Skip to content

ci(dependabot): only open PRs for security updates - #258

Merged
ximing merged 1 commit into
masterfrom
chore/dependabot-security-only
Sep 1, 2026
Merged

ci(dependabot): only open PRs for security updates#258
ximing merged 1 commit into
masterfrom
chore/dependabot-security-only

Conversation

@ximing

@ximing ximing commented Sep 1, 2026

Copy link
Copy Markdown
Owner

Summary

Dependabot 不再追最新版,只保留安全升级。

#210(changeset 发版)不是第三方依赖升级,本 PR 不动它。

Test plan

  • 对照 GitHub 文档:open-pull-requests-limit: 0 只停 version updates
  • gh api 确认 dependabot_security_updates.status == enabled、open alerts = 0

Stop weekly version-chasing PRs (`open-pull-requests-limit: 0`).
GitHub Dependabot security updates stay enabled and still open
PRs when there is a GHSA. Do not `@dependabot ignore` packages —
that would also suppress security patches.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant