Skip to content

chore(deps): Dependabot security updates only, labelled for the type gate - #12

Merged
fahad-ali7 merged 1 commit into
mainfrom
chore/dependabot-security-only
Sep 11, 2026
Merged

fahad-ali7 merged 1 commit into
mainfrom
chore/dependabot-security-only

Conversation

@fahad-ali7

@fahad-ali7 fahad-ali7 commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Dependabot PRs carry no type: label of their own, so pr-type-label — a required check — fails on every one of them and they pile up unmergeable. That is the reason they have been getting closed unread rather than triaged.

This adds (or rewrites) .github/dependabot.yml with one entry per manifest directory in this repo:

  • open-pull-requests-limit: 0 — scheduled version updates off. Security updates are explicitly exempt from this limit, so a PR still opens for every Dependabot alert that has a patch.
  • labels: ["type:security", "dependencies"] — labels applies to security-update PRs too, so they arrive already satisfying the gate.

The label is scoped per package-ecosystem/directory, which is why every manifest directory needs an entry even with version updates switched off.

Ref: https://docs.github.com/en/code-security/dependabot/working-with-dependabot/dependabot-options-reference

https://claude.ai/code/session_01XUThLXzfRd4RVtxXCQo2Ui

Summary by CodeRabbit

  • Chores
    • Dependency version update pull requests are no longer scheduled automatically.
    • Security update pull requests continue to be enabled and are labeled for easier identification.
    • Automated dependency update grouping has been removed.

Scheduled version updates off (open-pull-requests-limit: 0); security updates
are exempt from that limit and still open. labels: applies to security-update
PRs, so they now carry a type: label and satisfy the pr-type-label gate.

Claude-Session: https://claude.ai/code/session_01XUThLXzfRd4RVtxXCQo2Ui
@fahad-ali7 fahad-ali7 added the type:chore Dependencies, tooling, refactors, config, release plumbing label Sep 11, 2026
@coderabbitai

coderabbitai Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Team

Run ID: e4018077-792e-4f0e-8071-14a71acd9b74

📥 Commits

Reviewing files that changed from the base of the PR and between 0b4b18f and 5ea0ecf.

📒 Files selected for processing (1)
  • .github/dependabot.yml

Included review availability: 0 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 4 reviews per hour.


📝 Walkthrough

Walkthrough

Dependabot now uses a security-only policy for Go modules and GitHub Actions. Scheduled version updates are disabled with an open pull request limit of 0. Security pull requests receive type:security and dependencies labels.

Changes

Dependabot policy

Layer / File(s) Summary
Security-only update configuration
.github/dependabot.yml
The configuration documents the security-only policy, disables scheduled updates for Go modules and GitHub Actions, sets the open pull request limit to 0, and adds security labels.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 5ea0e

The security-only Dependabot configuration has no identified merge-blocking risk.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: limiting Dependabot to security updates and adding labels for the type gate.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/dependabot-security-only

Comment @coderabbitai help to get the list of available commands.

@fahad-ali7
fahad-ali7 merged commit c477c8e into main Sep 11, 2026
11 of 12 checks passed
@fahad-ali7
fahad-ali7 deleted the chore/dependabot-security-only branch September 11, 2026 11:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type:chore Dependencies, tooling, refactors, config, release plumbing

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant