Skip to content

chore: restrict dependabot to security updates only#1395

Merged
sd-db merged 3 commits intomainfrom
sd-db/chore/dependabot-security-only
Apr 13, 2026
Merged

chore: restrict dependabot to security updates only#1395
sd-db merged 3 commits intomainfrom
sd-db/chore/dependabot-security-only

Conversation

@sd-db
Copy link
Copy Markdown
Collaborator

@sd-db sd-db commented Apr 13, 2026

Summary

  • Sets open-pull-requests-limit: 0 on both pip and github-actions ecosystems, which disables routine version-bump PRs while still allowing security update PRs (they bypass this limit)
  • Changes pip scanning interval from daily to weekly since it only matters for security scanning cadence now

Context

Closed 9 open dependabot PRs that were all routine version bumps with no security motivation. This config change prevents future noise.

@github-actions
Copy link
Copy Markdown

Coverage report

This PR does not seem to contain any modification to coverable code.

@sd-db sd-db merged commit ea6a384 into main Apr 13, 2026
10 checks passed
@sd-db sd-db deleted the sd-db/chore/dependabot-security-only branch April 13, 2026 17:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants