Repository navigation
Configure Dependabot for automated dependency updates - #99
Conversation
The repo had no dependabot.yml, so the only Dependabot activity was security updates enabled in the repository settings, one PR per package. Version updates for npm and GitHub Actions (workflows plus the composite setup action) now run monthly. Each ecosystem opens at most two PRs a run: minor and patch bumps together, majors in a separate group. npm security updates are grouped along the same line; they still open when an advisory lands, since the schedule doesn't apply to them. DEVELOPMENT.md documents the cadence and the lockfile re-shake those PRs need; ARCHITECTURE.md drops Dependabot from its future-work list. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EDadxCzrbML6jH3mM4J54d
|
Policy events audit (scheduled check, unrelated to this PR's Dependabot changes — flagging here since no other PR touches A real, dated fee change takes effect today that Needed:
|
Summary
This PR sets up Dependabot to automatically check for npm package and GitHub Actions updates on a monthly schedule, with security updates enabled in repository settings to open immediately when advisories are published.
Key Changes
.github/dependabot.yml: Configures Dependabot to run monthly checks for npm packages and GitHub Actions, grouped by update type (minor/patch vs major) to limit the number of PRs per ecosystem per run. Security updates are grouped along the same minor/patch vs major line.DEVELOPMENT.md: Added "Automated Updates" section documenting the Dependabot schedule, grouping strategy, and the requirement to re-shake npm lockfiles before CI passes.ARCHITECTURE.md: Removed "Dependencies — Automated dependency update checks (Dependabot)" from the Future Improvements list since this is now implemented.Implementation Details
npm installlocally to update the lockfile beforeverify.yamlpasses, as Dependabot installs without lifecycle scriptshttps://claude.ai/code/session_01EDadxCzrbML6jH3mM4J54d