Skip to content

Add Dependabot version updates, and retire Renovate - #13

Closed
fenrick wants to merge 2 commits into
mainfrom
ci/dependabot
Closed

fenrick wants to merge 2 commits into
mainfrom
ci/dependabot

Conversation

@fenrick

@fenrick fenrick commented Sep 10, 2026

Copy link
Copy Markdown
Owner

Adds .github/dependabot.yml for both ecosystems in play, and removes the
Renovate configuration, because running both bots means two pull requests for
every update.

The configuration

Ecosystems cargo and github-actions, both at /
Schedule weekly, Monday 06:00 Australia/Brisbane
Grouping one pull request per ecosystem; security updates grouped separately so they are never queued behind an ordinary bump
Limit 5 open pull requests per ecosystem

Two details that are easy to get wrong and matter here:

Commit prefixes. Releases are generated from commit messages, so an
unprefixed dependency bump is silently left out of the changelog. Cargo
updates commit as fix(deps): — under Fixed, patch bump. Action updates
commit as ci(deps): — recorded but hidden, which is right for a
workflow-only change.

Grouping. Three separate Renovate pull requests appeared within minutes
of this repository existing. That is not a review rate anyone sustains, so
both ecosystems are grouped.

Renovate

The second commit removes renovate.json. Two bots proposing the same bump
gives you two branches, two CI runs, and two changelog entries if both get
merged.

This does not fully stop Renovate. The GitHub App installation is an
account-level setting that has to be removed under Settings → GitHub Apps,
or the repository excluded from its list. Until then, removing the config
makes Renovate fall back to its default behaviour — ungrouped, immediate —
which is worse than leaving the config in place. Worth doing in the same
sitting as merging this.

If you would rather keep Renovate, drop the second commit and the first still
stands on its own — though then it is Dependabot that wants disabling instead.

Not included

enable-beta-ecosystems, private registries, ignore rules and version
pinning. None apply: every dependency is a public crate or a public action,
and nothing is pinned below a major.

Covers both ecosystems in play: the Rust crates in Cargo.toml and the
actions the workflows use.

Updates are grouped, so a week's worth arrives as one pull request per
ecosystem rather than one per dependency — three separate pull requests
appeared within minutes of this repository existing, which is not a review
rate anyone sustains. Security updates are grouped separately so they are
never queued behind an ordinary version bump.

Commit prefixes are set deliberately. Releases are generated from commit
messages, so an unprefixed dependency bump would be left out of the
changelog entirely. Cargo updates commit as `fix(deps):` and appear under
Fixed; action updates commit as `ci(deps):` and are recorded but hidden.
Running both bots means two pull requests for every update, each with its
own branch, its own CI run and its own changelog entry if both are merged.
Dependabot is the one being kept.

Removing this file stops Renovate acting on its own configuration, but the
GitHub App installation is an account-level setting and has to be removed
separately, under Settings, GitHub Apps. Until that is done Renovate will
fall back to its default behaviour rather than stopping.
@fenrick fenrick closed this Sep 10, 2026
@fenrick
fenrick deleted the ci/dependabot branch September 10, 2026 00:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant