Skip to content

ci: configure Dependabot for uv and GitHub Actions - #66

Merged
david-debest merged 1 commit into
mainfrom
ci/dependabot-config
Oct 1, 2026
Merged

david-debest merged 1 commit into
mainfrom
ci/dependabot-config

Conversation

@david-debest

Copy link
Copy Markdown
Contributor

Why

The repo had no .github/dependabot.yml, so Dependabot never proposed updates for the current dependencies. The only Dependabot activity was 91 security alerts on manifests that were deleted in 884e3c4 / 05858a9 (api/, data-sink/, data-source/, mapper/, web/). Those alerts have been dismissed as not_used.

What

Adds .github/dependabot.yml with weekly version updates for:

  • uv (pyproject.toml / uv.lock): grouped into a single PR, commit prefix build.
  • github-actions (actions/checkout, astral-sh/setup-uv, actions/upload-artifact): grouped into a single PR, commit prefix ci.

Security updates are unaffected and still arrive as separate PRs when enabled in the repo settings.

Note for admins

If stale alerts reappear, toggling the dependency graph off/on (Settings → Code security) forces a re-scan. Insights → Dependency graph should list pyproject.toml / uv.lock.

Without a config Dependabot only raised security alerts (which had gone
stale on manifests deleted in 884e3c4 / 05858a9) and never proposed
updates for the current dependencies. Updates are grouped per ecosystem
to keep the PR volume low.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@david-debest
david-debest merged commit d04e6a3 into main Oct 1, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant