Skip to content

chore(deps): bump dashmap from 6.1.0 to 6.2.1 in /czech-file-knife#120

Merged
hyperpolymath merged 2 commits into
mainfrom
dependabot/cargo/czech-file-knife/dashmap-6.2.1
May 29, 2026
Merged

chore(deps): bump dashmap from 6.1.0 to 6.2.1 in /czech-file-knife#120
hyperpolymath merged 2 commits into
mainfrom
dependabot/cargo/czech-file-knife/dashmap-6.2.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 28, 2026

Bumps dashmap from 6.1.0 to 6.2.1.

Release notes

Sourced from dashmap's releases.

v6.2.1

This is an interim maintenance release for the existing v6 branch before v7 can be released. This bumps the MSRV to 1.85 and updates dependencies to their latest versions.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [dashmap](https://github.com/xacrimon/dashmap) from 6.1.0 to 6.2.1.
- [Release notes](https://github.com/xacrimon/dashmap/releases)
- [Commits](xacrimon/dashmap@v6.1.0...v6.2.1)

---
updated-dependencies:
- dependency-name: dashmap
  dependency-version: 6.2.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file rust Pull requests that update rust code labels May 28, 2026
@hyperpolymath hyperpolymath merged commit 355a6e6 into main May 29, 2026
21 of 23 checks passed
@hyperpolymath hyperpolymath deleted the dependabot/cargo/czech-file-knife/dashmap-6.2.1 branch May 29, 2026 00:27
hyperpolymath added a commit that referenced this pull request May 30, 2026
…andards#301) (#153)

## Summary

- Adds the canonical estate `ignore: dependency-name "*"
version-update:semver-major` block to each non-github-actions ecosystem
entry in `.github/dependabot.yml`
- 9 entries get the ignore (5 cargo: root + czech-file-knife + panoptes
+ personal-sysadmin + displace; mix; npm; pip; nix). github-actions is
left as-is per estate doc — SHA pins make action majors safe.
- Brings ambientops into conformance with standards#301 /
docs/DEPENDABOT-POLICY.adoc

## Context

Per the 2026-05-29 echidna incident (#120-#124 broke main for ~24h),
unattended dependabot semver-major merges fly through the estate
validation gates (K9 / A2ML / language-policy) but break the actual
compile gates on subsequent pushes. Estate policy now: majors land via
author-supplied PRs paired with call-site updates.

This PR closes 7 risky in-flight dependabot PRs as superseded:

- #147 reqwest 0.12.28→0.13.4 (0.x minor breaking)
- #145 config 0.14.1→0.15.23 (0.x minor breaking, multi-version)
- #144 symphonia 0.5.5→0.6.0 (0.x minor breaking)
- #146 thiserror 1.0.69→2.0.18 (major)
- #142 colored 2.2.0→3.1.1 (major)
- #136 rusqlite 0.31.0→0.40.0 (0.x huge jump)
- #135 nix 0.30.1→0.31.3 (0.x minor breaking)

Each needs a paired code-side migration that hasn't been done; this PR
parks them safely via the canonical policy.

## Test plan

- [ ] dependabot config check passes (YAML valid)
- [ ] CI green (existing gates)
- [ ] After merge, dependabot does not re-file the 7 closed PRs
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant