From 68b2f7329833f8f68aee7d66104e50ce8477844f Mon Sep 17 00:00:00 2001 From: Jolyon Suthers <201621+fenrick@users.noreply.github.com> Date: Thu, 10 Sep 2026 10:33:53 +1000 Subject: [PATCH 1/2] ci: add Dependabot version updates for cargo and actions MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Covers both ecosystems in play: the Rust crates in Cargo.toml and the actions the workflows use. Updates are grouped, so a week's worth arrives as one pull request per ecosystem rather than one per dependency — three separate pull requests appeared within minutes of this repository existing, which is not a review rate anyone sustains. Security updates are grouped separately so they are never queued behind an ordinary version bump. Commit prefixes are set deliberately. Releases are generated from commit messages, so an unprefixed dependency bump would be left out of the changelog entirely. Cargo updates commit as `fix(deps):` and appear under Fixed; action updates commit as `ci(deps):` and are recorded but hidden. --- .github/dependabot.yml | 63 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 63 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..e15a565 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,63 @@ +# Dependabot version updates. +# +# Two ecosystems are in play: the Rust crates in Cargo.toml, and the actions +# used by the workflows. Both are grouped, so a week's updates arrive as one +# pull request per ecosystem rather than one per dependency. +# +# Commit prefixes matter here. Releases are generated from commit messages by +# release-please, so an unprefixed commit is silently left out of the +# changelog. `fix` puts a dependency bump under "Fixed" and moves the patch +# version; `ci` is recorded but hidden, which is right for a workflow-only +# change. See CONTRIBUTING.md. +# +# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file + +version: 2 + +updates: + - package-ecosystem: "cargo" + directory: "/" + schedule: + interval: "weekly" + day: "monday" + time: "06:00" + timezone: "Australia/Brisbane" + open-pull-requests-limit: 5 + labels: + - "dependencies" + commit-message: + prefix: "fix" + include: "scope" + groups: + # Non-breaking updates travel together; there is no value in reviewing + # them one at a time. + rust-dependencies: + applies-to: version-updates + update-types: + - "minor" + - "patch" + # Security fixes are grouped separately so they are never queued behind + # an ordinary version bump. + rust-security: + applies-to: security-updates + patterns: + - "*" + + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" + day: "monday" + time: "06:00" + timezone: "Australia/Brisbane" + open-pull-requests-limit: 5 + labels: + - "dependencies" + commit-message: + prefix: "ci" + include: "scope" + groups: + github-actions: + applies-to: version-updates + patterns: + - "*" From 17bc7898fe4f921590b374adda83bde1207a43ab Mon Sep 17 00:00:00 2001 From: Jolyon Suthers <201621+fenrick@users.noreply.github.com> Date: Thu, 10 Sep 2026 10:33:53 +1000 Subject: [PATCH 2/2] ci: retire Renovate in favour of Dependabot Running both bots means two pull requests for every update, each with its own branch, its own CI run and its own changelog entry if both are merged. Dependabot is the one being kept. Removing this file stops Renovate acting on its own configuration, but the GitHub App installation is an account-level setting and has to be removed separately, under Settings, GitHub Apps. Until that is done Renovate will fall back to its default behaviour rather than stopping. --- renovate.json | 31 ------------------------------- 1 file changed, 31 deletions(-) delete mode 100644 renovate.json diff --git a/renovate.json b/renovate.json deleted file mode 100644 index 0afad54..0000000 --- a/renovate.json +++ /dev/null @@ -1,31 +0,0 @@ -{ - "$schema": "https://docs.renovatebot.com/renovate-schema.json", - "extends": ["config:recommended", ":semanticCommits"], - "schedule": ["before 6am on monday"], - "dependencyDashboard": true, - "packageRules": [ - { - "description": "One pull request for every GitHub Actions update.", - "matchManagers": ["github-actions"], - "groupName": "github actions", - "semanticCommitType": "ci" - }, - { - "description": "One pull request for all non-breaking Rust dependency updates.", - "matchManagers": ["cargo"], - "matchUpdateTypes": ["minor", "patch"], - "groupName": "rust dependencies", - "semanticCommitType": "fix" - }, - { - "description": "A breaking Rust update stays on its own, so it is reviewed on its own.", - "matchManagers": ["cargo"], - "matchUpdateTypes": ["major"], - "semanticCommitType": "fix" - } - ], - "lockFileMaintenance": { - "enabled": true, - "schedule": ["before 6am on the first day of the month"] - } -}