Skip to content

chore: ignore Dependabot updates for rust fixture crates - #879

Open
maoueh wants to merge 1 commit into
developfrom
feature/ignore-dependabot--sink-sql-db_proto-test
Open

chore: ignore Dependabot updates for rust fixture crates#879
maoueh wants to merge 1 commit into
developfrom
feature/ignore-dependabot--sink-sql-db_proto-test

Conversation

@maoueh

@maoueh maoueh commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

💪 What

  • Stops Dependabot version and security pull requests against the rust test and bench fixture crates
  • Leaves Go module Dependabot updates unchanged

🤔 Why

  • Dependabot keeps opening lockfile-only PRs for fixture crates that are not production code
  • Those PRs add review noise without changing product behavior

👩‍🔬 How to validate

  • Confirm the cargo ignore rules cover the SQL proto test fixtures, the e2e rust fixtures, and the wasm bench crates
  • Confirm the existing Go module update entries are still present and grouped the same way
  • After merge, new Dependabot PRs should not appear for those cargo directories

Stop version and security PRs against test and bench Cargo.lock files.
@sduchesneau

Copy link
Copy Markdown
Contributor

🔍 Vulnerabilities of ghcr.io/streamingfast/substreams:3e7b35b

📦 Image Reference ghcr.io/streamingfast/substreams:3e7b35b
digestsha256:1a78bc6cecb5939fa2cffc51a87e161f292dc51a4fe0d5ed8e772fd45390a233
vulnerabilitiescritical: 0 high: 0 medium: 0 low: 0
platformlinux/amd64
size123 MB
packages382
📦 Base Image oisupport/staging-amd64:24.04
also known as
  • a215e986b44aae6f10795ded1e39ce93d9c236d8163d21a522ffd0ab3659f546
  • noble
  • noble-20260730.1
digestsha256:019e8eb29a85e74d64925745884f2ec79aa27e3feab36353d24656f4d6b89467
vulnerabilitiescritical: 0 high: 0 medium: 5 low: 4

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants