Skip to content

chore: sync canonical dependabot config with all supported ecosystems - #133

Merged
gvatsal60 merged 1 commit into
masterfrom
chore/dependabot-canonical/master
Oct 4, 2026
Merged

gvatsal60 merged 1 commit into
masterfrom
chore/dependabot-canonical/master

Conversation

@gvatsal60

Copy link
Copy Markdown
Owner

Summary

Replaces .github/dependabot.yaml with the canonical fleet-wide Dependabot configuration so this branch matches every other branch in every repository.

  • Target branch: master
  • Source branch: chore/dependabot-canonical/master

Why

The audit found 14 divergent versions of .github/dependabot.yaml across the fleet, and only 8 of the 33 package ecosystems supported by Dependabot were configured anywhere:

bundler, devcontainers, docker, docker-compose, github-actions, pip, pre-commit, uv

Drift came from a mix of unquoted vs quoted interval, present/absent header comments, and per-repo ecosystem additions.

What changed

One file, .github/dependabot.yaml, now lists all 33 supported ecosystems, each with directory: "/" and the schedule interval: "weekly", day: "saturday", time: "09:00":

bazel, bun, bundler, cargo, composer, conda, deno, devcontainers, docker, docker-compose, dotnet-sdk, elm, gitsubmodule, github-actions, gomod, gradle, helm, julia, mix, maven, nix, npm, nuget, opentofu, pip, pre-commit, pub, rust-toolchain, sbt, swift, terraform, uv, vcpkg

Ecosystems with no manifest in this repository are inert: Dependabot resolves no dependencies for them and opens no pull request.

Verification

  • Parses as valid YAML (version: 2, 33 updates entries)
  • Compliant with the repo pre-commit stack: double-quote-string-fixer (double quotes), yamlfmt (2-space indent), .yamllint.yaml (max line length 112 ≤ 200)
  • Byte-identical to the canonical file in all 58 branches across 35 repositories

Reference

Copilot AI balanced review requested due to automatic review settings October 4, 2026 05:10

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@sonarqubecloud

sonarqubecloud Bot commented Oct 4, 2026

Copy link
Copy Markdown

@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@gvatsal60
gvatsal60 merged commit f47e437 into master Oct 4, 2026
12 checks passed
@gvatsal60
gvatsal60 deleted the chore/dependabot-canonical/master branch October 4, 2026 05:22
@kilo-code-bot

kilo-code-bot Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Note: PR #133 is already in MERGED state at the time of this review; findings below reflect head commit 3b219d0.

Files Reviewed (1 file)
  • .github/dependabot.yaml

Verification notes

  • All 33 updates entries are structurally identical and consistent (directory: "/", interval: "weekly", day: "saturday", time: "09:00").
  • Every package-ecosystem value is a supported Dependabot identifier (incl. docker-compose, gitsubmodule, opentofu, rust-toolchain, vcpkg, pre-commit); no invalid/typo'd values.
  • Manifests present in this repo are covered correctly: .pre-commit-config.yaml and .devcontainer/ at root match pre-commit and devcontainers with directory: "/".
  • Remaining ecosystems have no manifest here and resolve to no updates; pip and uv are both inert (no pyproject.toml/requirements.txt at root), so no duplicate-update risk is introduced today.
  • YAML shape is valid and within the repo's .yamllint.yaml line-length limit of 200.

Reviewed by free · Input: 37K · Output: 3K · Cached: 104.7K

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants