ci(deps): group Tauri npm and cargo bumps into one Dependabot PR; pin rmcp once - #750
Merged
Merged
Conversation
… rmcp once Two Dependabot shapes kept producing PRs that cannot pass: - Tauri: npm and cargo were proposed separately, so a Tauri release arrived as npm-only (#745), which check-tauri-versions.sh fails and `tauri build` refuses. The plugin crates never moved at all: each new plugin minor requires the new `tauri`, and a per-ecosystem update moves one dependency at a time. A `tauri` multi-ecosystem group now owns @tauri-apps/* on npm and tauri, tauri-build, tauri-plugin-* on cargo, so both halves land in one PR. Its member entries carry the same 7-day cooldown and hold back majors; the regular npm and cargo entries ignore those names so nothing is proposed twice. - rmcp: pinned exactly in both the app crate and crates/mas-mcp, and Dependabot bumped only one (#736, twice), which cannot resolve. The pin moves to [workspace.dependencies]; both crates inherit it, so a bump is one edit. The lockfile does not change. Checked against SchemaStore's dependabot-2.0 schema (0 errors). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This fixes the two Dependabot setups that kept producing PRs that can't pass.
1. Tauri: one PR for both halves
Problem: npm and cargo updates were proposed separately. A Tauri release arrived as npm-only (#745), which
check-tauri-versions.sh(#747) fails andtauri buildrefuses. The plugin crates never moved at all: each new plugin minor requires the newtauri, and a per-ecosystem update moves one dependency at a time. #749 did this bump by hand.Change: a
taurimulti-ecosystem group independabot.yml:@tauri-apps/*, and cargotauri,tauri-buildandtauri-plugin-*. Both carry the samecooldown: 7days, and both hold back majors, since Tauri 3 needs a migration.ignorethose same names, so nothing is proposed twice.chore(deps)prefix and thedependencieslabel, like the other dependency PRs.This follows the pattern a Dependabot maintainer suggested in the feature's beta discussion (dependabot/dependabot-core#12437): dedicated member entries for the group, plus
ignoreon the regular entries. Another Tauri app runs the same config (hamidfzm/glyph).2. rmcp: pinned once
Problem:
rmcpwas pinned exactly (=3.4.0) in both the app crate andcrates/mas-mcp. Dependabot bumped only one of them in #736, twice, so the workspace couldn't resolve.Change: the pin moves to
[workspace.dependencies], and both crates usermcp = { workspace = true }. A bump is now one edit. The exact pin stays, because it's how the seven-day rule is enforced until #225 lands. The lockfile doesn't change.Verification
.github/dependabot.ymlvalidates against SchemaStore'sdependabot-2.0.jsonwith 0 errors. That schema includesmulti-ecosystem-groups, and it allowscooldownandignoreon member entries.cargo metadata --lockedandcargo check --locked -p mas-mcpboth pass.dprint checkis clean.What I couldn't verify
dependabot/tauri-….cooldownon a member entry is honoured inside a multi-ecosystem group. The schema allows it, but if the first group PR proposes something younger than 7 days, that's why.rmcp3.5.0 forcrates/mas-mcpalone. Once this merges, Dependabot should rebuild it against the workspace pin. If it doesn't, close chore(deps): bump the cargo group across 1 directory with 2 updates #736 and let the next run reopen it.🤖 Generated with Claude Code
https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg
Generated by Claude Code