Skip to content

ci: limit dependabot majors, fix deploy doc drift - #389

Merged
FlyM1ss merged 2 commits into
mainfrom
ci/dependabot-ignore-majors
Jul 31, 2026
Merged

FlyM1ss merged 2 commits into
mainfrom
ci/dependabot-ignore-majors

Conversation

@FlyM1ss

@FlyM1ss FlyM1ss commented Jul 31, 2026 •

Copy link
Copy Markdown
Collaborator

Cleanup of #364's fallout.

dependabot.yml shipped without a major-version guard, and its first run opened 21 PRs (#365–#385) — the backlog of a repo that had never run scheduled updates. Ten carried majors behind green checks (checkout 4→7, gunicorn 25→26, ssh-action 0.1→1.2); the eight frontend/docs ones had no CI at all. Now: ignore semver-major on all six ecosystems, open-pull-requests-limit → 3 everywhere.

Security updates are unaffected — ignore and the PR limit are version-update options only. Take a major deliberately with @dependabot reopen, or by dropping that dependency's ignore entry.

Deploy/README.md still described a push-only workflow running uv sync --frozen; #364 added a pull_request trigger (validate-only, GHCR steps event-gated) and switched CI to --locked.

#365–#385 are closed, all recoverable via @dependabot reopen.

🤖 Generated with Claude Code

https://claude.ai/code/session_01YcHJNusN3sWaafk5RY3nYq

The config landed in #364 with no major-version guard and immediately opened
21 PRs (#365-#385) -- the accumulated backlog of a repo that had never run
scheduled version updates. Ten showed green checks while carrying majors
(actions/checkout 4->7, gunicorn 25->26, appleboy/ssh-action 0.1->1.2); eight
frontend/docs PRs had no CI at all.

Ignore semver-major across all six ecosystems and drop every
open-pull-requests-limit to 3. Security updates are unaffected -- ignore and
the PR limit are version-update options only.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YcHJNusN3sWaafk5RY3nYq
This was referenced Jul 31, 2026
Deploy/README.md still described a push-only workflow running `uv sync
--frozen`. Since #364 it also runs on pull_request (validate-only, GHCR
steps event-gated) and syncs with `--locked`. Note the deploy job's
ref-gate to main while here.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YcHJNusN3sWaafk5RY3nYq
@FlyM1ss FlyM1ss changed the title ci: limit dependabot to non-major updates ci: limit dependabot majors, fix deploy doc drift Jul 31, 2026
@FlyM1ss
FlyM1ss merged commit 7309e8c into main Jul 31, 2026
4 checks passed
@FlyM1ss
FlyM1ss deleted the ci/dependabot-ignore-majors branch July 31, 2026 05:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant