Skip to content

Conversation

koistya
Copy link
Member

@koistya koistya commented Sep 24, 2025

What's changed

  • Added .github/dependabot.yml for automated dependency updates
  • Configured weekly updates (Mondays 4 AM UTC) with all dependencies grouped
  • Added "dependencies" label and "deps" commit prefix for better organization
  • Security updates handled separately for critical fixes

Why

Keeps dependencies current with minimal maintenance overhead. Weekly cadence balances staying up-to-date with avoiding PR fatigue. Grouped updates reduce noise while allowing security patches to bypass grouping.

Testing

Dependabot will create its first PR on the next Monday after merge, with up to 5 open PRs allowed.

@koistya koistya merged commit 4e4607f into main Sep 24, 2025
8 checks passed
@koistya koistya deleted the dev branch September 24, 2025 21:41
@koistya koistya changed the title chore: add Dependabot configurationin chore: add Dependabot configuration Sep 24, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant