Skip to content

chore(deps): bump @openzeppelin-contracts 5.6.1 -> 5.7.0 - #141

Merged
thedavidmeister merged 1 commit into
mainfrom
2026-10-01-bump-soldeer-deps
Oct 1, 2026
Merged

thedavidmeister merged 1 commit into
mainfrom
2026-10-01-bump-soldeer-deps

Conversation

@thedavidmeister

@thedavidmeister thedavidmeister commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps every Soldeer dependency that has a newer published release, checked against https://api.soldeer.xyz/api/v1/revision?project_name=<name>&limit=1 on 2026-10-01.

package main latest this PR
@OpenZeppelin-Contracts 5.6.1 5.7.0 5.7.0
forge-std 1.16.2 1.17.0 1.16.2 (blocked, see below)
rain-lib-hash 0.1.27 0.1.27 unchanged
rain-lib-typecast 0.1.4 0.1.4 unchanged
rain-math-binary 0.1.4 0.1.4 unchanged
rain-sol-codegen 0.1.37 0.1.37 unchanged
rain-solmem 0.1.28 0.1.28 unchanged

OpenZeppelin 5.6.1 -> 5.7.0

One version per package: the foundry.toml pin, the soldeer.lock entry, both versioned imports in src/lib/caller/LibContext.sol, and the versioned filter_paths entry in slither.config.json all move together. No remapping aliases the old version.

Not a port. The only OZ modules this repo imports are SignatureChecker and MessageHashUtils. Between the tags, MessageHashUtils changes only its version header comment, and SignatureChecker zero-pads the ERC-1271 staticcall calldata to a 32-byte boundary (OpenZeppelin/openzeppelin-contracts#6646). Call sites in LibContext are unchanged. Bytecode of anything touching SignatureChecker.isValidSignatureNow moves because of that padding.

forge-std 1.16.2 -> 1.17.0: stopped

rain-sol-codegen 0.1.37 is the latest published release and its own source pins forge-std by versioned path:

dependencies/rain-sol-codegen-0.1.37/src/lib/LibCodeGen.sol:5:   import {Vm} from "forge-std-1.16.2/src/Vm.sol";
dependencies/rain-sol-codegen-0.1.37/src/lib/LibFs.sol:5:        import {Vm, VmSafe} from "forge-std-1.16.2/src/Vm.sol";
dependencies/rain-sol-codegen-0.1.37/src/lib/LibHexString.sol:5: import {Vm} from "forge-std-1.16.2/src/Vm.sol";

src/lib/codegen/LibGenParseMeta.sol imports LibCodeGen, so with recursive_deps = false that path resolves only through this repo's own forge-std-1.16.2/ remapping. Moving forge-std to 1.17.0 would remove the only directory it resolves to, and bridging it would mean either a second Soldeer key for forge-std or a remapping aliasing 1.16.2 onto 1.17.0, both ruled out. The fix is upstream: a rain.sol.codegen release built on forge-std 1.17.0, after which this repo can take both in one bump.

Verification

All in the rainix sol-shell CI pins (nix develop github:rainlanguage/rainix/8657b83b68f41957ab85da91132c3f652c1f32c0#sol-shell):

  • forge soldeer install twice from a wiped dependencies/, soldeer.lock, remappings.txt: both files byte-identical between runs; exactly one directory per package on disk.
  • forge test -vvv: 17 suites, 128 passed, 0 failed, 0 skipped. Same count as the last green run on main.
  • forge fmt --check: clean.
  • forge lint -D warnings: exit 0, 0 findings.
  • reuse lint: compliant (80/80).
  • slither .: 0 results. (Before the filter_paths retarget it reported 19, all inside dependencies/@openzeppelin-contracts-5.7.0/.)
  • pre-commit run --all-files: passed.

Relation to #134

Independent of #134 (EIP-712 signed context). Both touch src/lib/caller/LibContext.sol, but this PR changes only the two @openzeppelin-contracts-5.6.1/ import paths at the top of the file. Whichever merges second rebases trivially.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated the underlying OpenZeppelin Contracts version from 5.6.1 to 5.7.0. Project references and related analysis configuration now align with the updated version. This update does not change application behavior or add, remove, or alter any user-facing functionality. No other user-visible changes are included.

Latest published Soldeer revision of every dependency, checked against
api.soldeer.xyz on 2026-10-01:

  @OpenZeppelin-Contracts  5.6.1  -> 5.7.0   (bumped)
  forge-std                1.16.2 -> 1.17.0  (NOT bumped, see below)
  rain-lib-hash            0.1.27 (latest)
  rain-lib-typecast        0.1.4  (latest)
  rain-math-binary         0.1.4  (latest)
  rain-sol-codegen         0.1.37 (latest)
  rain-solmem              0.1.28 (latest)

The OZ bump rewrites the two versioned imports in LibContext.sol, the
lockfile entry, and the slither filter_paths entry in the same commit.
Not a port: the only OZ modules this repo uses are SignatureChecker and
MessageHashUtils, and the 5.6.1 -> 5.7.0 diff to them is a comment-only
header bump in MessageHashUtils and zero-padding of the ERC-1271 static
call calldata in SignatureChecker (OZ #6646). No call site changes.

forge-std is left at 1.16.2 deliberately. rain-sol-codegen 0.1.37, which
is its own latest release, imports `forge-std-1.16.2/src/Vm.sol` by
versioned path from src/lib/LibCodeGen.sol, LibFs.sol and
LibHexString.sol, and this repo's src/lib/codegen/LibGenParseMeta.sol
imports LibCodeGen. With one version per package and no aliasing
remapping, moving forge-std to 1.17.0 removes the only directory that
path resolves to. That needs a rain.sol.codegen release on forge-std
1.17.0 first.

Verified in the rainix sol-shell CI pins: forge soldeer install twice
(soldeer.lock and remappings.txt byte-identical between runs), forge
test (17 suites, 128 passed, 0 failed, same count as main), forge fmt
--check, forge lint -D warnings (0 findings), reuse lint, slither (0
results), pre-commit run --all-files.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
CLAUDE.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: rainlanguage/rainlang.interface/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: a852eaad-86c6-4712-8b13-3dc01a65e4ab

📥 Commits

Reviewing files that changed from the base of the PR and between 6fe73f7 and f151325.

⛔ Files ignored due to path filters (1)
  • soldeer.lock is excluded by !**/*.lock
📒 Files selected for processing (3)
  • foundry.toml
  • slither.config.json
  • src/lib/caller/LibContext.sol

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The Foundry dependency, Slither filter path, and two imports in LibContext.sol now reference OpenZeppelin Contracts 5.7.0 instead of 5.6.1. No runtime logic changed.

Changes

OpenZeppelin dependency update

Layer / File(s) Summary
Update dependency and references
foundry.toml, src/lib/caller/LibContext.sol, slither.config.json
The Foundry dependency, Slither filter path, and imports for SignatureChecker and MessageHashUtils now reference OpenZeppelin Contracts 5.7.0. The forge-std filter is unchanged.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to f1513

The 5.7.0 references align, and the reported tests pass. No actionable merge blocker is established.

Architecture Summary

Architecture risk: 🔵 Low · up to f1513

The change affects 3 systems.

Changed systems: foundry.toml, slither.config.json, src

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — foundry.toml (service) was modified; 1 changed file maps to changed impact.
  • observed — slither.config.json (service) was modified; 1 changed file maps to changed impact.
  • observed — src (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in foundry.toml: The @openzeppelin-contracts dependency version changed from 5.6.1 to 5.7.0.
  • observed — Modified behavior in slither.config.json: The OpenZeppelin dependency path in filter_paths changes from version 5.6.1 to 5.7.0; the forge-std path remains unchanged.
  • observed — Modified behavior in src/lib/caller/LibContext.sol: The OpenZeppelin imports for SignatureChecker and MessageHashUtils now reference version 5.7.0 instead of 5.6.1.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: upgrading the @openzeppelin-contracts dependency from 5.6.1 to 5.7.0.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@thedavidmeister
thedavidmeister merged commit 27e89e2 into main Oct 1, 2026
5 of 6 checks passed
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

@coderabbitai assess this PR size classification for the totality of the PR with the following criterias and report it in your comment:

S/M/L PR Classification Guidelines:

This guide helps classify merged pull requests by effort and complexity rather than just line count. The goal is to assess the difficulty and scope of changes after they have been completed.

Small (S)

Characteristics:

  • Simple bug fixes, typos, or minor refactoring
  • Single-purpose changes affecting 1-2 files
  • Documentation updates
  • Configuration tweaks
  • Changes that require minimal context to review

Review Effort: Would have taken 5-10 minutes

Examples:

  • Fix typo in variable name
  • Update README with new instructions
  • Adjust configuration values
  • Simple one-line bug fixes
  • Import statement cleanup

Medium (M)

Characteristics:

  • Feature additions or enhancements
  • Refactoring that touches multiple files but maintains existing behavior
  • Breaking changes with backward compatibility
  • Changes requiring some domain knowledge to review

Review Effort: Would have taken 15-30 minutes

Examples:

  • Add new feature or component
  • Refactor common utility functions
  • Update dependencies with minor breaking changes
  • Add new component with tests
  • Performance optimizations
  • More complex bug fixes

Large (L)

Characteristics:

  • Major feature implementations
  • Breaking changes or API redesigns
  • Complex refactoring across multiple modules
  • New architectural patterns or significant design changes
  • Changes requiring deep context and multiple review rounds

Review Effort: Would have taken 45+ minutes

Examples:

  • Complete new feature with frontend/backend changes
  • Protocol upgrades or breaking changes
  • Major architectural refactoring
  • Framework or technology upgrades

Additional Factors to Consider

When deciding between sizes, also consider:

  • Test coverage impact: More comprehensive test changes lean toward larger classification
  • Risk level: Changes to critical systems bump up a size category
  • Team familiarity: Novel patterns or technologies increase complexity

Notes:

  • the assessment must be for the totality of the PR, that means comparing the base branch to the last commit of the PR
  • the assessment output must be exactly one of: S, M or L (single-line comment) in format of: SIZE={S/M/L}
  • do not include any additional text, only the size classification
  • your assessment comment must not include tips or additional sections
  • do NOT tag me or anyone else on your comment

@linear

linear Bot commented Oct 1, 2026

Copy link
Copy Markdown

RAI-2817

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant