Skip to content

Drop the Slack PR notifications and tune Dependabot - #135

Merged
selcukgural merged 1 commit into
mainfrom
ci/dependabot-tuning
Sep 24, 2026
Merged

selcukgural merged 1 commit into
mainfrom
ci/dependabot-tuning

Conversation

@selcukgural

Copy link
Copy Markdown
Owner

Summary

  • Remove .github/workflows/slack-pr-notify.yml (review-requested, merged and direct-push messages). The deploy summary message in deploy.yml stays.
  • Dependabot, docker: ignore Node major updates. The first proposal was node:25-alpine (Bump node from 22-alpine to 25-alpine in /web #119), an odd-numbered line that reached end of life on 2026-06-01; CI tests on Node 22 via setup-node, so the image bump was untested. Node upgrades happen deliberately (LTS only, image and CI together).
  • Dependabot, web: ignore eslint >= 10 — eslint-config-next's bundled eslint-plugin-react fails to load on it (Bump eslint from 9.39.5 to 10.11.0 in /web #124).
  • Dependabot, actions: group github/codeql-action* so init and analyze always share a version (Bump github/codeql-action/init from 3.38.2 to 4.38.1 #123 bumped only init, and analyze refused the newer config).

Test plan

  • dependabot.yml parses as YAML
  • CI green on this PR
  • After merge, Dependabot's next run no longer proposes a Node major or ESLint 10

🤖 Generated with Claude Code

- Remove slack-pr-notify.yml (review-requested, merged and direct-push
  messages); the deploy summary stays.
- Never propose a Node major for the images: Node moves deliberately, LTS
  lines only, together with CI's setup-node version.
- Hold ESLint 10 until eslint-config-next's react plugin loads on it.
- Group the CodeQL actions so init and analyze always move together.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant