Skip to content

Commit 5ab9b05

Browse files
Copilotrvagg
andcommitted
Configure Dependabot for critical dependencies with monthly schedule
Co-authored-by: rvagg <[email protected]>
1 parent 56e320a commit 5ab9b05

File tree

1 file changed

+28
-2
lines changed

1 file changed

+28
-2
lines changed

.github/dependabot.yml

Lines changed: 28 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,32 @@ updates:
33
- package-ecosystem: "cargo"
44
directory: "/"
55
schedule:
6-
interval: "weekly"
6+
interval: "monthly"
77
allow:
8-
- dependency-name: "wasmtime"
8+
# Critical wasmtime dependencies - require careful review for security and performance
9+
- dependency-name: "wasmtime"
10+
- dependency-name: "wasmtime-environ"
11+
12+
# Core serialization and encoding dependencies
13+
- dependency-name: "serde"
14+
- dependency-name: "cid"
15+
- dependency-name: "ipld-core"
16+
- dependency-name: "multihash-codetable"
17+
- dependency-name: "multihash-derive"
18+
19+
# Cryptographic dependencies - important for security updates
20+
- dependency-name: "blake2b_simd"
21+
- dependency-name: "k256"
22+
- dependency-name: "bls-signatures"
23+
24+
# Protocol and utilities
25+
- dependency-name: "unsigned-varint"
26+
27+
# Filecoin-specific dependencies
28+
- dependency-name: "filecoin-proofs-api"
29+
- dependency-name: "fvm-wasm-instrument"
30+
31+
# IPLD encoding dependencies
32+
- dependency-name: "serde_ipld_dagcbor"
33+
- dependency-name: "serde_repr"
34+
- dependency-name: "serde_tuple"

0 commit comments

Comments
 (0)