-
-
Notifications
You must be signed in to change notification settings - Fork 190
chore(dependabot): Add basic Dependabot config - #1283
Conversation
Keep compatible dependency versions current in Cargo.lock so CI exercises recent releases without changing the versions resolved by library users. Group minor and patch updates into one pull request while leaving major updates as individual notices because they may require user-facing compatibility review.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 2c80129. Configure here.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Cargo may reject this versioning strategy value
Medium Severity
Dependabot's schema validation for the cargo ecosystem has historically accepted only auto and lockfile-only for versioning-strategy, rejecting increase-if-necessary. A rejected value invalidates the whole file, so no update PRs are opened at all rather than just ignoring the option. Worth confirming the value validates before merging.
Reviewed by Cursor Bugbot for commit 2c80129. Configure here.
Uh oh!
There was an error while loading. Please reload this page.
I think this could be nice to have, the proposed config will update our lockfile (which only affects our CI environment) every week in a single PR, then will open separate PRs for major version bumps in
Cargo.tomlwhen these are available. We will treat the major version bumps more like notifications that we can update, but likely will often not merge these, at least not right away.