Skip to content

chore: Dependabot grouped security + weekly version updates - #27

Merged
yashdhote merged 1 commit into
developfrom
chore/dependabot-grouped-updates
Sep 4, 2026
Merged

yashdhote merged 1 commit into
developfrom
chore/dependabot-grouped-updates

Conversation

@mayurrawte

Copy link
Copy Markdown
Member

Adds .github/dependabot.yml.

  • All security fixes per ecosystem arrive in one grouped PR instead of one per package.
  • Weekly (Mon 06:00 IST) version updates, grouped: one PR for dev dependencies, one for minor/patch bumps of runtime deps. Majors stay individual.
  • Docker base images and GitHub Actions kept current the same way.
  • Max 5 open Dependabot PRs per ecosystem.

Ecosystems: npm, github-actions

Part of the Sprinto vulnerability-SLA cleanup.

@yashdhote
yashdhote merged commit 7ed3d2d into develop Sep 4, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants