Skip to content

chore: group renovate security updates#329

Merged
choufraise merged 1 commit into
mainfrom
chore/renovate-security-grouping
Jun 9, 2026
Merged

chore: group renovate security updates#329
choufraise merged 1 commit into
mainfrom
chore/renovate-security-grouping

Conversation

@choufraise

@choufraise choufraise commented Jun 8, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • group Renovate vulnerability alert PRs into one security update PR
  • keep the security label and lowest fixed version strategy
  • leave routine minor/patch/major Renovate behavior unchanged

Reasoning

NAuth is not auto-deployed from dependency PRs, so batching simultaneous security fixes reduces review noise while keeping vulnerability updates separate from routine dependency maintenance.

Group vulnerability-driven Renovate PRs into a single security update PR.

This keeps security fixes visible and unscheduled, but avoids separate PRs for each vulnerable dependency when multiple fixes are detected at the same time.

Routine dependency update behavior is unchanged: minor updates are grouped weekly, routine patches stay disabled, and major updates still require Dependency Dashboard approval.

Signed-off-by: Thobias Karlsson <thobias.karlsson@gmail.com>
@choufraise choufraise requested a review from a team as a code owner June 8, 2026 14:22
@choufraise choufraise merged commit 6eeb93c into main Jun 9, 2026
4 checks passed
@choufraise choufraise deleted the chore/renovate-security-grouping branch June 9, 2026 05:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants