chore(deps): bump config from 0.14.1 to 0.15.23#145
Conversation
Bumps [config](https://github.com/rust-cli/config-rs) from 0.14.1 to 0.15.23. - [Changelog](https://github.com/rust-cli/config-rs/blob/main/CHANGELOG.md) - [Commits](rust-cli/config-rs@v0.14.1...v0.15.23) --- updated-dependencies: - dependency-name: config dependency-version: 0.15.23 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
Closing as superseded by ambientops#153 (estate dependabot policy conformance, standards#301). The canonical |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
…andards#301) (#153) ## Summary - Adds the canonical estate `ignore: dependency-name "*" version-update:semver-major` block to each non-github-actions ecosystem entry in `.github/dependabot.yml` - 9 entries get the ignore (5 cargo: root + czech-file-knife + panoptes + personal-sysadmin + displace; mix; npm; pip; nix). github-actions is left as-is per estate doc — SHA pins make action majors safe. - Brings ambientops into conformance with standards#301 / docs/DEPENDABOT-POLICY.adoc ## Context Per the 2026-05-29 echidna incident (#120-#124 broke main for ~24h), unattended dependabot semver-major merges fly through the estate validation gates (K9 / A2ML / language-policy) but break the actual compile gates on subsequent pushes. Estate policy now: majors land via author-supplied PRs paired with call-site updates. This PR closes 7 risky in-flight dependabot PRs as superseded: - #147 reqwest 0.12.28→0.13.4 (0.x minor breaking) - #145 config 0.14.1→0.15.23 (0.x minor breaking, multi-version) - #144 symphonia 0.5.5→0.6.0 (0.x minor breaking) - #146 thiserror 1.0.69→2.0.18 (major) - #142 colored 2.2.0→3.1.1 (major) - #136 rusqlite 0.31.0→0.40.0 (0.x huge jump) - #135 nix 0.30.1→0.31.3 (0.x minor breaking) Each needs a paired code-side migration that hasn't been done; this PR parks them safely via the canonical policy. ## Test plan - [ ] dependabot config check passes (YAML valid) - [ ] CI green (existing gates) - [ ] After merge, dependabot does not re-file the 7 closed PRs
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Bumps config from 0.14.1 to 0.15.23.
Changelog
Sourced from config's changelog.
... (truncated)
Commits
9053d29chore: Release config version 0.15.23e194797docs: Update changelog40f2698fix(env): apply convert_case to each nested key segment (#754)c2920acfix(env): apply convert_case to each nested key segment06d760etest: capture missing nested-segment case conversion in Environmente7e72ccchore(deps): Update pre-commit hook crate-ci/typos to v1.46.0 (#753)16a85fachore(deps): Update compatible (dev) (#752)53c9e30chore(deps): Update pre-commit hook crate-ci/typos to v1.46.07f4482cchore(deps): Update Rust Stable to v1.95 (#750)33f0b36chore(deps): Update Rust crate yaml-rust2 to 0.11.0 (#749)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)