version: 2 # Scope: the root Cargo workspace, which produces the Rust binaries we # ship to users (the Node.js and Python native extensions). The # `rust/lancedb` library crate shares the same lockfile; its consumers # pick their own dependency versions, but bumping transitive deps here # keeps the binaries we ship current. updates: - package-ecosystem: cargo directory: / schedule: interval: weekly open-pull-requests-limit: 10 # Only update Cargo.lock, never widen/raise the version requirements in # Cargo.toml. The goal is keeping the lockfile (and the binaries we ship) # current on security fixes, not forcing our library's consumers onto # newer minimum versions. versioning-strategy: lockfile-only groups: # The arrow-rs and datafusion crates are released in lockstep and have to # move together, so keep them in one PR instead of one per sub-crate. # Listed first: a dependency joins the first group it matches. arrow-datafusion: patterns: - arrow - arrow-* - parquet - parquet-* - datafusion - datafusion-* - object_store rust-minor-patch: update-types: - minor - patch - package-ecosystem: pip directory: /python schedule: interval: weekly # Only update uv.lock, never widen version requirements in pyproject.toml. versioning-strategy: lockfile-only groups: python-deps: patterns: - "*" # The npm ecosystem covers pnpm lockfiles. There are two separate installs: # the bindings themselves and the examples, which have their own lockfile. # As with cargo and pip above, only bump the lockfile — the version ranges # in package.json are our consumers' constraints, not ours. - package-ecosystem: npm directory: /nodejs schedule: interval: weekly versioning-strategy: lockfile-only groups: nodejs-deps: patterns: - "*" - package-ecosystem: npm directory: /nodejs/examples schedule: interval: weekly versioning-strategy: lockfile-only groups: nodejs-examples-deps: patterns: - "*"