Skip to content

fix(deps): limit Dependabot Cargo update scope - #242

Closed
decofe wants to merge 1 commit into
mainfrom
centaur/fix-dependabot-cargo-updates-1791219679
Closed

decofe wants to merge 1 commit into
mainfrom
centaur/fix-dependabot-cargo-updates-1791219679

Conversation

@decofe

@decofe decofe commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Reduce Dependabot's Cargo update workload by allowing only direct dependencies. The all-dependency setting introduced in the earlier update can exceed the 55-minute job limit, as observed in Foundry's Cargo run. Schedules, groups, cooldowns and non-Cargo updates are unchanged; indirect dependencies will no longer be standalone version-update candidates.

Prompted by: @DaniPopes

Restrict version-update candidates to direct dependencies to reduce
Cargo scan workload and avoid whole-lockfile update timeouts.

Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>
@decofe decofe closed this Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants