chore(deps): never automerge cargo dev-dependency updates (LAB-6713) - #94
Conversation
Trusted publishers now pass cargo vet with no per-version entry, and a dev-dependency update can move a runtime dependency in the shared Cargo.lock. Widen the serde_json-only automerge:false rule to every cargo dev-dependency so a human merges each one.
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 52 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configurationConfiguration used: Repository: cachekit-io/cachekit-core/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: cachekit-io/cachekit-core/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. WalkthroughThe final Cargo rule in ChangesRenovate configuration
Priority: ➖ Normal Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Other 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…st (LAB-6713) The description now names the preset automerge it overrides, says it matches every dev-dependency on purpose, and scopes the keep-last note to this file.
120e160
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
This PR updates the Renovate configuration so that no cargo dev-dependency update is merged automatically. Every such update now waits for a human to merge it.
Change (
renovate.json)The last
packageRulesentry is changed in place:"matchPackageNames": ["serde_json"]"matchDepTypes": ["dev-dependencies"]matchManagers["cargo"]["cargo"](unchanged)automergefalsefalse(unchanged)descriptionThere are no code, API, or build changes. The change affects only how Renovate handles its PRs.
Functional impact
rust-dev-depsgroupRationale (from the rule description)
cargo vetno longer holds these updates back. Crates whose publisher is trusted insupply-chain/audits.tomlpasscargo vetwithout a per-version review, so a failing vet check can no longer stop them.Cargo.lock, so a dev-dependency bump can move a runtime dependency.Maintenance note
The rule must stay last in
packageRules. Renovate applies matching rules in order, and a later rule's keys replace an earlier one's. Any rule added after this one that setsautomerge: truewould override it. The rule's description now says this, so future editors see the constraint.This PR updates the description of an existing Renovate rule. The rule's behavior does not change. The only edit is the
descriptionfield of the Cargo dev-dependency rule inrenovate.json.Summary
The rule's settings stay the same:
matchManagers: ["cargo"]matchDepTypes: ["dev-dependencies"]automerge: falseThe revised description now explains:
rust-dev-depsgroup and its dev-dependency rule.supply-chain/audits.tomlpasscargo vetwithout per-version review. Any dev-dependency update can also move a runtime dependency in the sharedCargo.lock. The rule therefore matches every dev-dependency, not only the trusted crates, and a human merges each update.automergewould override it.Impact