chore(deps): batch Dependabot updates monthly - #18
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Routine dependency updates currently run weekly and open separate pull requests. This changes uv and GitHub Actions to one monthly batch per ecosystem with a seven-day release cooldown.
/for the sharedpyproject.tomlanduv.lock, and GitHub Actions at/for the workflows.monthly-batch, explicitly scoped toversion-updates..github/dependabot.yml; package versions, lockfiles, workflows, and generated catalogs remain unchanged.Validation passed: PyYAML parsing and Dependabot JSON schema; manifest locations, unique coverage, and security separation;
git diff --check; all README quality gates (lock check, Ruff format/lint, ty, skill validation, catalog generation, build); 317 offline tests with 100% statement and branch coverage, with the Test DC test skipped. Installed the built wheel in an isolated environment and verified schema-versioned JSON with empty stderr.Security settings were already enabled: vulnerability alerts returned HTTP 204; automated security fixes returned
enabled: true, paused: false; GraphQL confirmedhasVulnerabilityAlertsEnabled: trueand five dependency graph manifests. GitHub currently reports zero dependencies for each manifest, so this verifies the enabled settings and manifest visibility, not complete dependency ingestion or the absence of vulnerabilities. No security setting change was necessary.The alerts API also reports one existing open high-severity alert. Remediating it would require a separate dependency update and is outside this configuration-only change.