Skip to content

chore(dependabot): Add basic Dependabot config - #1283

Open
szokeasaurusrex wants to merge 1 commit into
masterfrom
chore/dependabot-cargo-updates
Open

chore(dependabot): Add basic Dependabot config#1283
szokeasaurusrex wants to merge 1 commit into
masterfrom
chore/dependabot-cargo-updates

Conversation

@szokeasaurusrex

@szokeasaurusrex szokeasaurusrex commented Aug 6, 2026

Copy link
Copy Markdown
Member

I think this could be nice to have, the proposed config will update our lockfile (which only affects our CI environment) every week in a single PR, then will open separate PRs for major version bumps in Cargo.toml when these are available. We will treat the major version bumps more like notifications that we can update, but likely will often not merge these, at least not right away.

Keep compatible dependency versions current in Cargo.lock so CI exercises recent releases without changing the versions resolved by library users. Group minor and patch updates into one pull request while leaving major updates as individual notices because they may require user-facing compatibility review.
@szokeasaurusrex
szokeasaurusrex requested a review from a team as a code owner August 6, 2026 08:34
@szokeasaurusrex szokeasaurusrex changed the title build(dependabot): Configure grouped Cargo dependency updates chore(dependabot): Add basic Dependabot config Aug 6, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 2c80129. Configure here.

Comment thread .github/dependabot.yml
schedule:
interval: weekly
# Avoid changing Cargo.toml when the existing requirement allows the update.
versioning-strategy: increase-if-necessary

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cargo may reject this versioning strategy value

Medium Severity

Dependabot's schema validation for the cargo ecosystem has historically accepted only auto and lockfile-only for versioning-strategy, rejecting increase-if-necessary. A rejected value invalidates the whole file, so no update PRs are opened at all rather than just ignoring the option. Worth confirming the value validates before merging.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 2c80129. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants