Skip to content

ci(dependabot): ignore version majors, group bun and cargo patches - #9

Merged
Mathious6 merged 1 commit into
mainfrom
ci/dependabot-minor-patch
Aug 27, 2026
Merged

Mathious6 merged 1 commit into
mainfrom
ci/dependabot-minor-patch

Conversation

@Mathious6

Copy link
Copy Markdown
Owner

What changed

Restrict bun and cargo Dependabot version updates to grouped minor/patch.
Ignore version-update majors for bun, cargo, and GitHub Actions so
TypeScript 7 / Vite 8 / ureq 3 / action majors cannot land as
lockfile-only PRs. Action minor/patch PRs stay individual because
Actions execute in CI and in the tag-only release workflow.

Security updates are not ignored (ignore.update-types does not apply
to security-only jobs).

Verification

  • The change is focused and follows AGENTS.md.
  • Tests cover changed domain behavior. (config only)
  • Documentation matches user-visible behavior. (none)
  • No proxy credentials, proxy lists, or secrets are included.
  • ci.yml green on this PR.

Keep weekly bun and cargo version PRs to minor and patch. Ignore
version-update majors so TypeScript 7, Vite 8, ureq 3, and action
majors cannot land as lockfile-only PRs. Security updates are not
covered by this ignore.
@Mathious6
Mathious6 merged commit 8849ad2 into main Aug 27, 2026
7 checks passed
@Mathious6
Mathious6 deleted the ci/dependabot-minor-patch branch August 27, 2026 11:50
@Mathious6

Copy link
Copy Markdown
Owner Author

Dependabot config check runs:

All three completed successfully and accepted the policy: bun and cargo show the major-version ignore and their frontend/rust minor-patch groups; github_actions shows the major-version ignore with no group. No new major version-update PR was created.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant