Dependabot 29 's version updates open pull requests that move dependencies to their newest releases on a schedule, vulnerable or not, so upgrades stay small. They are configured in .github/dependabot.yml:
# Dependabot version updates for BookNest: npm dependencies and the actions its workflows use.
version: 2
updates:
- package-ecosystem: npm
directory: /
schedule:
interval: weekly
day: monday
time: "06:00"
timezone: Asia/Kuala_Lumpur
groups:
npm-minor-and-patch:
update-types: [minor, patch]
open-pull-requests-limit: 5
labels: [dependencies]
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
labels: [dependencies]groups bundles minor and patch bumps into one weekly pull request, while a major version arrives alone for its own review; github-actions keeps uses: lines current, SHA pins (Code Scanning and SARIF) included. Dependabot ran as soon as the file reached main, as two Actions runs of its own:
for r in 36149499220 36149499341; do
gh run view $r --log | grep -o 'No update needed for .*' | sort -u; doneOutput
No update needed for express 5.2.1 No update needed for pg 8.23.0 No update needed for actions/checkout 7 ... No update needed for docker/setup-buildx-action 4
Nothing was out of date, so no pull request appeared. When one does, CI runs on it with a read-only token and only Dependabot's own secrets (Dependabot Secrets).