Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

0.x dependencies are never updated #725

Open
kylewillmon opened this issue Oct 7, 2022 · 1 comment
Open

0.x dependencies are never updated #725

kylewillmon opened this issue Oct 7, 2022 · 1 comment
Labels
medium priority Should be handled as soon as possible task Task or chore that is not a bug or enhancement

Comments

@kylewillmon
Copy link
Contributor

We have a weekly cargo update for minor version updates and weekly Dependabot run for major version updates. However, it turns out that neither of these handles bumping dependencies from 0.x to 0.x+1

Originally posted by @kylewillmon in #707 (comment)

@kylewillmon kylewillmon added medium priority Should be handled as soon as possible task Task or chore that is not a bug or enhancement labels Oct 12, 2022
@kylewillmon
Copy link
Contributor Author

Thanks to #889, we now know that Dependabot will update these minor versions if there is a security alert on the package.

This issue remains relevant, but that is at least a little bit of comfort.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
medium priority Should be handled as soon as possible task Task or chore that is not a bug or enhancement
Projects
None yet
Development

No branches or pull requests

1 participant