Skip to content

Conversation

@JoshLozensky
Copy link
Contributor

@JoshLozensky JoshLozensky commented Oct 23, 2024

Added grouping to dependabot config so PRs can contain multiple suggestions. The groupings are minor and patch updates with a security designation and minor and patch updates without a security designation. Major version updates will all still get their own PRs

Additionally, it will label grouped PRs with whether the updates are security-related or not based on the group names of security and notsecurity

@JoshLozensky JoshLozensky requested a review from a team as a code owner October 23, 2024 22:01
@westin-m
Copy link
Contributor

Note: more info in the docs if anyone is curious like I was: dependabot groups

@kllysng
Copy link
Contributor

kllysng commented Oct 23, 2024

My only concern is that it can get confusing to group updates, whereas separate PRs are very clear. We could see how this goes and always change back though. Thanks, @JoshLozensky!

Copy link
Collaborator

@jennyf19 jennyf19 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:shipit:

@JoshLozensky JoshLozensky merged commit f97314c into master Oct 24, 2024
5 checks passed
@JoshLozensky JoshLozensky deleted the lozensky/GroupDependabotUpdates branch October 24, 2024 18:36
This was referenced Nov 3, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants