Skip to content

Conversation

@ericstj
Copy link
Member

@ericstj ericstj commented Jul 7, 2025

Configure dependabot for public dependency updates. This will help this repo stay up to date with public dependencies.

We'll still need to review dependency PRs, and mirror packages to our feeds, but this will help ensure we stay up to date.

@ericstj ericstj requested review from Copilot and tarekgh July 7, 2025 18:09
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Adds a Dependabot configuration to enable weekly NuGet dependency updates.

  • Introduces a new .github/dependabot.yml file
  • Configures Dependabot to check the root directory for NuGet manifests on a weekly schedule

- package-ecosystem: "nuget"
directory: "/" # Location of package manifests
schedule:
interval: "weekly"
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

does it cost much if we enable running it daily instead?

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That's too often, we have to review the PRs and merge them. I don't want daily PRs if dependencies update that often. Weekly is fine.

Copy link
Member

@tarekgh tarekgh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@ericstj
Copy link
Member Author

ericstj commented Jul 9, 2025

/ba-g checks are skipped for workflow only PRs.

@ericstj ericstj merged commit 03a691c into main Jul 9, 2025
4 checks passed
@ericstj
Copy link
Member Author

ericstj commented Jul 9, 2025

@ericstj ericstj deleted the ericstj-dependabot branch July 28, 2025 15:30
@github-actions github-actions bot locked and limited conversation to collaborators Aug 28, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants