chore(deps): bump @openzeppelin-contracts 5.6.1 -> 5.7.0 - #141
Conversation
Latest published Soldeer revision of every dependency, checked against api.soldeer.xyz on 2026-10-01: @OpenZeppelin-Contracts 5.6.1 -> 5.7.0 (bumped) forge-std 1.16.2 -> 1.17.0 (NOT bumped, see below) rain-lib-hash 0.1.27 (latest) rain-lib-typecast 0.1.4 (latest) rain-math-binary 0.1.4 (latest) rain-sol-codegen 0.1.37 (latest) rain-solmem 0.1.28 (latest) The OZ bump rewrites the two versioned imports in LibContext.sol, the lockfile entry, and the slither filter_paths entry in the same commit. Not a port: the only OZ modules this repo uses are SignatureChecker and MessageHashUtils, and the 5.6.1 -> 5.7.0 diff to them is a comment-only header bump in MessageHashUtils and zero-padding of the ERC-1271 static call calldata in SignatureChecker (OZ #6646). No call site changes. forge-std is left at 1.16.2 deliberately. rain-sol-codegen 0.1.37, which is its own latest release, imports `forge-std-1.16.2/src/Vm.sol` by versioned path from src/lib/LibCodeGen.sol, LibFs.sol and LibHexString.sol, and this repo's src/lib/codegen/LibGenParseMeta.sol imports LibCodeGen. With one version per package and no aliasing remapping, moving forge-std to 1.17.0 removes the only directory that path resolves to. That needs a rain.sol.codegen release on forge-std 1.17.0 first. Verified in the rainix sol-shell CI pins: forge soldeer install twice (soldeer.lock and remappings.txt byte-identical between runs), forge test (17 suites, 128 passed, 0 failed, same count as main), forge fmt --check, forge lint -D warnings (0 findings), reuse lint, slither (0 results), pre-commit run --all-files. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (1)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: rainlanguage/rainlang.interface/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe Foundry dependency, Slither filter path, and two imports in ChangesOpenZeppelin dependency update
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Other Merge Risk: ⚪ Minimal · up to The 5.7.0 references align, and the reported tests pass. No actionable merge blocker is established. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 3 systems. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai assess this PR size classification for the totality of the PR with the following criterias and report it in your comment: S/M/L PR Classification Guidelines:This guide helps classify merged pull requests by effort and complexity rather than just line count. The goal is to assess the difficulty and scope of changes after they have been completed. Small (S)Characteristics:
Review Effort: Would have taken 5-10 minutes Examples:
Medium (M)Characteristics:
Review Effort: Would have taken 15-30 minutes Examples:
Large (L)Characteristics:
Review Effort: Would have taken 45+ minutes Examples:
Additional Factors to ConsiderWhen deciding between sizes, also consider:
Notes:
|
Bumps every Soldeer dependency that has a newer published release, checked against
https://api.soldeer.xyz/api/v1/revision?project_name=<name>&limit=1on 2026-10-01.OpenZeppelin 5.6.1 -> 5.7.0
One version per package: the
foundry.tomlpin, thesoldeer.lockentry, both versioned imports insrc/lib/caller/LibContext.sol, and the versionedfilter_pathsentry inslither.config.jsonall move together. No remapping aliases the old version.Not a port. The only OZ modules this repo imports are
SignatureCheckerandMessageHashUtils. Between the tags,MessageHashUtilschanges only its version header comment, andSignatureCheckerzero-pads the ERC-1271 staticcall calldata to a 32-byte boundary (OpenZeppelin/openzeppelin-contracts#6646). Call sites inLibContextare unchanged. Bytecode of anything touchingSignatureChecker.isValidSignatureNowmoves because of that padding.forge-std 1.16.2 -> 1.17.0: stopped
rain-sol-codegen0.1.37 is the latest published release and its own source pins forge-std by versioned path:src/lib/codegen/LibGenParseMeta.solimportsLibCodeGen, so withrecursive_deps = falsethat path resolves only through this repo's ownforge-std-1.16.2/remapping. Moving forge-std to 1.17.0 would remove the only directory it resolves to, and bridging it would mean either a second Soldeer key for forge-std or a remapping aliasing 1.16.2 onto 1.17.0, both ruled out. The fix is upstream: a rain.sol.codegen release built on forge-std 1.17.0, after which this repo can take both in one bump.Verification
All in the rainix
sol-shellCI pins (nix develop github:rainlanguage/rainix/8657b83b68f41957ab85da91132c3f652c1f32c0#sol-shell):forge soldeer installtwice from a wipeddependencies/,soldeer.lock,remappings.txt: both files byte-identical between runs; exactly one directory per package on disk.forge test -vvv: 17 suites, 128 passed, 0 failed, 0 skipped. Same count as the last green run on main.forge fmt --check: clean.forge lint -D warnings: exit 0, 0 findings.reuse lint: compliant (80/80).slither .: 0 results. (Before thefilter_pathsretarget it reported 19, all insidedependencies/@openzeppelin-contracts-5.7.0/.)pre-commit run --all-files: passed.Relation to #134
Independent of #134 (EIP-712 signed context). Both touch
src/lib/caller/LibContext.sol, but this PR changes only the two@openzeppelin-contracts-5.6.1/import paths at the top of the file. Whichever merges second rebases trivially.🤖 Generated with Claude Code
Summary by CodeRabbit