Skip to content

Conversation

@ajnelson-nist
Copy link
Member

Offline, I checked the Cargo lock status and saw there were some updates that could be applied. One of the dependencies in a 0.x.0 version range changed an API, so the first Dependabot round of activity might cause a build break. (They're pre-1.0.0, so I have no complaints.) I have a patch ready to go, but I'm curious if the automated version bumps go the before or after the API change.

Signed-off-by: Alex Nelsin <[email protected]>
@ajnelson-nist
Copy link
Member Author

This PR is ready for review and merge.

@ajnelson-nist ajnelson-nist marked this pull request as ready for review November 19, 2025 20:45
Copy link
Contributor

@vulnmaster vulnmaster left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed and approved. We noted that Github dependabot is already doing a weekly check on the /java/case2geo directory but for some reason that we do not understand we need to assign the weekly interval for the /rust/case2geojson directory.

@vulnmaster vulnmaster merged commit a2a6f15 into main Nov 19, 2025
16 checks passed
@vulnmaster vulnmaster deleted the add_rust_to_dependabot branch November 19, 2025 21:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants