Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 23 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,29 @@ updates:
groups:
cargo-pcai-core:
update-types: ["minor", "patch"]
ignore:
# sha2 is held on the 0.10 line. RustCrypto 0.11 moves digest output
# from generic-array::GenericArray to hybrid-array::Array, which does
# not implement LowerHex, so every `format!("{:x}", hasher.finalize())`
# stops compiling -- three call sites here (pcai_core_lib hash.rs and
# search/duplicates.rs, pcai_perf_cli main.rs). Dependabot raised
# 0.10.9 -> 0.11.0 as #84; it failed to build.
#
# The bump also would not consolidate anything: cudaforge and
# openai-harmony still require 0.10, so taking 0.11 directly compiles
# two SHA-2 implementations instead of one. 0.10.9 carries no advisory.
# Revisit when the 0.11 line has reached the rest of the tree, as a
# deliberate migration rather than a bump.
#
# Expressed as a version range, not `update-types:
# version-update:semver-major`. Dependabot classifies an update by which
# SemVer *component* changed, and 0.10.9 -> 0.11.0 changes the minor
# component -- the major component stays 0. A semver-major ignore would
# therefore never match this bump, and because cargo-pcai-core groups
# minor and patch, the broken update could be folded into the grouped PR
# and block an otherwise good batch. A range cannot be misclassified.
- dependency-name: "sha2"
versions: [">=0.11.0"]
labels:
- "dependencies"
- "rust"
Expand Down
Loading