Aligns baibot's direct reqwest dep with the 0.13 copy that
async-openai/matrix-sdk/mxlink already pull, instead of the lone 0.12
copy kept alive only by the anthropic fork. 0.13 renamed the
`rustls-tls` feature to `rustls`; update the feature list accordingly.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The anthropic git dependency now uses reqwest 0.12 / rustls 0.23, pulling
rustls-webpki 0.103.13 instead of the 0.101.7 that was dragged in via the
old reqwest 0.11. This clears three RUSTSEC/Dependabot advisories:
- GHSA-82j2-j2ch-gfr8 (high): DoS via panic on malformed CRL BIT STRING
- GHSA-xgp8-3hg3-c2mh (low): name constraints accepted for wildcard names
- GHSA-965h-392x-2mh5 (low): name constraints for URI names incorrectly accepted
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Adapt to upstream API changes:
- Handle the new ImageModel::GptImage2 variant in image-model match arms
- ImageSize dropped Copy (gained an Other(String) variant), so clone it
Supersedes #170.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
matrix-sdk 0.18.0 introduces no breaking changes that affect baibot, but
it does require a matching mxlink release: mxlink 1.14.0 pins matrix-sdk
0.17.0, so without bumping mxlink the two matrix-sdk versions conflict.
mxlink 1.15.0 (released alongside this) tracks matrix-sdk 0.18.0, so we
bump the floor to >=1.15.0.
Verified locally: cargo build and the full test suite pass.
Supersedes Renovate PR #161.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Closes#137. The 0.36 -> 0.38 bump (skipping 0.37) introduces Tower-based
middleware support and a fix to the ReasoningItem `type` field, but
neither affects baibot's call sites — no code adaptation was needed.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
matrix-sdk 0.17.0 brings a few breaking API changes that we adapt to:
- Drop the `native-tls` feature on matrix-sdk; it was removed upstream
in 2026-04 (matrix-sdk now hardwires rustls). The previous workaround
comment referencing rust-mxlink issue #1 is no longer relevant.
- `Relation::Reply` is now a tuple variant wrapping a `Reply` struct;
pattern matches updated to bind through `reply.in_reply_to.event_id`.
Also bumps the Rust toolchain from 1.93.0 to 1.95.0 (closes#85, which
proposed the Dockerfile bump in isolation). rustc 1.94+ trips a
query-depth overflow when computing async layouts in the matrix-sdk
timeline future graph; matrix-rust-sdk PR #6489 raises the limit, but
\`recursion_limit\` is per-crate, so we repeat \`#![recursion_limit = "256"]\`
on this crate root.
Bumps the mxlink floor to 1.14.0, which carries the matching adapter.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>