Skip to content

chore: limit Dependabot to lockfile updates - #30

Merged
AksharP5 merged 1 commit into
mainfrom
chore/dependabot-lockfile-updates
Aug 18, 2026
Merged

chore: limit Dependabot to lockfile updates#30
AksharP5 merged 1 commit into
mainfrom
chore/dependabot-lockfile-updates

Conversation

@AksharP5

Copy link
Copy Markdown
Owner

The initial Dependabot run opened unrelated major dependency upgrades immediately after activation.

Keep routine updates inside the versions already allowed by Cargo.toml and group compatible lockfile refreshes into one weekly PR. Security alerts and the RustSec CI audit still cover vulnerable versions outside those constraints.

Validation: parsed .github/dependabot.yml successfully.

@AksharP5
AksharP5 merged commit be5dbd9 into main Aug 18, 2026
9 checks passed
@AksharP5
AksharP5 deleted the chore/dependabot-lockfile-updates branch August 18, 2026 03:48
@AksharP5 AksharP5 mentioned this pull request Aug 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant