Skip to content

Bundle Dependabot updates and auto-merge passing PRs - #84

Merged
frostevent merged 1 commit into
mainfrom
jeremie/dependabot-auto-merge
Oct 10, 2026
Merged

frostevent merged 1 commit into
mainfrom
jeremie/dependabot-auto-merge

Conversation

@frostevent

Copy link
Copy Markdown
Collaborator

Reduces Dependabot PR noise: updates are grouped more broadly, and passing minor/patch PRs merge themselves.

Dependabot config (weekly cadence kept)

  • npm: three groups, npm-minor-patch, npm-major, npm-security (applies-to: security-updates), so security advisories are bundled instead of opening one PR each.
  • The / and /site npm entries are combined into one entry with directories.
  • GitHub Actions: actions-minor-patch and actions-major, so majors are grouped too.
  • 7-day cooldown on every ecosystem, since auto-merge would otherwise merge a version published the same week.

Auto-merge workflow

.github/workflows/dependabot-auto-merge.yml runs only when both the PR author and the actor are dependabot[bot]. It reads dependabot/fetch-metadata@v3 and, for minor and patch updates, approves the PR and enables squash auto-merge. The PR merges once the required checks pass. Majors and failing PRs still need a human.

For a grouped PR, fetch-metadata reports the highest update type in the group, which is why majors are in their own group.

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@frostevent
frostevent merged commit 2d7a009 into main Oct 10, 2026
14 checks passed
@frostevent
frostevent deleted the jeremie/dependabot-auto-merge branch October 10, 2026 12:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant