Skip to content

Try Dependabot with single multi-ecosystem group to update everything at once - #1471

Open
brandur wants to merge 1 commit into
masterfrom
brandur-dependabot-multi-ecosystem
Open

brandur wants to merge 1 commit into
masterfrom
brandur-dependabot-multi-ecosystem

Conversation

@brandur

@brandur brandur commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Our Dependabot configuration right now is a nightmare. We're getting
updates on a constant basis, and often they'll arrive in huge batches.
e.g. We got a half dozen separate ones just this morning.

I'm not totally convinced Dependabot can be fixed (we might need to just
disable it and do something home-rolled), but let's see if it's possible
by reconfiguring to use a "multi-ecosystem group" that bundles in
everything at once.

This won't include security updates, but there's a chance that it could
reduce the noise from routine dependency updates somewhat.

[1] https://docs.github.com/en/code-security/how-tos/secure-your-supply-chain/secure-your-dependencies/configuring-multi-ecosystem-updates

… at once

Our Dependabot configuration right now is a nightmare. We're getting
updates on a constant basis, and often they'll arrive in huge batches.
e.g. We got a half dozen separate ones just this morning.

I'm not totally convinced Dependabot can be fixed (we might need to just
disable it and do something home-rolled), but let's see if it's possible
by reconfiguring to use a "multi-ecosystem group" that bundles in
everything at once.

This won't include security updates, but there's a chance that it could
reduce the noise from routine dependency updates somewhat.

[1] https://docs.github.com/en/code-security/how-tos/secure-your-supply-chain/secure-your-dependencies/configuring-multi-ecosystem-updates
@brandur
brandur requested a review from bgentry October 7, 2026 05:37
@bgentry

bgentry commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Hmm let me think about this a bit. I keep telling you to ignore/archive these because the only thing sustainable for us is some sort of AI driven automation which we haven’t really set up properly yet (I’ve been driving it manually which is a huge help but still not enough). That’s also the only way to have any hope of properly validating all these deps from a security perspective.

in general getting more granular update PRs makes them easier to review and get merged without conflicts. The noise is the main issue IMO given the frequency of security updates these days.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants