Repository navigation
chore(deps): Dependabot security updates only, labelled for the type gate - #12
Conversation
Scheduled version updates off (open-pull-requests-limit: 0); security updates are exempt from that limit and still open. labels: applies to security-update PRs, so they now carry a type: label and satisfy the pr-type-label gate. Claude-Session: https://claude.ai/code/session_01XUThLXzfRd4RVtxXCQo2Ui
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Team Run ID: 📒 Files selected for processing (1)
Included review availability: 0 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 4 reviews per hour. 📝 WalkthroughWalkthroughDependabot now uses a security-only policy for Go modules and GitHub Actions. Scheduled version updates are disabled with an open pull request limit of ChangesDependabot policy
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Other Merge Risk: ⚪ Minimal · up to The security-only Dependabot configuration has no identified merge-blocking risk. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Dependabot PRs carry no
type:label of their own, sopr-type-label— a required check — fails on every one of them and they pile up unmergeable. That is the reason they have been getting closed unread rather than triaged.This adds (or rewrites)
.github/dependabot.ymlwith one entry per manifest directory in this repo:open-pull-requests-limit: 0— scheduled version updates off. Security updates are explicitly exempt from this limit, so a PR still opens for every Dependabot alert that has a patch.labels: ["type:security", "dependencies"]—labelsapplies to security-update PRs too, so they arrive already satisfying the gate.The label is scoped per
package-ecosystem/directory, which is why every manifest directory needs an entry even with version updates switched off.Ref: https://docs.github.com/en/code-security/dependabot/working-with-dependabot/dependabot-options-reference
https://claude.ai/code/session_01XUThLXzfRd4RVtxXCQo2Ui
Summary by CodeRabbit