From dc1f7195f9ec65ef0a9cb46ca0dd56c004f7fe1c Mon Sep 17 00:00:00 2001 From: Ray Walker Date: Wed, 30 Sep 2026 19:32:23 +1000 Subject: [PATCH 1/3] fix(deps): hold getrandom at 0.2 out of the non-major Renovate group getrandom 0.3 removed the js feature. The direct 0.2 entry exists to turn that feature on for the getrandom 0.2 copy that ring and rand_core also use on wasm32, so a bump past 0.2 fails the Cargo.lock update and blocks every other update in the all-minor-patch group. Take such an update out of the group and hold it under Pending Approval on the Dependency Dashboard. Vulnerability updates are not held: Renovate forces dependencyDashboardApproval off for them. Patch updates within 0.2 stay in the group. --- renovate.json | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/renovate.json b/renovate.json index eb7ac3b..63ddc09 100644 --- a/renovate.json +++ b/renovate.json @@ -1,4 +1,14 @@ { "$schema": "https://docs.renovatebot.com/renovate-schema.json", - "extends": ["local>cachekit-io/renovate-config"] + "extends": ["local>cachekit-io/renovate-config"], + "packageRules": [ + { + "description": "Hold getrandom at 0.2. The direct 0.2 entry turns on the js feature for the getrandom 0.2 copy that ring and rand_core also use on wasm32, and getrandom 0.3 removed that feature. A bump past 0.2 fails the Cargo.lock update and takes the whole non-major group down with it, so it waits under Pending Approval on the Dependency Dashboard instead. Vulnerability updates are not held: Renovate forces dependencyDashboardApproval off for them. Drop this rule once nothing in Cargo.lock depends on getrandom 0.2.", + "matchManagers": ["cargo"], + "matchPackageNames": ["getrandom"], + "matchUpdateTypes": ["minor", "major"], + "groupName": null, + "dependencyDashboardApproval": true + } + ] } From 3ca929376a6e6511dd20a203aebf2be3942f5203 Mon Sep 17 00:00:00 2001 From: Ray Walker Date: Wed, 30 Sep 2026 19:43:29 +1000 Subject: [PATCH 2/3] chore(deps): give cargo 0.x minor bumps their own Renovate PR Cargo treats a 0.x minor bump as semver-incompatible, but Renovate classes it as minor and puts it in the all-minor-patch group. Holding getrandom was not enough: reqwest 0.12 to 0.13 removed the rustls-tls feature and fails the same Cargo.lock update, and other 0.x bumps in the group raise rust-version past 1.85 or change APIs. Give every cargo 0.x minor update its own PR so one breaking bump no longer blocks the routine ones. 0.x patch updates stay in the group; the getrandom hold stays on top. --- renovate.json | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/renovate.json b/renovate.json index 63ddc09..a0fefe8 100644 --- a/renovate.json +++ b/renovate.json @@ -3,7 +3,14 @@ "extends": ["local>cachekit-io/renovate-config"], "packageRules": [ { - "description": "Hold getrandom at 0.2. The direct 0.2 entry turns on the js feature for the getrandom 0.2 copy that ring and rand_core also use on wasm32, and getrandom 0.3 removed that feature. A bump past 0.2 fails the Cargo.lock update and takes the whole non-major group down with it, so it waits under Pending Approval on the Dependency Dashboard instead. Vulnerability updates are not held: Renovate forces dependencyDashboardApproval off for them. Drop this rule once nothing in Cargo.lock depends on getrandom 0.2.", + "description": "Cargo treats a 0.x minor bump (0.12 to 0.13) as semver-incompatible, the same as a major, but Renovate classes it as minor, so it lands in the non-major group. There one such bump can break the whole group: a removed feature fails the Cargo.lock update, and an API change or a higher rust-version fails CI. Each such update gets its own PR instead. 0.x patch updates stay in the group.", + "matchManagers": ["cargo"], + "matchCurrentVersion": "<1.0.0", + "matchUpdateTypes": ["minor"], + "groupName": null + }, + { + "description": "Hold getrandom at 0.2. The direct 0.2 entry turns on the js feature for the getrandom 0.2 copy that ring and rand_core also use on wasm32, and getrandom 0.3 removed that feature, so a bump past 0.2 fails the Cargo.lock update. It waits under Pending Approval on the Dependency Dashboard instead of opening a PR that cannot pass. Vulnerability updates are not held: Renovate forces dependencyDashboardApproval off for them. Drop this rule once nothing in Cargo.lock depends on getrandom 0.2.", "matchManagers": ["cargo"], "matchPackageNames": ["getrandom"], "matchUpdateTypes": ["minor", "major"], From 778a58e77dd0e91b5bd32a1305712a01e327691a Mon Sep 17 00:00:00 2001 From: Ray Walker Date: Wed, 30 Sep 2026 19:57:55 +1000 Subject: [PATCH 3/3] chore(deps): hold generic-array at 0.14.7 for Renovate crypto-common 0.1 pins generic-array to exactly 0.14.7, so Renovate's 0.14.9 lock file update cannot resolve. Renovate runs every lock file update in a group as one cargo chain, so this one failure would fail the whole all-minor-patch group. Hold it under Pending Approval instead. --- renovate.json | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/renovate.json b/renovate.json index a0fefe8..bc8c38e 100644 --- a/renovate.json +++ b/renovate.json @@ -16,6 +16,14 @@ "matchUpdateTypes": ["minor", "major"], "groupName": null, "dependencyDashboardApproval": true + }, + { + "description": "Hold generic-array at 0.14.7. crypto-common 0.1, which the RustCrypto 0.10 crates depend on, pins generic-array to exactly 0.14.7, so any other 0.14.x fails the Cargo.lock update and takes the whole non-major group with it. It waits under Pending Approval on the Dependency Dashboard instead. Vulnerability updates are not held. Drop this rule once nothing in Cargo.lock depends on crypto-common 0.1.", + "matchManagers": ["cargo"], + "matchPackageNames": ["generic-array"], + "matchUpdateTypes": ["patch"], + "groupName": null, + "dependencyDashboardApproval": true } ] }