Skip to content

Fix Dependabot cargo security updates for non-rust-vmm crates - #22

Draft
guzongmin with Copilot wants to merge 2 commits into
mainfrom
copilot/fix-dependabot-failure
Draft

guzongmin with Copilot wants to merge 2 commits into
mainfrom
copilot/fix-dependabot-failure

Conversation

Copilot AI commented Sep 15, 2026 •

Copy link
Copy Markdown

Dependabot security updates for Cargo were failing with all_versions_ignored on non-rust-vmm dependencies such as serde_with. The failure came from overlapping Cargo update rules for the same directories, where the restrictive allowlist was selected first.

  • Dependabot config

    • Collapse the duplicate Cargo entries for / and /fuzz into a single update rule.
    • Keep Cargo security updates enabled for all dependencies with:
      allow:
        - dependency-type: all
  • Grouping behavior

    • Preserve the intended split between rust-vmm and everything else by expressing it as groups within the single Cargo rule.
    • Define rust-vmm with explicit dependency patterns.
    • Define non-rust-vmm as a catch-all group with matching exclude-patterns so crates like serde_with are no longer filtered out by config shape.
  • Behavioral impact

    • Security advisories for non-rust-vmm Cargo dependencies can now generate updates instead of failing during Dependabot processing.
    • Existing cooldown settings and grouping intent remain intact.
groups:
  rust-vmm:
    patterns:
      - "acpi_tables"
      - "kvm-bindings"
      # ...
  non-rust-vmm:
    patterns:
      - "*"
    exclude-patterns:
      - "acpi_tables"
      - "kvm-bindings"
      # ...

Co-authored-by: guzongmin <59240482+guzongmin@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix failing GitHub Actions job Dependabot Fix Dependabot cargo security updates for non-rust-vmm crates Sep 15, 2026
Copilot AI requested a review from guzongmin September 15, 2026 00:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants