Dependabot Version Updates

Dependabot 29 's version updates open pull requests that move dependencies to their newest releases on a schedule, vulnerable or not, so upgrades stay small. They are configured in .github/dependabot.yml:

.github/dependabot.ymlYAML
# Dependabot version updates for BookNest: npm dependencies and the actions its workflows use.
version: 2
updates:
  - package-ecosystem: npm
    directory: /
    schedule:
      interval: weekly
      day: monday
      time: "06:00"
      timezone: Asia/Kuala_Lumpur
    groups:
      npm-minor-and-patch:
        update-types: [minor, patch]
    open-pull-requests-limit: 5
    labels: [dependencies]
  - package-ecosystem: github-actions
    directory: /
    schedule:
      interval: weekly
    labels: [dependencies]

groups bundles minor and patch bumps into one weekly pull request, while a major version arrives alone for its own review; github-actions keeps uses: lines current, SHA pins (Code Scanning and SARIF) included. Dependabot ran as soon as the file reached main, as two Actions runs of its own:

What Dependabot's first npm and Actions runs decided
for r in 36149499220 36149499341; do
  gh run view $r --log | grep -o 'No update needed for .*' | sort -u; done
Output
No update needed for express 5.2.1
No update needed for pg 8.23.0
No update needed for actions/checkout 7
...
No update needed for docker/setup-buildx-action 4

Nothing was out of date, so no pull request appeared. When one does, CI runs on it with a read-only token and only Dependabot's own secrets (Dependabot Secrets).