Skip to content

Enable semiannual Dependabot updates for Cargo and GitHub Actions#296

Open
lafrenierejm wants to merge 1 commit into
phiresky:masterfrom
lafrenierejm:enable-dependabot
Open

Enable semiannual Dependabot updates for Cargo and GitHub Actions#296
lafrenierejm wants to merge 1 commit into
phiresky:masterfrom
lafrenierejm:enable-dependabot

Conversation

@lafrenierejm

Copy link
Copy Markdown
Contributor

No description provided.

@phiresky

phiresky commented Nov 9, 2025

Copy link
Copy Markdown
Owner

I'm not sure we have good enough tests to have this be useful and dependabot has a tendency to be very noisy, considering this is not an extremely active project. I'd rather only update dependencies much less frequently, maybe like 1/6months or when there's a specific reason (like security).

The interval is specifically set to semiannually to reduce the maintenance
burden of frequent dependency updates.
@lafrenierejm

Copy link
Copy Markdown
Contributor Author

I'd rather only update dependencies much less frequently, maybe like 1/6months or when there's a specific reason (like security).

@phiresky Thanks for the feedback! I have updated the schedule from weekly to semiannually.

@lafrenierejm lafrenierejm changed the title Enable Dependabot for Cargo and GitHub Actions Enable Dependabot for semiannual Cargo and GitHub Actions updates Dec 7, 2025
@lafrenierejm lafrenierejm changed the title Enable Dependabot for semiannual Cargo and GitHub Actions updates Enable semiannual Dependabot updates for Cargo and GitHub Actions Dec 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants