Skip to content

Conversation

@bkrem
Copy link
Member

@bkrem bkrem commented Nov 5, 2025

Summary

  • Configure Dependabot for daily dependency checks at 09:00 UTC
  • Group dev dependencies into single PRs for easier management
  • Enable auto-merge for patch and minor updates after CI passes
  • Require manual review for major version bumps

Configuration Details

Dependabot Settings:

  • Daily schedule with max 5 open PRs
  • Groups all devDependencies together (patch/minor only)
  • Production dependencies get individual PRs
  • Conventional commit format: chore(deps): ...

Auto-merge Behavior:

  • ✅ Patch updates (1.2.3 → 1.2.4): Auto-approved + auto-merged after CI
  • ✅ Minor updates (1.2.0 → 1.3.0): Auto-approved + auto-merged after CI
  • ❌ Major updates (1.0.0 → 2.0.0): Requires manual review

Expected Automation Level

~90% automation while maintaining control over breaking changes and release notes.

Note: Changesets are still required manually for production dependency updates before auto-merge completes.

Test Plan

  • Merge this PR
  • Wait for Dependabot to create first PRs
  • Verify auto-merge works for patch/minor updates
  • Verify major updates require manual review

- Add Dependabot configuration for daily dependency checks
- Group dev dependencies for easier management
- Configure auto-merge for patch and minor updates
- Require manual review for major version bumps
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants