From aaad7b380ba3f636116b70003dc23ed70fa82407 Mon Sep 17 00:00:00 2001 From: Corie Watson Date: Mon, 18 May 2026 12:18:15 +0100 Subject: [PATCH 1/4] chore(deps): group security --- .github/dependabot.yml | 24 ++++++++++++++++++++---- 1 file changed, 20 insertions(+), 4 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 2d837857c..0fcb2f31a 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,23 +1,39 @@ version: 2 + updates: - package-ecosystem: "npm" directories: - "/**" schedule: interval: "weekly" + labels: - "dependencies" - "automated" + commit-message: prefix: "chore" include: "scope" + groups: - minor-and-patch: + version-minor-and-patch-by-dependency: + applies-to: version-updates patterns: - "*" update-types: - - "minor" - - "patch" + - minor + - patch + + security-minor-and-patch: + applies-to: security-updates + patterns: + - "*" + update-types: + - major + - minor + - patch + ignore: - dependency-name: "*" - update-types: ["version-update:semver-major"] + update-types: + - "version-update:semver-major" From dcf12433fa1c3bbdb1b557838b45440147caeb61 Mon Sep 17 00:00:00 2001 From: Corie Watson Date: Mon, 18 May 2026 12:21:36 +0100 Subject: [PATCH 2/4] chore(deps): rename dependency group for minor and patch updates --- .github/dependabot.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 0fcb2f31a..543d49e28 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -16,7 +16,7 @@ updates: include: "scope" groups: - version-minor-and-patch-by-dependency: + version-minor-and-patch: applies-to: version-updates patterns: - "*" From 6e56e70e04308f23b3b6ba6209feeec12ff652e0 Mon Sep 17 00:00:00 2001 From: Corie Watson Date: Mon, 18 May 2026 12:22:29 +0100 Subject: [PATCH 3/4] chore(deps): rename security updates group in dependabot configuration --- .github/dependabot.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 543d49e28..39a206be6 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -24,7 +24,7 @@ updates: - minor - patch - security-minor-and-patch: + security-updates: applies-to: security-updates patterns: - "*" From 24df2eee3d1cc43c9fc4ab4de2c9561ddf136e99 Mon Sep 17 00:00:00 2001 From: Corie Watson Date: Tue, 19 May 2026 15:30:12 +0100 Subject: [PATCH 4/4] chore(deps): add cooldown settings for Dependabot updates --- .github/dependabot.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 39a206be6..f89ebe3f4 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -6,6 +6,11 @@ updates: - "/**" schedule: interval: "weekly" + cooldown: + default-days: 7 + semver-major-days: 7 + semver-minor-days: 7 + semver-patch-days: 7 labels: - "dependencies"