Bump the `rand` dev-dependency to the latest (0.10), which exposes rand_core
0.10, while the latest `rsa` (0.9) still requires an rand_core 0.6 RNG for key
generation. Bridge the skew with a small, test-only adapter instead of pinning
rand back.
* Add `rand_core_06 = { package = "rand_core", version = "0.6" }` so the shim
can implement the old traits (cargo unifies it with the rand_core 0.6 that
rsa already uses).
* `RandCompat<R>` wraps a modern RNG and re-implements rand_core 0.6's RngCore
+ CryptoRng over it, delegating to rand_core 0.10's infallible methods.
Implementing both satisfies rand_core 0.6's blanket CryptoRngCore impl, which
is exactly the bound rsa keygen requires.
* The CryptoRng bound is preserved (only wraps RNGs still marked
cryptographically secure), so the randomness is not weakened — it is purely a
trait-version shim. Tests now use `RandCompat(rand::rng())`.
46 tests pass (incl. the RSA-based EPUB roundtrips that exercise the shim);
clippy + rustfmt clean.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>