Repository navigation
chore: add Dependabot config for GitHub Actions - #94
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
| github-actions: | ||
| patterns: | ||
| - "*" | ||
| labels: |
There was a problem hiding this comment.
Nit: the dependencies label doesn't currently exist in this repo's label list. Per GitHub's docs, when labels is explicitly set in dependabot.yml, Dependabot uses only the specified labels and won't auto-create ones that are missing (that auto-create behavior only applies to its unconfigured defaults). So as-is, the label will just be silently skipped on PRs. Either pre-create the dependencies label in the repo, or drop the labels key entirely to fall back to Dependabot's default label (which it does auto-create). Not a blocker either way.
There was a problem hiding this comment.
Reviewed the new .github/dependabot.yml. The config is minimal, valid YAML, and correctly scoped to the github-actions ecosystem:
package-ecosystem: github-actions+directory: /is the standard setup — this covers both.github/workflows/*.ymland the composite action at.github/actions/setup/action.yml, so all currently-used actions (actions/checkout,actions/setup-node,oven-sh/setup-bun,denoland/setup-deno,fastly/compute-actions/setup,changesets/action, and the SHA-pinneddodopayments/dualmark-verify-action) will be tracked.- Weekly schedule + single group (
patterns: ["*"]) +open-pull-requests-limit: 5matches the stated goal of one grouped PR/week instead of per-action noise. - Scope is appropriately limited to github-actions, as noted in the description.
One minor nit left inline: the dependencies label referenced in the config doesn't exist yet in the repo, and since labels is explicitly set (rather than left to Dependabot's defaults), it won't be auto-created — so it'll just be silently skipped on the resulting PRs. Easy fix, not a blocker.
No security or correctness concerns. LGTM.
Adds a Dependabot
version-updatesconfig covering thegithub-actionsecosystem.Why: third-party actions are a supply-chain surface that nothing was keeping current
in this repo. Dependabot alerts and security updates are now enabled org-wide, but those
only fire on published advisories -- this keeps action versions from going stale in between.
Noise control: all actions are grouped into a single PR, weekly, capped at 5 open PRs.
Expect roughly one PR per week, not one per action.
Scope is deliberately limited to
github-actions. Package ecosystems (npm, pip, cargo,docker, ...) are a separate follow-up so this rollout stays reviewable.