CI previously re-implemented a subset of the prek hooks by hand (`cargo
test` + a bare `cargo clippy`), so `cargo fmt --check` and the stricter
`cargo clippy -- -D warnings` were enforced only by the local pre-commit
hook — easily bypassed with --no-verify (as PR #193 was). Run the same
prek suite CI-side so .pre-commit-config.yaml is the single source of
truth for what gets checked, on both commit and push.
Also drop the hard-coded `dtolnay/rust-toolchain@1.93.0` pin (which had
drifted from rust-toolchain.toml's 1.96.0) in favor of
actions-rust-lang/setup-rust-toolchain, which reads the toolchain version
and components from rust-toolchain.toml — so CI's rustfmt/clippy match
what developers run, and there is no second place to keep in sync. All
three actions are tag-pinned, so Renovate can manage them (unlike the
branch-pinned dtolnay ref).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The squashed thinking-notice PR was committed with --no-verify, so three
files were never run through `cargo fmt` under the project's pinned
toolchain (rust-toolchain.toml = 1.96.0). Format them so `cargo fmt
--all -- --check` passes — a prerequisite for wiring the prek suite
(which includes that check) into CI in the next commit.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Opt-in 💭 thinking-notice for slow text generation, plus a fix making Venice unsupported-field auto-recovery survive the per-message controller rebuild. Prepares 1.24.0.
Co-authored-by: Aine <aine@etke.cc>
Correct the 1.23.0 release date to 2026-06-23 and document the
system-CA-trust fix (2888cb9, via etke_openai_api_rust 0.1.10) that also
ships in this release.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
0.1.10 enables ureq's `native-certs` feature, so the OpenAI-compatible
provider trusts the system CA store (honouring SSL_CERT_FILE) instead of
only the bundled webpki-roots. Without it, endpoints behind a private or
internal CA (FreeIPA, org PKI) fail the TLS handshake with "invalid peer
certificate: UnknownIssuer".
Fixes#188.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Aligns baibot's direct reqwest dep with the 0.13 copy that
async-openai/matrix-sdk/mxlink already pull, instead of the lone 0.12
copy kept alive only by the anthropic fork. 0.13 renamed the
`rustls-tls` feature to `rustls`; update the feature list accordingly.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The anthropic git dependency now uses reqwest 0.12 / rustls 0.23, pulling
rustls-webpki 0.103.13 instead of the 0.101.7 that was dragged in via the
old reqwest 0.11. This clears three RUSTSEC/Dependabot advisories:
- GHSA-82j2-j2ch-gfr8 (high): DoS via panic on malformed CRL BIT STRING
- GHSA-xgp8-3hg3-c2mh (low): name constraints accepted for wildcard names
- GHSA-965h-392x-2mh5 (low): name constraints for URI names incorrectly accepted
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>