Skip to content

chore: add Dependabot config for GitHub Actions - #94

Merged
aagarwal1012 merged 1 commit into
mainfrom
chore/dependabot-github-actions
Sep 15, 2026
Merged

aagarwal1012 merged 1 commit into
mainfrom
chore/dependabot-github-actions

Conversation

@aagarwal1012

Copy link
Copy Markdown
Member

Adds a Dependabot version-updates config covering the github-actions ecosystem.

Why: third-party actions are a supply-chain surface that nothing was keeping current
in this repo. Dependabot alerts and security updates are now enabled org-wide, but those
only fire on published advisories -- this keeps action versions from going stale in between.

Noise control: all actions are grouped into a single PR, weekly, capped at 5 open PRs.
Expect roughly one PR per week, not one per action.

Scope is deliberately limited to github-actions. Package ecosystems (npm, pip, cargo,
docker, ...) are a separate follow-up so this rollout stays reviewable.

@vercel

vercel Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
dualmark Ready Ready Preview Sep 15, 2026 11:39am UTC

Request Review

Comment thread .github/dependabot.yml
github-actions:
patterns:
- "*"
labels:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit: the dependencies label doesn't currently exist in this repo's label list. Per GitHub's docs, when labels is explicitly set in dependabot.yml, Dependabot uses only the specified labels and won't auto-create ones that are missing (that auto-create behavior only applies to its unconfigured defaults). So as-is, the label will just be silently skipped on PRs. Either pre-create the dependencies label in the repo, or drop the labels key entirely to fall back to Dependabot's default label (which it does auto-create). Not a blocker either way.

@dodo-squirrels dodo-squirrels Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the new .github/dependabot.yml. The config is minimal, valid YAML, and correctly scoped to the github-actions ecosystem:

  • package-ecosystem: github-actions + directory: / is the standard setup — this covers both .github/workflows/*.yml and the composite action at .github/actions/setup/action.yml, so all currently-used actions (actions/checkout, actions/setup-node, oven-sh/setup-bun, denoland/setup-deno, fastly/compute-actions/setup, changesets/action, and the SHA-pinned dodopayments/dualmark-verify-action) will be tracked.
  • Weekly schedule + single group (patterns: ["*"]) + open-pull-requests-limit: 5 matches the stated goal of one grouped PR/week instead of per-action noise.
  • Scope is appropriately limited to github-actions, as noted in the description.

One minor nit left inline: the dependencies label referenced in the config doesn't exist yet in the repo, and since labels is explicitly set (rather than left to Dependabot's defaults), it won't be auto-created — so it'll just be silently skipped on the resulting PRs. Easy fix, not a blocker.

No security or correctness concerns. LGTM.

@aagarwal1012
aagarwal1012 merged commit 986d791 into main Sep 15, 2026
7 checks passed
@aagarwal1012
aagarwal1012 deleted the chore/dependabot-github-actions branch September 15, 2026 11:54

This branch was successfully deployed

1 active deployment
Preview — b7a18f52 Deployed Sep 15, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant