Skip to content

0.x dependencies are never updated #725

Description

@kylewillmon

We have a weekly cargo update for minor version updates and weekly Dependabot run for major version updates. However, it turns out that neither of these handles bumping dependencies from 0.x to 0.x+1

Originally posted by @kylewillmon in #707 (comment)

Activity

  1. added
    medium priorityShould be handled as soon as possible
    taskTask or chore that is not a bug or enhancement
    on Oct 12, 2022
  2. kylewillmon commented on Jan 3, 2023

    @kylewillmon
    ContributorAuthor

    Thanks to #889, we now know that Dependabot will update these minor versions if there is a security alert on the package.

    This issue remains relevant, but that is at least a little bit of comfort.

  3. kylewillmon commented on Dec 26, 2024

    @kylewillmon
    ContributorAuthor

    A bit of a workaround here is to periodically use cargo's unstable update-breaking feature to make sure we're using the latest version possible:

    cargo +nightly -Zunstable-options update --breaking
    
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    medium priorityShould be handled as soon as possibletaskTask or chore that is not a bug or enhancement

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions