From 618c65f772261911b58bb52990beacf8c8ec75bf Mon Sep 17 00:00:00 2001 From: Brandur Date: Wed, 7 Oct 2026 00:32:24 -0500 Subject: [PATCH] Try Dependabot with single multi-ecosystem group to update everything at once Our Dependabot configuration right now is a nightmare. We're getting updates on a constant basis, and often they'll arrive in huge batches. e.g. We got a half dozen separate ones just this morning. I'm not totally convinced Dependabot can be fixed (we might need to just disable it and do something home-rolled), but let's see if it's possible by reconfiguring to use a "multi-ecosystem group" that bundles in everything at once. This won't include security updates, but there's a chance that it could reduce the noise from routine dependency updates somewhat. [1] https://docs.github.com/en/code-security/how-tos/secure-your-supply-chain/secure-your-dependencies/configuring-multi-ecosystem-updates --- .github/dependabot.yml | 69 ++++++++++++++++-------------------------- 1 file changed, 26 insertions(+), 43 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 3999e4631..39deef6d1 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,63 +1,46 @@ -# To get started with Dependabot version updates, you'll need to specify which -# package ecosystems to update and where the package manifests are located. -# Please see the documentation for all configuration options: -# https://docs.github.com/github/administering-a-repository/configuration-options-for-dependency-updates +# Combine all routine version updates, including major releases, into one PR. +# Add new ecosystems to this group so they share the same schedule. +# https://docs.github.com/en/code-security/how-tos/secure-your-supply-chain/secure-your-dependencies/configuring-multi-ecosystem-updates version: 2 +multi-ecosystem-groups: + dependencies: + schedule: + interval: "weekly" + day: "monday" + time: "09:00" + timezone: "America/Chicago" + updates: - package-ecosystem: "cargo" directory: "/rust" cooldown: default-days: 7 - groups: - rust-dependencies: - update-types: - - "minor" - - "patch" - schedule: - interval: "weekly" + multi-ecosystem-group: "dependencies" + patterns: + - "*" - package-ecosystem: "github-actions" # The JavaScript workflows' composite actions live under .github/actions. directories: - "/" - "/.github/actions/*" - schedule: - interval: "weekly" + multi-ecosystem-group: "dependencies" + patterns: + - "*" - package-ecosystem: "gomod" directories: - "**/*" - groups: - go-dependencies: - update-types: - - "minor" - - "patch" - schedule: - interval: "weekly" - # Routine minor and patch updates to the JavaScript workspace arrive as one - # grouped pull request per dependency type; major updates stay separate so - # each can be reviewed on its own. Exact pins in package.json (Prisma, the - # TypeScript-next preview, pnpm overrides) stay exact because `increase` - # rewrites the pinned version rather than widening it. + multi-ecosystem-group: "dependencies" + patterns: + - "*" + # Exact pins in package.json (Prisma, the TypeScript-next preview, pnpm + # overrides) stay exact because `increase` rewrites the pinned version + # rather than widening it. - package-ecosystem: "npm" directory: "/js" cooldown: default-days: 7 - groups: - development-dependencies: - dependency-type: "development" - patterns: - - "*" - update-types: - - "minor" - - "patch" - production-dependencies: - dependency-type: "production" - patterns: - - "*" - update-types: - - "minor" - - "patch" - open-pull-requests-limit: 10 - schedule: - interval: "monthly" + multi-ecosystem-group: "dependencies" + patterns: + - "*" versioning-strategy: increase