# Keep the pinned GitHub Actions and the Rust dependencies current, one PR at a time.
# The actions are pinned by SHA in the workflows; Dependabot bumps the SHA and updates the
# version comment, so pinning does not mean going stale.
version: 2
updates:
  - package-ecosystem: github-actions
    directory: /
    schedule:
      interval: weekly
    commit-message:
      prefix: ci

  - package-ecosystem: cargo
    directory: /
    schedule:
      interval: weekly
    commit-message:
      prefix: deps
    # pgrx must match cargo-pgrx EXACTLY, and cargo-pgrx is a pinned toolchain version
    # (=0.19.2) in the CI, the Dockerfile and the README -- not a Cargo dependency Dependabot
    # can bump. A pgrx bump on its own therefore always breaks the build (a PR did), so pgrx is
    # upgraded by hand, in lockstep with cargo-pgrx, and left out of Dependabot here.
    ignore:
      - dependency-name: pgrx
      - dependency-name: pgrx-tests
