Skip to content

Commit 1251363

Browse files
Copilotrvagg
andauthored
chore: dependabot for critical dependencies with monthly schedule (#2194)
Co-authored-by: rvagg <[email protected]>
1 parent b73258b commit 1251363

File tree

1 file changed

+27
-2
lines changed

1 file changed

+27
-2
lines changed

.github/dependabot.yml

Lines changed: 27 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,32 @@ updates:
33
- package-ecosystem: "cargo"
44
directory: "/"
55
schedule:
6-
interval: "weekly"
6+
interval: "monthly"
77
allow:
8+
# Critical wasmtime dependencies - require careful review for security and performance
89
- dependency-name: "wasmtime"
9-
- dependency-name: "wasmtime-environ"
10+
- dependency-name: "wasmtime-environ"
11+
12+
# Core serialization and encoding dependencies
13+
- dependency-name: "serde"
14+
- dependency-name: "cid"
15+
- dependency-name: "ipld-core"
16+
- dependency-name: "multihash-codetable"
17+
- dependency-name: "multihash-derive"
18+
19+
# Cryptographic dependencies - important for security updates
20+
- dependency-name: "blake2b_simd"
21+
- dependency-name: "k256"
22+
- dependency-name: "bls-signatures"
23+
24+
# Protocol and utilities
25+
- dependency-name: "unsigned-varint"
26+
27+
# Filecoin-specific dependencies
28+
- dependency-name: "filecoin-proofs-api"
29+
- dependency-name: "fvm-wasm-instrument"
30+
31+
# IPLD encoding dependencies
32+
- dependency-name: "serde_ipld_dagcbor"
33+
- dependency-name: "serde_repr"
34+
- dependency-name: "serde_tuple"

0 commit comments

Comments
 (0)