Aligns baibot's direct reqwest dep with the 0.13 copy that
async-openai/matrix-sdk/mxlink already pull, instead of the lone 0.12
copy kept alive only by the anthropic fork. 0.13 renamed the
`rustls-tls` feature to `rustls`; update the feature list accordingly.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The anthropic git dependency now uses reqwest 0.12 / rustls 0.23, pulling
rustls-webpki 0.103.13 instead of the 0.101.7 that was dragged in via the
old reqwest 0.11. This clears three RUSTSEC/Dependabot advisories:
- GHSA-82j2-j2ch-gfr8 (high): DoS via panic on malformed CRL BIT STRING
- GHSA-xgp8-3hg3-c2mh (low): name constraints accepted for wildcard names
- GHSA-965h-392x-2mh5 (low): name constraints for URI names incorrectly accepted
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- Avoid unwrap_or() on a statically-Some value by using the raw token count
- Use an array literal instead of vec! for the non-allocated test cases
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Make gpt-image-2 the default image-generation model and add it to the
recognized model-id mapping, updating the sample provider configs to match.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Adapt to upstream API changes:
- Handle the new ImageModel::GptImage2 variant in image-model match arms
- ImageSize dropped Copy (gained an Other(String) variant), so clone it
Supersedes #170.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
matrix-sdk 0.18.0 introduces no breaking changes that affect baibot, but
it does require a matching mxlink release: mxlink 1.14.0 pins matrix-sdk
0.17.0, so without bumping mxlink the two matrix-sdk versions conflict.
mxlink 1.15.0 (released alongside this) tracks matrix-sdk 0.18.0, so we
bump the floor to >=1.15.0.
Verified locally: cargo build and the full test suite pass.
Supersedes Renovate PR #161.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Bumps the base image in Dockerfile/Dockerfile.ci (via Renovate #158) and
keeps rust-toolchain.toml in sync, since rustup honors the toolchain file
inside the container build and would otherwise keep using 1.95.0.
Verified locally under 1.96.0: cargo check, clippy -D warnings, fmt check,
and cargo test --all-features all pass.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>