Skip to content

Stop Dependabot proposing major versions and cap its open PRs - #138

Merged
selcukgural merged 1 commit into
mainfrom
ci/dependabot-no-majors
Sep 24, 2026
Merged

selcukgural merged 1 commit into
mainfrom
ci/dependabot-no-majors

Conversation

@selcukgural

Copy link
Copy Markdown
Owner

Summary

  • Ignore version-update:semver-major for every ecosystem (actions, nuget, npm web/extension/postman, docker). Majors are planned by hand so related pieces move together (Node image + CI setup-node, CodeQL init + analyze, StackExchange.Redis + the packages built on it).
  • open-pull-requests-limit: 2 per ecosystem.
  • The Node and ESLint specific ignores from Drop the Slack PR notifications and tune Dependabot #135 are folded into the wildcard.
  • Security updates are a repository setting and are not affected.

The first Dependabot round's major PRs (#126, #127, #130–#134, #137) and the 27-package NuGet group (#129) were closed.

Test plan

  • dependabot.yml parses as YAML
  • Dependabot's next run opens no major-version PRs

🤖 Generated with Claude Code

Majors are planned changes that move related pieces together; minor
and patch updates keep coming, grouped, at most two open PRs per
ecosystem. Security updates are unaffected.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@selcukgural
selcukgural merged commit 3556305 into main Sep 24, 2026
6 checks passed
@selcukgural
selcukgural deleted the ci/dependabot-no-majors branch September 24, 2026 20:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant