From 527053771d7f7652a9c1426286a51e9b7edd3bcf Mon Sep 17 00:00:00 2001 From: Clayton Carter Date: Fri, 26 Sep 2025 16:01:01 -0400 Subject: [PATCH] deps: reduce dependabot noise --- .github/dependabot.yml | 31 +++++++++++++++++++++++++++++-- 1 file changed, 29 insertions(+), 2 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 41c7ebc61..c4607a9e6 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,16 +1,43 @@ version: 2 +# Reference and docs for this file: +# https://docs.github.com/en/code-security/dependabot/working-with-dependabot/dependabot-options-reference + updates: + # group cargo deps into a single monthly PR + - package-ecosystem: "cargo" + directory: "/" + schedule: + interval: "monthly" + commit-message: + prefix: "build:" + groups: + deps: + patterns: + - "*" + ignore: + - dependency-name: git2 + - dependency-name: clap_mangen + + # flakey or problematic deps are still submitted individually - package-ecosystem: "cargo" directory: "/" schedule: - interval: "weekly" + interval: "monthly" commit-message: prefix: "build:" + allow: + - dependency-name: git2 + - dependency-name: clap_mangen + # group GH actions deps into a single monthly PR - package-ecosystem: "github-actions" directory: "/" schedule: - interval: "weekly" + interval: "monthly" commit-message: prefix: "build:" + groups: + actions-deps: + patterns: + - "*"