Files
wickra/.github/dependabot.yml
T
kingchenc dd6a4affb2 ci(dependabot): group updates per ecosystem into a single PR (#288)
All nine Dependabot ecosystems now batch their updates into one grouped PR each
(`groups: { <name>: { patterns: ["*"] } }`) instead of one PR per dependency.

A routine refresh previously fanned out into a dozen-plus PRs (the Maven batch
alone opened 12), each running the full nine-language CI matrix (~55 checks) and
clogging the runner queue ahead of release and feature runs. Grouping collapses
that to one PR per ecosystem.

Trade-off: a single broken update blocks its whole group until excluded — fine
for routine maintenance bumps. Security updates are unaffected (they are not
grouped and continue to arrive individually).
2026-06-12 23:39:26 +02:00

144 lines
3.8 KiB
YAML

version: 2
updates:
# Rust workspace (root Cargo.toml + all member crates).
- package-ecosystem: cargo
directory: "/"
schedule:
interval: weekly
open-pull-requests-limit: 10
cooldown:
default-days: 7
commit-message:
prefix: "deps(cargo)"
groups:
cargo:
patterns: ["*"]
# Node binding npm dependencies.
- package-ecosystem: npm
directory: "/bindings/node"
schedule:
interval: weekly
open-pull-requests-limit: 10
cooldown:
default-days: 7
commit-message:
prefix: "deps(npm)"
groups:
node-binding:
patterns: ["*"]
# Python binding pip dependencies.
- package-ecosystem: pip
directory: "/bindings/python"
schedule:
interval: weekly
open-pull-requests-limit: 10
cooldown:
default-days: 7
commit-message:
prefix: "deps(pip)"
groups:
python-binding:
patterns: ["*"]
# Hash-pinned CI/bench Python tooling under .github/requirements/. Each
# <name>.in is the loose source; the matching hash-locked <name>.txt is the
# output regenerated by scripts/update-lockfiles.sh (uv). Dependabot keeps the
# pins fresh; ci-dev-py39.in caps numpy <2.1 so 3.9 stays installable. Any
# bump that breaks a matrix row surfaces in the PR's CI run.
- package-ecosystem: pip
directory: "/.github/requirements"
schedule:
interval: weekly
open-pull-requests-limit: 10
cooldown:
default-days: 7
commit-message:
prefix: "deps(ci-pip)"
groups:
ci-pip:
patterns: ["*"]
# GitHub Actions — keeps the SHA-pinned actions current (Dependabot reads
# the version comment after each pinned SHA and bumps both together).
- package-ecosystem: github-actions
directory: "/"
schedule:
interval: weekly
open-pull-requests-limit: 10
cooldown:
default-days: 7
commit-message:
prefix: "deps(actions)"
groups:
github-actions:
patterns: ["*"]
# Java binding + examples (Maven). Tracks the C-ABI binding's build plugins
# (e.g. central-publishing-maven-plugin) and the examples' jackson dependency,
# which had no Dependabot coverage before — a stale publishing plugin slipped
# through unnoticed until an OSV scan flagged it.
- package-ecosystem: maven
directories:
- "/bindings/java"
- "/bindings/java/benchmarks"
- "/examples/java"
schedule:
interval: weekly
open-pull-requests-limit: 10
cooldown:
default-days: 7
commit-message:
prefix: "deps(maven)"
groups:
maven:
patterns: ["*"]
# C# binding (NuGet). The published Wickra.csproj is a thin C-ABI wrapper with
# no external packages, but the test and benchmark projects pull xunit,
# Microsoft.NET.Test.Sdk and BenchmarkDotNet.
- package-ecosystem: nuget
directories:
- "/bindings/csharp/Wickra.Tests"
- "/bindings/csharp/benchmarks"
schedule:
interval: weekly
open-pull-requests-limit: 10
cooldown:
default-days: 7
commit-message:
prefix: "deps(nuget)"
groups:
nuget:
patterns: ["*"]
# Node examples (npm) — separate from the binding's own package.json.
- package-ecosystem: npm
directory: "/examples/node"
schedule:
interval: weekly
open-pull-requests-limit: 10
cooldown:
default-days: 7
commit-message:
prefix: "deps(npm)"
groups:
node-examples:
patterns: ["*"]
# Go examples (Go modules). The binding's own go.mod has no external deps;
# the examples pull coder/websocket.
- package-ecosystem: gomod
directory: "/examples/go"
schedule:
interval: weekly
open-pull-requests-limit: 10
cooldown:
default-days: 7
commit-message:
prefix: "deps(gomod)"
groups:
go-examples:
patterns: ["*"]