The workflows pin mache's actions at thirteen places, and the last three
moves of those pins were made by hand. Dependabot already watches the
actions, but it put every action in one weekly group, so a mache bump
would have arrived beside unrelated ones. That matters because mache's
releases can change what a match plays: v0.6.0 moved the default book
table, and the hand bump had to add six book_table lines to keep the
table the engine's book input describes.
mache now has a group of its own and is excluded from the rest. The
development doc says to read mache's changelog for a breaking line
before merging one.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MStzRapxqqqByoFQmfA69p
The workflows pin mache's actions in thirteen places, and the last three moves of those pins were made by hand. Dependabot already watches the actions, but in one group with everything else, so a mache bump would arrive beside unrelated ones. mache's releases can change what a match plays: v0.6.0 moved the default book table, and the hand bump had to add six
book_tablelines to keepscripts/book.sh..github/dependabot.yml: mache gets its own group and is excluded from the general actions group.docs/DEVELOPMENT.md: read mache's changelog for a breaking line before merging a bump.Not checked: whether Dependabot matches
aywrite/mache*against the path-style pins. The next mache release will show it.🤖 Generated with Claude Code
https://claude.ai/code/session_01MStzRapxqqqByoFQmfA69p
Generated by Claude Code