Skip to content

chore(security): add 3-day Dependabot cooldown and grouped updates#41

Merged
felickz merged 2 commits into
mainfrom
copilot/edit-dependabot-config
May 26, 2026
Merged

chore(security): add 3-day Dependabot cooldown and grouped updates#41
felickz merged 2 commits into
mainfrom
copilot/edit-dependabot-config

Conversation

Copy link
Copy Markdown
Contributor

Copilot AI commented May 20, 2026

This updates Dependabot configuration to enforce a 3-day cooldown on automated update PRs while preserving existing grouping behavior per ecosystem. It also confirms package-lock.json is committed so CI npm ci remains deterministic.

  • Dependabot cadence hardening

    • Added cooldown.default-days: 3 to every entry under updates in .github/dependabot.yml.
  • Grouping behavior preserved

    • Existing groups blocks were left intact on both current entries (including github-actions), per requirement to avoid rewriting existing grouping definitions.
  • Deterministic Node install path

    • Confirmed package-lock.json is present and tracked in the repository for workflow consistency with .github/workflows/nodejs.yml.
updates:
  - package-ecosystem: npm
    directory: /
    schedule:
      interval: monthly
    cooldown:
      default-days: 3
    groups:
      dependencies:
        patterns:
          - '*'

@felickz
Copy link
Copy Markdown

felickz commented May 21, 2026

Copy link
Copy Markdown
Contributor Author

Copilot AI commented May 21, 2026

@copilot fix the failing CI (https://github.com/advanced-security/ghe-cross-instance-committers/actions/runs/26187443244/job/77256252377?pr=41) for this PR

Addressed in commit e9503e1.

I fixed the CI break by restoring ESLint v9 compatibility with the repo’s existing .eslintrc setup and adding jest-util as a direct dev dependency so ts-jest can resolve it during tests.

Copilot AI requested a review from felickz May 21, 2026 20:06
@felickz felickz merged commit ed50269 into main May 26, 2026
4 checks passed
@felickz felickz deleted the copilot/edit-dependabot-config branch May 26, 2026 19:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants