Skip to content

ci(deps): group Tauri npm and cargo bumps into one Dependabot PR; pin rmcp once - #750

Merged
EVWorth merged 1 commit into
mainfrom
claude/dependabot-tauri-group
Oct 5, 2026
Merged

EVWorth merged 1 commit into
mainfrom
claude/dependabot-tauri-group

Conversation

@EVWorth

@EVWorth EVWorth commented Oct 5, 2026

Copy link
Copy Markdown
Owner

This fixes the two Dependabot setups that kept producing PRs that can't pass.

1. Tauri: one PR for both halves

Problem: npm and cargo updates were proposed separately. A Tauri release arrived as npm-only (#745), which check-tauri-versions.sh (#747) fails and tauri build refuses. The plugin crates never moved at all: each new plugin minor requires the new tauri, and a per-ecosystem update moves one dependency at a time. #749 did this bump by hand.

Change: a tauri multi-ecosystem group in dependabot.yml:

  • Member entries: npm @tauri-apps/*, and cargo tauri, tauri-build and tauri-plugin-*. Both carry the same cooldown: 7 days, and both hold back majors, since Tauri 3 needs a migration.
  • The regular npm and cargo entries ignore those same names, so nothing is proposed twice.
  • The group's PR gets the chore(deps) prefix and the dependencies label, like the other dependency PRs.

This follows the pattern a Dependabot maintainer suggested in the feature's beta discussion (dependabot/dependabot-core#12437): dedicated member entries for the group, plus ignore on the regular entries. Another Tauri app runs the same config (hamidfzm/glyph).

2. rmcp: pinned once

Problem: rmcp was pinned exactly (=3.4.0) in both the app crate and crates/mas-mcp. Dependabot bumped only one of them in #736, twice, so the workspace couldn't resolve.

Change: the pin moves to [workspace.dependencies], and both crates use rmcp = { workspace = true }. A bump is now one edit. The exact pin stays, because it's how the seven-day rule is enforced until #225 lands. The lockfile doesn't change.

Verification

  • .github/dependabot.yml validates against SchemaStore's dependabot-2.0.json with 0 errors. That schema includes multi-ecosystem-groups, and it allows cooldown and ignore on member entries.
  • cargo metadata --locked and cargo check --locked -p mas-mcp both pass. dprint check is clean.

What I couldn't verify

  • Dependabot doesn't run on a PR. Whether the group behaves as intended shows only on the next weekly run after merge, in Insights → Dependency graph → Dependabot. Watch for a PR on a branch named dependabot/tauri-….
  • GitHub's docs don't say whether the 7-day cooldown on a member entry is honoured inside a multi-ecosystem group. The schema allows it, but if the first group PR proposes something younger than 7 days, that's why.
  • chore(deps): bump the cargo group across 1 directory with 2 updates #736 still proposes rmcp 3.5.0 for crates/mas-mcp alone. Once this merges, Dependabot should rebuild it against the workspace pin. If it doesn't, close chore(deps): bump the cargo group across 1 directory with 2 updates #736 and let the next run reopen it.

🤖 Generated with Claude Code

https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg


Generated by Claude Code

… rmcp once

Two Dependabot shapes kept producing PRs that cannot pass:

- Tauri: npm and cargo were proposed separately, so a Tauri release
  arrived as npm-only (#745), which check-tauri-versions.sh fails and
  `tauri build` refuses. The plugin crates never moved at all: each new
  plugin minor requires the new `tauri`, and a per-ecosystem update
  moves one dependency at a time. A `tauri` multi-ecosystem group now
  owns @tauri-apps/* on npm and tauri, tauri-build, tauri-plugin-* on
  cargo, so both halves land in one PR. Its member entries carry the
  same 7-day cooldown and hold back majors; the regular npm and cargo
  entries ignore those names so nothing is proposed twice.
- rmcp: pinned exactly in both the app crate and crates/mas-mcp, and
  Dependabot bumped only one (#736, twice), which cannot resolve. The
  pin moves to [workspace.dependencies]; both crates inherit it, so a
  bump is one edit. The lockfile does not change.

Checked against SchemaStore's dependabot-2.0 schema (0 errors).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg
@EVWorth
EVWorth merged commit 97e287a into main Oct 5, 2026
12 checks passed
@EVWorth
EVWorth deleted the claude/dependabot-tauri-group branch October 5, 2026 03:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants