Skip to content

chore(deps): bump alloy-signer-ledger from 1.8.3 to 2.0.5 - #1493

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/alloy-signer-ledger-2.0.5
Open

chore(deps): bump alloy-signer-ledger from 1.8.3 to 2.0.5#1493
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/cargo/alloy-signer-ledger-2.0.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps alloy-signer-ledger from 1.8.3 to 2.0.5.

Release notes

Sourced from alloy-signer-ledger's releases.

v2.0.5

What's Changed

New Contributors

Full Changelog: alloy-rs/alloy@v2.0.4...v2.0.5

v2.0.4

... (truncated)

Changelog

Sourced from alloy-signer-ledger's changelog.

2.0.5 - 2026-05-18

Bug Fixes

  • [ci] Satisfy zepter secp256k1 propagation (#3993)
  • [network] Preserve transaction request extra fields
  • [consensus] Correct recovered transaction docs (#3984)
  • [signer-ledger] Reject invalid derivation paths (#3960)
  • [consensus-any] Saturate baseFeePerGas above u64::MAX on deser (#3741) (#3976)
  • [eips] Avoid panic in 7594 match_versioned_hashes (#3975)
  • [signer-trezor] Reject unsupported tx types (#3959)
  • [transport] Make retry queue count cancel-safe (#3956)
  • [signer-trezor] Dispatch EIP-1559 by tx type (#3958)
  • [rpc-types-trace] Default missing/null CallOutput.output to empty bytes (#3931)
  • [eip1559] Prevent divide-by-zero in next base fee calculation
  • [provider] Clean up failed impersonated sends (#3944)
  • Deduplicate AnyRpcTransaction conversion helpers (#3947)
  • [ci] Stabilize main red tests (#3942)

Dependencies

  • [deps] Bump github/codeql-action from 4.35.2 to 4.35.4 (#3990)
  • [deps] Bump taiki-e/install-action from 2.75.27 to 2.77.1
  • [deps] Bump crate-ci/typos from 1.45.0 to 1.46.0 (#3965)
  • [deps] Bump taiki-e/install-action from 2.75.20 to 2.75.27 (#3964)
  • [deps] Bump taiki-e/install-action from 2.75.15 to 2.75.20 (#3946)
  • [deps] Bump foundry-rs/foundry-toolchain from 1.7.0 to 1.8.0 (#3945)

Documentation

  • [rpc-types-eth] Correct sealed_header docs (#3995)
  • [node-bindings] Clarify Reth genesis behavior (#3994)
  • [eips] Document blob cell selection invariants (#3973)
  • [signer-tempo] Add changelog (#3962)

Features

  • [rpc-types-engine] Add payload attributes builders (#3985)
  • [rpc-types-beacon] Add builder validation request v6 (#3981)
  • [eips] Add EIP-7594 matching cell computation (#3974)
  • [rpc-types-engine] Add SSZ codecs for engine types (#3970)
  • [pubsub] Typed terminal-error channel (#3963)
  • [signer-tempo] Add Tempo wallet keystore reader (#3936)
  • [rpc-types-engine] Add sealed block execution data conversions (#3955)

Miscellaneous Tasks

  • Release 2.0.5
  • Release 2.0.5
  • Release 2.0.5

... (truncated)

Commits
  • 653989f chore: release 2.0.5
  • ee8c72f chore: release 2.0.5
  • a90ea92 chore: release 2.0.5
  • 51090d3 chore: release 2.0.5
  • 2d3a3fb docs(rpc-types-eth): correct sealed_header docs (#3995)
  • a019321 fix(ci): satisfy zepter secp256k1 propagation (#3993)
  • a51afc1 docs(node-bindings): clarify Reth genesis behavior (#3994)
  • 2aa6712 chore(deps): bump github/codeql-action from 4.35.2 to 4.35.4 (#3990)
  • f97b3cb fix(network): preserve transaction request extra fields
  • 51cb51d chore(deps): bump taiki-e/install-action from 2.75.27 to 2.77.1
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [alloy-signer-ledger](https://github.com/alloy-rs/alloy) from 1.8.3 to 2.0.5.
- [Release notes](https://github.com/alloy-rs/alloy/releases)
- [Changelog](https://github.com/alloy-rs/alloy/blob/main/CHANGELOG.md)
- [Commits](alloy-rs/alloy@v1.8.3...v2.0.5)

---
updated-dependencies:
- dependency-name: alloy-signer-ledger
  dependency-version: 2.0.5
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update Rust code labels Aug 3, 2026

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Value Audit — sound-with-nits

Verdict sound-with-nits
Concerns 1 (1 weak-concern)
Heuristic 0.0s
Duplication 0.0s
Interrogation 900.0s (2 bridge agents)
Total 900.0s

💰 Value — sound-with-nits

Bumps alloy-signer-ledger 1.8.3→2.0.5 to align it with the already-2.0 aws/gcp remote signers; correct and minimal, but leaves the workspace mid-migration with alloy compiled in two major versions at once.

  • What it does: Raises the workspace requirement on alloy-signer-ledger from 1.8 to 2.0 (Cargo.toml:428) and updates Cargo.lock so the Ledger remote-signer path (and its transitive alloy-consensus/alloy-network/alloy-signer deps) move from the 1.8.3 line to the 2.0.5 line. No source changes — pure manifest/lock bump.
  • Goals it achieves: Keep the Ledger hardware-wallet signing backend on the current alloy 2.0 release line that the other cloud signers (AWS KMS, GCP KMS) already target, picking up upstream 2.x fixes (e.g. the EIP-1559 divide-by-zero fix, provider cleanup) and consolidating the remote-signer camp on one alloy major.
  • Assessment: Coherent and in the grain: alloy-signer-aws and alloy-signer-gcp were already pinned at 2.0 (Cargo.toml:426-427), so this brings the third remote signer onto the same line. The change is minimal and directionally correct. However, the workspace is mid-migration — alloy-signer and alloy-signer-local remain at 1.8 (Cargo.toml:414-415) while the remote signers sit at 2.0, so `alloy-sign
  • Better / existing approach: A single coordinated PR that also bumps alloy-signer (Cargo.toml:414) and alloy-signer-local (Cargo.toml:415) from 1.8 to 2.0 would collapse the dual-major compile of alloy-signer/alloy-consensus/alloy-network in one shot, rather than leaving the 1.8/2.0 split to be chipped at one dependabot PR at a time. Checked: the split predates this PR (aws/gcp were already 2.0), so this PR is n
  • Model: opencode/zai-coding-plan/glm-5.2
  • Bridge attempts: 2
  • Bridge warning: opencode/kimi-for-coding/k2p7: opencode: opencode error

🎯 Usefulness — error

usefulness agent produced no parseable value-audit JSON.

  • Model: opencode/zai-coding-plan/glm-5.2
  • Bridge attempts: 1
  • Bridge error: no parseable JSON response

💰 Value Audit

🟡 alloy 1.8/2.0 split left half-finished; keystore is the seam [maintenance] ``

After this bump the tree compiles alloy-signer/consensus/network in two majors at once (Cargo.lock:848 vs :863, :142 vs :169, :432 vs :458), and crates/keystore/Cargo.toml:37-52 consumes both alloy-signer@1.8 (via local) and alloy-signer-ledger@2.0 under one roof. That dual-compile is bloat and a future type-mismatch hazard at the signer-integration boundary. The cleaner fix is a coordinated follow-up bumping alloy-signer and alloy-signer-local (Cargo.toml:414-415) to 2.0 to collapse


What this audit checks

It judges the change on its merits — not whether it was tasked out in an issue. Unticketed, fast-moving work is fine; the question is whether the change is good and whether a better or existing approach should be used instead.

Pass What it asks
Heuristic Vague title? Whitespace-only or cruft-bearing diff? (content signals only)
Duplication Do added function/class names already exist elsewhere in the repo?
Value Audit What does it do? What goal does it achieve? Is it good? Better architecture or already-exists?
Usefulness Audit Does it integrate and fit? Will it hold up in real use and actually get used?

Findings are concerns, not blocks — the human reviewer decides what to do with them.

value-audit · 20260803T122543Z

@tangletools

Copy link
Copy Markdown
Contributor

❌ Needs Work — 17424806

Review health 100/100 · Reviewer score 60/100 · Confidence 70/100 · 3 findings (1 critical, 1 medium, 1 low)

glm deepseek deepseek-flash aggregate
Readiness 92 82 60 60
Confidence 70 70 70 70
Correctness 92 82 60 60
Security 92 82 60 60
Testing 92 82 60 60
Architecture 92 82 60 60

Reviewer score is advisory once the run is complete and the verdict has no blockers.

Full multi-shot audit completed 2/2 planned shots over 2 changed files. Global verifier still owns final merge decision. | Full multi-shot audit completed 2/2 planned shots over 2 changed files. Global verifier still owns final merge decision. | Full multi-shot audit completed 2/2 planned shots over 2 changed files. Global verifier still owns final merge decision.

Blocking

🟣 CRITICAL alloy-signer-ledger 2.0 bump breaks compilation of the ledger remote signer (Signer trait version split) — Cargo.toml

Workspace dependency alloy-signer-ledger bumped from 1.8 to 2.0 (line 428) resolves to alloy-signer-ledger 2.0.5 in Cargo.lock, which depends on alloy-signer 2.0.5, alloy-network 2.0.5, alloy-consensus 2.0.5 (Cargo.lock ~L915-930). The workspace still pins alloy-signer=1.8, alloy-network=1.8, alloy-consensus=1.8 (Cargo.toml:414,416,418), so two versions of the same crates coexist. crates/keystore/src/remote/ledger.rs:4 does use alloy_signer::Signer; which binds to the 1.8.3 trait, but alloy-signer-ledger 2.0.5's LedgerSigner implements the 2.0.5 Signer trait (verified in ~/.cargo/registry/src/.../alloy-signer-ledger-2.0.5/src/signer.rs:90). CI clippy jobs on head commit 1742480

Other

🟠 MEDIUM Cannot verify compilation — no cargo toolchain in review environment — Cargo.toml

alloy-signer-ledger bumped from 1.8 to 2.0, but no cargo is available in this review jail to run cargo check -p blueprint-keystore --features ledger-node. The ledger.rs consumer (crates/keystore/src/remote/ledger.rs) imports use alloy_signer::Signer from the v1.8 workspace dep while LedgerSigner v2.0 internally depends on alloy-signer 2.0 — though method calls resolve to inherent methods, this should be confirmed with a compile check. CI green on the actual PR should resolve this.

🟡 LOW Duplicate alloy crate versions after ledger 2.0 bump — Cargo.toml

alloy-signer-ledger 2.0.5 hard-depends on alloy-consensus/network/signer = 2.0.5 (verified in registry Cargo.toml: [dependencies.alloy-consensus] version = "2.0.5"). The workspace still declares alloy-consensus=1.8 (line 418), alloy-network=1.8 (line 416), alloy-signer-local=1.8 (line 415). Cargo.lock now resolves two copies of each (rg -c count=2). Compiles fine but bloats dep graph and signals a partial migration. Fix: either complete the alloy-{consensus,network,s


tangletools · 2026-08-03T12:33:29Z · trace

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ 1 Blocking Finding — 17424806

Full multi-shot audit completed 2/2 planned shots over 2 changed files. Global verifier still owns final merge decision. | Full multi-shot audit completed 2/2 planned shots over 2 changed files. Global verifier still owns final merge decision. | Full multi-shot audit completed 2/2 planned shots over 2 changed files. Global verifier still owns final merge decision.

Full immutable report for this review: trace

Summary comment for this run: full summary


tangletools · 2026-08-03T12:33:29Z · immutable trace

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update Rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant