Skip to content

chore(deps): never automerge cargo dev-dependency updates (LAB-6713) - #94

Merged
27Bslash6 merged 2 commits into
mainfrom
lab-6713-no-dev-dep-automerge
Sep 30, 2026
Merged

27Bslash6 merged 2 commits into
mainfrom
lab-6713-no-dev-dep-automerge

Conversation

@27Bslash6

@27Bslash6 27Bslash6 commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

This PR updates the Renovate configuration so that no cargo dev-dependency update is merged automatically. Every such update now waits for a human to merge it.

Change (renovate.json)

The last packageRules entry is changed in place:

Field Before After
Matcher "matchPackageNames": ["serde_json"] "matchDepTypes": ["dev-dependencies"]
matchManagers ["cargo"] ["cargo"] (unchanged)
automerge false false (unchanged)
description serde_json-specific reason general dev-dependency reason, plus a note to keep the rule last

There are no code, API, or build changes. The change affects only how Renovate handles its PRs.

Functional impact

  • The rule used to cover only serde_json. It now covers every cargo dev-dependency. serde_json is a dev-dependency, so it is still covered and the old rule is no longer needed.
  • These updates were previously automerged but will now wait for a human:
    • minor and patch dev-dependency updates in the shared preset's rust-dev-deps group
    • standalone dev-dependency updates such as criterion
  • Runtime dependency updates are unchanged.

Rationale (from the rule description)

  • cargo vet no longer holds these updates back. Crates whose publisher is trusted in supply-chain/audits.toml pass cargo vet without a per-version review, so a failing vet check can no longer stop them.
  • Dev-dependency bumps can change runtime dependencies. Dev and runtime dependencies share one Cargo.lock, so a dev-dependency bump can move a runtime dependency.

Maintenance note

The rule must stay last in packageRules. Renovate applies matching rules in order, and a later rule's keys replace an earlier one's. Any rule added after this one that sets automerge: true would override it. The rule's description now says this, so future editors see the constraint.


This PR updates the description of an existing Renovate rule. The rule's behavior does not change. The only edit is the description field of the Cargo dev-dependency rule in renovate.json.

Summary

The rule's settings stay the same:

  • matchManagers: ["cargo"]
  • matchDepTypes: ["dev-dependencies"]
  • automerge: false

The revised description now explains:

  • Why the rule exists: it overrides the shared Renovate preset. That preset automerges Cargo dev-dependency updates through its rust-dev-deps group and its dev-dependency rule.
  • Why it applies to all dev-dependencies: publishers trusted in supply-chain/audits.toml pass cargo vet without per-version review. Any dev-dependency update can also move a runtime dependency in the shared Cargo.lock. The rule therefore matches every dev-dependency, not only the trusted crates, and a human merges each update.
  • Ordering constraint: the rule must stay last in this file. Any later rule in the file that sets automerge would override it.

Impact

  • There are no changes to public APIs, code, or dependency resolution.
  • The added documentation makes it less likely that someone reorders or loosens the rule and re-enables automerge for dev-dependency updates by accident.

Trusted publishers now pass cargo vet with no per-version entry, and a dev-dependency update can move a runtime dependency in the shared Cargo.lock. Widen the serde_json-only automerge:false rule to every cargo dev-dependency so a human merges each one.
@kodus-27b

kodus-27b Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 52 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: cachekit-io/cachekit-core/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 50b1865f-cbeb-498e-9d82-60f2b7c2ea3d

📥 Commits

Reviewing files that changed from the base of the PR and between 204d346 and 120e160.

📒 Files selected for processing (1)
  • renovate.json

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: cachekit-io/cachekit-core/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 8fc3ad30-0bd8-45cd-8c26-b815f3ec61f6

📥 Commits

Reviewing files that changed from the base of the PR and between a186355 and 204d346.

📒 Files selected for processing (1)
  • renovate.json

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

The final Cargo rule in renovate.json now disables automerging for all dev-dependency updates. Its description covers the stated lockfile concern and says to keep the rule last.

Changes

Renovate configuration

Layer / File(s) Summary
Cargo dev-dependency automerge rule
renovate.json
The final Cargo rule now matches all dev-dependencies instead of only serde_json. automerge remains false, and the description says to keep the rule last.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: Cargo dev-dependency updates will not be automerged. The ticket reference is relevant and does not reduce clarity.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

kodus-27b[bot]
kodus-27b Bot previously approved these changes Sep 30, 2026
coderabbitai[bot]
coderabbitai Bot previously approved these changes Sep 30, 2026
…st (LAB-6713)

The description now names the preset automerge it overrides, says it matches every dev-dependency on purpose, and scopes the keep-last note to this file.
@kodus-27b

kodus-27b Bot commented Sep 30, 2026

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

@27Bslash6
27Bslash6 merged commit 757c9d0 into main Sep 30, 2026
33 checks passed
@27Bslash6
27Bslash6 deleted the lab-6713-no-dev-dep-automerge branch September 30, 2026 15:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant