From 0090c78d1f0fa6585f1d9c5daabe17f6bbf76eff Mon Sep 17 00:00:00 2001 From: Manuel de Brito Fontes Date: Mon, 28 Sep 2026 19:10:34 -0300 Subject: [PATCH] dependabot: once a week, Monday morning, and no pull request remade each time main moves Every ecosystem was weekly and spin still had pull requests almost daily: a change to this file starts every ecosystem at once, and a change to a manifest on main had Dependabot remake its open pull requests. A fixed day and time, rebase-strategy disabled - main's ruleset wants the branch up to date anyway, which "Update branch" does when it is merged - and a week's cooldown where it was missing. Where there was no file, the actions and the packages nothing moved. Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/dependabot.yml | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 9b807c9..ea02d5b 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,3 +1,9 @@ +# Every change to this file - a comment's too - starts a run of every ecosystem below, whatever +# the schedule says: change it rarely. Each runs Monday morning, a week after a release +# (cooldown), and rebase-strategy is disabled so a pull request is not remade each time main +# moves: main's ruleset merges a branch only up to date with it, and "Update branch" or +# `@dependabot rebase` brings one up when it is merged. +# # What is here is what Dependabot can actually see, and nothing else. # # Not here, on purpose: every pin the machine is built from. They are in versions.yaml - the @@ -23,6 +29,12 @@ updates: directory: / schedule: interval: weekly + day: monday + time: "06:00" + timezone: America/Argentina/Buenos_Aires + rebase-strategy: disabled + cooldown: + default-days: 7 groups: actions: patterns: ["*"] @@ -35,3 +47,9 @@ updates: directory: / schedule: interval: weekly + day: monday + time: "06:00" + timezone: America/Argentina/Buenos_Aires + rebase-strategy: disabled + cooldown: + default-days: 7