Skip to content

ci: group Dependabot security updates to reduce PR noise - #26

Open
BreakableHoodie wants to merge 2 commits into
mainfrom
security/dependabot-grouping
Open

ci: group Dependabot security updates to reduce PR noise#26
BreakableHoodie wants to merge 2 commits into
mainfrom
security/dependabot-grouping

Conversation

@BreakableHoodie

Copy link
Copy Markdown
Contributor

Summary

Adds a dependabot.yml configuration that groups all security updates into a single PR per ecosystem, rather than one PR per package.

Ecosystems configured: npm

Without grouping, Dependabot opens one PR per vulnerable package — this repo could see many PRs at once as security scanning ramps up. Grouping batches them into one weekly PR that's easier to review and merge.

🤖 Generated with Claude Code

@vercel

vercel Bot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
project-pech-civictech Ready Ready Preview, Comment Jun 10, 2026 5:57pm

Request Review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant