Skip to content

chore(deps): group dependabot updates per ecosystem - #9

Merged
christiangda merged 1 commit into
mainfrom
chore/dependabot-grouped-updates
Oct 1, 2026
Merged

christiangda merged 1 commit into
mainfrom
chore/dependabot-grouped-updates

Conversation

@christiangda

Copy link
Copy Markdown
Contributor

Why

Dependabot opens one PR per bumped dependency, which floods the review queue with small PRs that usually belong together.

What

Adds a groups block with patterns: ["*"] to each ecosystem in .github/dependabot.yml (Go module). Each ecosystem now gets one weekly PR that holds all its pending version updates. This matches the setup already used in idp-scim-sync, machineid and go-rest-api-service-template.

Impact

  • CI configuration only. No code or behaviour change.
  • Security updates are not affected. Groups apply only to version updates.
  • Trade-off: if one bump in a grouped PR breaks the build, the whole group waits until it is fixed or the bad dependency is excluded with @dependabot ignore.

🤖 Generated with Claude Code

Dependabot opens one PR per dependency bump, which floods the review
queue. Grouping every Go module update into a single weekly PR per
ecosystem cuts the noise and keeps related bumps (e.g. the several
github/codeql-action sub-actions) on the same version.

Security updates are unaffected: groups apply only to version updates.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@christiangda christiangda self-assigned this Oct 1, 2026
@christiangda
christiangda merged commit 223b806 into main Oct 1, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant