From 0d314ea63178de2bb44865d98c35fbb7affd07c5 Mon Sep 17 00:00:00 2001 From: Dan Guido Date: Sun, 14 Dec 2025 19:58:02 -0500 Subject: [PATCH] Add cooldown and grouping to Dependabot config (#14931) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Add 7-day cooldown to protect against supply chain attacks - Group updates by ecosystem to reduce PR noise - Change schedule from daily to weekly - Add Docker ecosystem for base image updates 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 4.5 --- .github/dependabot.yml | 24 ++++++++++++++++++++++-- 1 file changed, 22 insertions(+), 2 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 1b7c0da8..e7d98836 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -5,7 +5,13 @@ updates: - package-ecosystem: "github-actions" directory: "/" schedule: - interval: "daily" + interval: "weekly" + cooldown: + default-days: 7 + groups: + github-actions: + patterns: + - "*" # Maintain dependencies for Python using uv # Using "uv" ecosystem ensures both pyproject.toml AND uv.lock are updated together @@ -13,4 +19,18 @@ updates: - package-ecosystem: "uv" directory: "/" schedule: - interval: "daily" + interval: "weekly" + cooldown: + default-days: 7 + groups: + python: + patterns: + - "*" + + # Maintain Docker base image (python:3.12-alpine) + - package-ecosystem: "docker" + directory: "/" + schedule: + interval: "weekly" + cooldown: + default-days: 7