Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot Grouped Security Updates [Public Beta] #831

Closed
github-product-roadmap opened this issue Nov 8, 2023 · 1 comment
Closed

Dependabot Grouped Security Updates [Public Beta] #831

github-product-roadmap opened this issue Nov 8, 2023 · 1 comment
Labels
cloud Available on Cloud dependabot Feature: GitHub Dependabot preview Feature phase: Preview shipped Shipped

Comments

@github-product-roadmap
Copy link
Collaborator

Summary

Dependabot security updates creates pull requests to update dependencies that have a vulnerability issued against it. It currently creates one pull request per dependency, but that results in a lot of noise for developers. With this feature, developers will be able to receive multiple security updates in a single pull request.

Intended Outcome

We would like to reduce the perceived "noise" of Dependabot (i.e. reduce the number of pull requests it opens) while increasing the merge rate of Dependabot pull requests (currently ~20%)

How will it work?

People will be able to turn this feature on from repository settings and then Dependabot will group multiple updates into single pull requests

@github github locked and limited conversation to collaborators Nov 8, 2023
@github-product-roadmap github-product-roadmap added preview Feature phase: Preview cloud Available on Cloud dependabot Feature: GitHub Dependabot labels Nov 8, 2023
@ankneis ankneis added the shipped Shipped label Dec 8, 2023
@ankneis
Copy link
Collaborator

ankneis commented Dec 8, 2023

@ankneis ankneis closed this as completed Dec 8, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
cloud Available on Cloud dependabot Feature: GitHub Dependabot preview Feature phase: Preview shipped Shipped
Development

No branches or pull requests

2 participants