Stream: wasmtime

Topic: Does anyone know how dependabot works?


view this post on Zulip Alex Crichton (Sep 29 2026 at 21:40):

CI runs frequently have warnings nowadays of "your node version is gonna be deprecated" and most of the time it's pretty trivial to update, just bumping some version numbers. That's a run from wasm-tools but we've run into the same thing on Wasmtime too. My thinking is that dependencies-in-CI are something we rarely update unless something is going wrong which isn't always a great time to update things, so I'd ideally like to be a bit more proactive about updates.

In lieu of adding more checklists in more places I was hoping to enable dependabot or some github-builtin thing which sends updates. I've seen this on other repos myself and was curious to try it out. My current attempt has resulted in nothing happening, however.

So I wanted to ask: does anyone else have experience with updating dependabot, and if so would you be willing to help us out to enable it on maybe wasm-tools, and assuming that goes well, later wasmtime?

view this post on Zulip Pat Hickey (Sep 29 2026 at 21:47):

I've asked someone on my team at F5 who isnt usually a BA contributor if they can help

view this post on Zulip Antoine Lavandier (Sep 30 2026 at 08:29):

In the project that I'm working on, we use renovate (mend-io hosted) instead of dependabot. In terms of configuration, you basically just give it a json file. Reconfiguration are done through designated branches and it open PR by itself can even auto-merge them if you want that. Here the config that we use in our repo https://github.com/ariel-os/ariel-os/blob/main/.github/renovate.json5
This was done because dependabot did/does not support running with rust nightly and we needed that in our repo.

view this post on Zulip Celarye (Sep 30 2026 at 09:44):

When a dependabot change gets pushed to the default branch (I think it's only the default branch, would need to read the documentation to make sure) a test will run showing if the configuration is valid: https://github.com/bytecodealliance/wasm-tools/runs/104579659930

As you can see this one failed because the update-types under allow is expecting an array. On top of that my local editor has some checking enabled apparently because it says dependency-name is a required field under allow as well.

The documentation on how to configure depandabot can be found over at: https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#configuration-options-for-dependabotyml

Based on this, the following patch should work, but to be honest I am not super experienced either and it can be trial and error:

From b41d8ef9303ab12624e644f130c10055f0e0c8b7 Mon Sep 17 00:00:00 2001
From: Eduard Smet <contact@celarye.dev>
Date: Wed, 30 Sep 2026 11:40:39 +0200
Subject: [PATCH] ci(dependabot): Fix configuration

---
 .github/dependabot.yml | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/.github/dependabot.yml b/.github/dependabot.yml
index d1ee31458..ebfbe86ce 100644
--- a/.github/dependabot.yml
+++ b/.github/dependabot.yml
@@ -10,4 +10,5 @@ updates:
     schedule:
       interval: "weekly"
     allow:
-      - update-types: "version-update:semver-major"
+      - dependency-name: "*"
+        update-types: ["version-update:semver-major"]
--
2.55.0

view this post on Zulip Celarye (Sep 30 2026 at 09:58):

This is how I use Dependabot in one of my Cargo based projects and have a minor/patch group and major group: https://github.com/wpbs-rs/wpbs/blob/main/.github/dependabot.yaml

view this post on Zulip Alex Crichton (Sep 30 2026 at 15:18):

Thanks Antoine Lavandier! I'll check that out if dependabot ends up being not suitable. Also d'oh thanks as well Celarye in retrospect of course I should have checked the actions logs... Trying out https://github.com/bytecodealliance/wasm-tools/pull/2701 and gonna see what happens

view this post on Zulip Dylan Arbour (Sep 30 2026 at 17:49):

Renovate is a bit more configurable than Dependabot, but, it has a similar opaque workflow where trying to figure out how certain filters, includes, excludes work.

Dependabot is arguably simpler, but in my experience, harder to audit. I'll go look for some logs in the repos I have it enabled on.

Either way, if there is a push to move to Renovate I can definitely help.

view this post on Zulip Alex Crichton (Sep 30 2026 at 17:56):

does Renovate require a github app or similar to be installed?

view this post on Zulip Dylan Arbour (Sep 30 2026 at 23:11):

It doesn't require it, but that's the easiest way to use it and free for open source.

You can self host as well.


Last updated: Oct 11 2026 at 02:20 UTC