/v1/revision?project_name=<name>&limit=1), one version per package, with every versioned import path under src/ and test/ rewritten in the same commit:

package old new
forge-std 1.16.1 1.17.0
@OpenZeppelin-Contracts 5.6.1 5.7.0
rain-string 0.2.0 0.3.9
rain-math-saturating 0.1.10 0.1.10 (already latest)

No remapping aliases an old version to a new one and no package has a second Soldeer key. rain-string and @openzeppelin-contracts were pinned by path in LibFixedPointDecimalParse.sol, LibFixedPointDecimalStrings.sol, LibFixedPointDecimalArithmeticOpenZeppelin.sol and LibFixedPointDecimalFormat.sol; all four now point at the new versions. This unblocks rain.vats #339.

rain-string 0.2.0 -> 0.3.9 is a port, not a pin bump

Read from the v0.2.0..sol-v0.3.9 diff of rain.string:

  • Every CMASK_* constant widened from uint128 to uint256. This library only passes CMASK_NUMERIC_0_9, CMASK_DECIMAL_POINT and CMASK_ZERO into LibParseChar.skipMask / isMask, whose mask parameter was already uint256, so call sites bind identically.
  • LibParseDecimal.unsafeDecimalStringToInt now validates every byte and returns the new ParseInvalidDecimalChar selector on a non-digit. Every region this library hands it is first bounded by skipMask(CMASK_NUMERIC_0_9), so the region can never hold a non-digit and the new selector is unreachable from here. Overflow / empty classification for all-digit input is unchanged.
  • LibParseChar.skipMask / isMask made the bounds check branchless (zeroed load address instead of a jump); same results.
  • LibConformString.conformStringToMask went from three arguments to two. This repo never imports LibConformString, so no call site changes.

OZ utils/math/Math.sol and utils/Strings.sol, the only OZ files this library uses, are byte-identical between v5.6.1 and v5.7.0.

Second commit

ci: drop the blank line yamlfmt rejects in pr-assessment.yaml: the rainix static job runs pre-commit run --all-files, and the yamlfmt hook rewrote this file. The committed change is the hook's own output.

Verification

All in the pinned rainix sol-shell the repo's CI uses (nix develop github:rainlanguage/rainix/8657b83b…#sol-shell -c):

  • forge soldeer install run twice; soldeer.lock and remappings.txt byte-identical between runs
  • forge test -vvv: 12 suites, 78 tests passed, 0 failed (same 78 as main before the bump)
  • forge fmt --check: clean
  • forge lint -D warnings: exit 0
  • slither .: 14 contracts analyzed, 0 results
  • reuse lint: compliant
  • pre-commit run --all-files: all hooks pass
  • rainix-sol-single-contract: pass

QA

  • Discriminating tests: n/a - no new tests; the diff adds no behaviour to this repo. The existing LibFixedPointDecimalParseTest (examples, corrupt integer, precision loss, overflow) and FixedPointDecimalArithmeticOpenZeppelin.t.sol drive the ported rain-string parser and the OZ Math/Strings entry points through the new paths; all 78 pass unchanged against the new dependency source.
  • Mutations applied: n/a - every Solidity hunk is a version string inside an import path plus the manifest, lock and remappings; a mutated path is a compile error, not a surviving mutant. No mutation run was performed and none is claimed.
  • Oracle: the rain.string v0.2.0..sol-v0.3.9 source diff (read before touching call sites) for what changed and whether it reaches this repo; diff of OZ Math.sol/Strings.sol at v5.6.1 vs v5.7.0 (identical); the Soldeer revision API for "latest"; test expectations are main's, untouched.
  • Category check: task asks (A) every dep on latest, (B) imports rewritten in the same commit with one version per package, (C) stop on any dep whose latest pins an older shared package by path, (D) CI-equivalent verification. Covered A, B, D; C: rain-string 0.3.9 and rain-math-saturating 0.1.10 ship no src/ import of forge-std, OZ or any rain package, so nothing to stop on.

🤖 Generated with Claude Code

thedavidmeister and others added 2 commits October 1, 2026 22:19
forge-std 1.16.1 -> 1.17.0
@OpenZeppelin-Contracts 5.6.1 -> 5.7.0
rain-string 0.2.0 -> 0.3.9
rain-math-saturating 0.1.10 (already latest, unchanged)

Every versioned import path under src/ and test/ is rewritten in this
commit so the tree holds exactly one version of each package; no
remapping aliases an old version to a new one and no package has a
second Soldeer key.

rain-string 0.2.0 -> 0.3.9 is a port rather than a pin bump: the
CMASK_* constants widened from uint128 to uint256 and
LibParseDecimal.unsafeDecimalStringToInt now rejects non-digit bytes
with ParseInvalidDecimalChar. Neither changes this library's behaviour.
LibParseChar.skipMask/isMask already took the mask as uint256, so the
widened constants bind to the same parameter type, and every region
this library hands to unsafeDecimalStringToInt is bounded by
skipMask(CMASK_NUMERIC_0_9) first, so it can never contain a non-digit.
conformStringToMask's arity change does not reach this repo, which
never imports LibConformString. The OZ Math.sol and Strings.sol this
library uses are byte-identical between 5.6.1 and 5.7.0.

Verified in the pinned rainix sol-shell CI uses: forge soldeer install
twice with soldeer.lock and remappings.txt byte-stable between runs,
forge test (12 suites, 78 tests, all passing, same count as before the
bump), forge fmt --check, forge lint -D warnings, slither (0 results),
reuse lint and rainix-sol-single-contract.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The rainix static job runs pre-commit over every file and the yamlfmt
hook rewrites this file to remove the blank line between the trigger
and the jobs block. This is the hook's own output committed, so the
job passes instead of failing on a diff.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 800d681a-4c3f-4775-86c2-f3d5938087b1

📥 Commits

Reviewing files that changed from the base of the PR and between 713c3b5 and a53d7c6.

⛔ Files ignored due to path filters (1)
  • soldeer.lock is excluded by !**/*.lock
📒 Files selected for processing (19)
  • .github/workflows/pr-assessment.yaml
  • foundry.toml
  • remappings.txt
  • src/lib/LibFixedPointDecimalArithmeticOpenZeppelin.sol
  • src/lib/LibFixedPointDecimalStrings.sol
  • src/lib/format/LibFixedPointDecimalFormat.sol
  • src/lib/parse/LibFixedPointDecimalParse.sol
  • test/src/lib/FixedPointDecimalArithmeticOpenZeppelin.t.sol
  • test/src/lib/FixedPointDecimalScale.decimalOrIntToInt.t.sol
  • test/src/lib/FixedPointDecimalScale.scale18.t.sol
  • test/src/lib/FixedPointDecimalScale.scaleBy.t.sol
  • test/src/lib/FixedPointDecimalScale.scaleDown.t.sol
  • test/src/lib/FixedPointDecimalScale.scaleDownRoundUp.t.sol
  • test/src/lib/FixedPointDecimalScale.scaleToIntegerLossless.t.sol
  • test/src/lib/FixedPointDecimalScale.scaleUp.t.sol
  • test/src/lib/FixedPointDecimalScale.scaleUpSaturating.t.sol
  • test/src/lib/FixedPointDecimalScaleN.t.sol
  • test/src/lib/format/LibFixedPointDecimalFormat.fixedPointToDecimalString.t.sol
  • test/src/lib/parse/LibFixedPointDecimalParse.decimalStringToFixedPoint.t.sol
 _____________________________
< Goodbye, code review angst. >
 -----------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@thedavidmeister
thedavidmeister merged commit d5d04bc into main Oct 1, 2026
3 of 6 checks passed
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

@coderabbitai assess this PR size classification for the totality of the PR with the following criterias and report it in your comment:

S/M/L PR Classification Guidelines:

This guide helps classify merged pull requests by effort and complexity rather than just line count. The goal is to assess the difficulty and scope of changes after they have been completed.

Small (S)

Characteristics:

  • Simple bug fixes, typos, or minor refactoring
  • Single-purpose changes affecting 1-2 files
  • Documentation updates
  • Configuration tweaks
  • Changes that require minimal context to review

Review Effort: Would have taken 5-10 minutes

Examples:

  • Fix typo in variable name
  • Update README with new instructions
  • Adjust configuration values
  • Simple one-line bug fixes
  • Import statement cleanup

Medium (M)

Characteristics:

  • Feature additions or enhancements
  • Refactoring that touches multiple files but maintains existing behavior
  • Breaking changes with backward compatibility
  • Changes requiring some domain knowledge to review

Review Effort: Would have taken 15-30 minutes

Examples:

  • Add new feature or component
  • Refactor common utility functions
  • Update dependencies with minor breaking changes
  • Add new component with tests
  • Performance optimizations
  • More complex bug fixes

Large (L)

Characteristics:

  • Major feature implementations
  • Breaking changes or API redesigns
  • Complex refactoring across multiple modules
  • New architectural patterns or significant design changes
  • Changes requiring deep context and multiple review rounds

Review Effort: Would have taken 45+ minutes

Examples:

  • Complete new feature with frontend/backend changes
  • Protocol upgrades or breaking changes
  • Major architectural refactoring
  • Framework or technology upgrades

Additional Factors to Consider

When deciding between sizes, also consider:

  • Test coverage impact: More comprehensive test changes lean toward larger classification
  • Risk level: Changes to critical systems bump up a size category
  • Team familiarity: Novel patterns or technologies increase complexity

Notes:

  • the assessment must be for the totality of the PR, that means comparing the base branch to the last commit of the PR
  • the assessment output must be exactly one of: S, M or L (single-line comment) in format of: SIZE={S/M/L}
  • do not include any additional text, only the size classification
  • your assessment comment must not include tips or additional sections
  • do NOT tag me or anyone else on your comment

@linear

linear Bot commented Oct 1, 2026

Copy link
Copy Markdown

RAI-2820

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant