From 204d3469830fc7f21e46de690acbe76ec44318af Mon Sep 17 00:00:00 2001 From: Ray Walker Date: Thu, 1 Oct 2026 01:20:10 +1000 Subject: [PATCH 1/2] chore(deps): never automerge cargo dev-dependency updates (LAB-6713) Trusted publishers now pass cargo vet with no per-version entry, and a dev-dependency update can move a runtime dependency in the shared Cargo.lock. Widen the serde_json-only automerge:false rule to every cargo dev-dependency so a human merges each one. --- renovate.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/renovate.json b/renovate.json index f20034a..78f171c 100644 --- a/renovate.json +++ b/renovate.json @@ -26,9 +26,9 @@ "dependencyDashboardApproval": true }, { - "description": "serde_json never automerges. Its publisher is trusted in supply-chain/audits.toml, so cargo vet passes its new releases with no per-version review, and the serde_core it resolves is a runtime dependency. A human merges every serde_json update.", + "description": "Cargo dev-dependency updates never automerge in this repo. Crates whose publisher is trusted in supply-chain/audits.toml pass cargo vet with no per-version review, and a dev-dependency update can move a runtime dependency in Cargo.lock, so a human merges every one. Keep this rule last: a later rule that sets automerge would override it.", "matchManagers": ["cargo"], - "matchPackageNames": ["serde_json"], + "matchDepTypes": ["dev-dependencies"], "automerge": false } ] From 120e1609b438376a93125082f12fd59c0e2e680a Mon Sep 17 00:00:00 2001 From: Ray Walker Date: Thu, 1 Oct 2026 01:27:40 +1000 Subject: [PATCH 2/2] chore(deps): say why the dev-dependency automerge rule is wide and last (LAB-6713) The description now names the preset automerge it overrides, says it matches every dev-dependency on purpose, and scopes the keep-last note to this file. --- renovate.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/renovate.json b/renovate.json index 78f171c..3eaaa78 100644 --- a/renovate.json +++ b/renovate.json @@ -26,7 +26,7 @@ "dependencyDashboardApproval": true }, { - "description": "Cargo dev-dependency updates never automerge in this repo. Crates whose publisher is trusted in supply-chain/audits.toml pass cargo vet with no per-version review, and a dev-dependency update can move a runtime dependency in Cargo.lock, so a human merges every one. Keep this rule last: a later rule that sets automerge would override it.", + "description": "Cargo dev-dependency updates never automerge in this repo. This overrides the shared preset, which automerges them through its rust-dev-deps group and its dev-dependency rule. Crates whose publisher is trusted in supply-chain/audits.toml pass cargo vet with no per-version review, and any dev-dependency update can move a runtime dependency in the shared Cargo.lock. So the rule matches every dev-dependency, not only the trusted crates, and a human merges each one. Keep this rule last in this file: a later rule here that sets automerge would override it.", "matchManagers": ["cargo"], "matchDepTypes": ["dev-dependencies"], "automerge": false