Skip to content

Enable semiannual Dependabot updates for Cargo and GitHub Actions#296

Open
lafrenierejm wants to merge 1 commit intophiresky:masterfrom
lafrenierejm:enable-dependabot
Open

Enable semiannual Dependabot updates for Cargo and GitHub Actions#296
lafrenierejm wants to merge 1 commit intophiresky:masterfrom
lafrenierejm:enable-dependabot

Conversation

@lafrenierejm
Copy link
Copy Markdown
Contributor

No description provided.

@phiresky
Copy link
Copy Markdown
Owner

phiresky commented Nov 9, 2025

I'm not sure we have good enough tests to have this be useful and dependabot has a tendency to be very noisy, considering this is not an extremely active project. I'd rather only update dependencies much less frequently, maybe like 1/6months or when there's a specific reason (like security).

The interval is specifically set to semiannually to reduce the maintenance
burden of frequent dependency updates.
@lafrenierejm
Copy link
Copy Markdown
Contributor Author

I'd rather only update dependencies much less frequently, maybe like 1/6months or when there's a specific reason (like security).

@phiresky Thanks for the feedback! I have updated the schedule from weekly to semiannually.

@lafrenierejm lafrenierejm changed the title Enable Dependabot for Cargo and GitHub Actions Enable Dependabot for semiannual Cargo and GitHub Actions updates Dec 7, 2025
@lafrenierejm lafrenierejm changed the title Enable Dependabot for semiannual Cargo and GitHub Actions updates Enable semiannual Dependabot updates for Cargo and GitHub Actions Dec 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants