Consolidate dependency and GitHub Actions maintenance - #346
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Consolidate dependency and GitHub Actions maintenance into one PR. Upgrade async-openai to 0.42 and reqwest to 0.13 together, migrate chat request construction and TLS features, and refresh Cargo.lock. The lockfile is outside the affected version ranges of all eight Dependabot alerts open when reviewed.
Remove tiktoken's dependency on the old OpenAI client and replace the removed backoff API with the client's retry layer.
openai.retriesnow limits additional attempts, including zero to disable retries. Preserve chat/legacy routing, custom endpoints, proxy configuration, and response trimming. Raise the documented minimum Rust version to 1.88 to match the resolved dependencies, and fix the Clippy warning enabled by that change.Supersedes #343, #337, #332, #331, #330, #327, #306, #304, #298, and #296. The error-handling and float-literal fixes from #341 are already on main.
Refresh all workflow actions with pinact: checkout 7.0.1, setup-rust-toolchain 2.0.0 (replacing actions-rs/toolchain), rust-cache 2.9.2, github-script 9.0.0, create-gh-release-action 1.11.0, and upload-rust-binary-action 1.30.2. Setup-just remains at 4.0.0. All actions are pinned to full SHAs with verified version comments. Preserve explicit cache steps and existing build warning behavior. Fix shell quoting, pass the Homebrew secret through the reusable workflow interface, and derive the Winget version from the release tag input instead of the caller's branch ref.
Workflow validation at
15f46b3cb65b39221fe85f4467c45c53dbd253cf:pinact run --check --verify-comment,actionlint(including ShellCheck), andgit diff --checkpassed. Updated-head CI has passed lint, Linux build/tests, and the version check; Windows is running and both macOS jobs are queued as of the latest check. Publishing workflows are statically validated; no release was triggered.Validation at
43c7432a2bd3d0230a7fe8c207b88712aaa9d2ec:just lint build testpassed locally on macOS with Rust 1.94.1, including CLI end-to-end tests and all 10 Rust tests. Local HTTP regression tests cover chat and legacy request payloads, response decoding/trimming, and retries enabled/disabled. No live model API calls were used. CI passed lint, the version check, Linux, both macOS targets, Windows, and the aggregate gate.