chore: enable Dependabot for automated dependency updates#1498
Open
jsonmp-k8 wants to merge 1 commit intokagent-dev:mainfrom
Open
chore: enable Dependabot for automated dependency updates#1498jsonmp-k8 wants to merge 1 commit intokagent-dev:mainfrom
jsonmp-k8 wants to merge 1 commit intokagent-dev:mainfrom
Conversation
Contributor
There was a problem hiding this comment.
Pull request overview
Adds a Dependabot configuration to automate dependency update PRs across the repository’s primary ecosystems (CI actions, Go, Python, UI, and Docker images), aiming to keep dependencies current with reduced PR noise via grouping.
Changes:
- Introduces
.github/dependabot.ymlwith weekly scheduled update checks. - Configures grouping for minor/patch updates for GitHub Actions, Go modules, Python (pip), and npm.
- Adds Docker update scanning for multiple Dockerfile directories and assigns default labels/reviewers.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
860c5d9 to
fdb98a0
Compare
Add .github/dependabot.yml to automatically create PRs for outdated and vulnerable dependencies across all ecosystems in the repo. Ecosystems configured: - GitHub Actions: CI workflows - Go modules: /go - Python (uv): all 9 workspace packages and 6 samples/tests - npm: Next.js UI - Docker: all production, devcontainer, sample, and e2e Dockerfiles Configuration: - Weekly schedule (Monday) for all ecosystems - Minor/patch updates grouped per ecosystem to reduce PR noise - Commit prefix chore(deps): for consistency with repo conventions - Reviewers assigned per CODEOWNERS - Template Dockerfiles (.tmpl) and vendored deps excluded Signed-off-by: Jaison Paul <paul.jaison@gmail.com>
ccc3995 to
57bc605
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
.github/dependabot.ymlto automatically create PRs for outdated and vulnerable dependencies across all ecosystems in the repoEcosystems Configured
github-actions/gomod/gopip/pythonnpm/uidocker/godocker/pythondocker/uidocker/docker/skills-initConfiguration Details
dependencieson all PRschore(deps):for consistency with repo conventionsVerification
After merge:
Notes
pipecosystem entry points at/pythonwhere the UV workspacepyproject.tomllives. If Dependabot doesn't pick up sub-packages underpython/packages/, separate entries can be added in a follow-up