Skip to content

Conversation

@k0kubun
Copy link
Member

@k0kubun k0kubun commented Aug 22, 2025

This PR adds dependabot.yml.

It appears that we currently trigger dependabot as frequently as possible, but none of updates seems urgent. As we use weekly updates in other repositories, it should be fine to follow it in this repository as well.

We also don't actually run JavaScript files when running benchmarks, so we shouldn't need to spend time updating that either. We use version tags in GitHub Actions too. So this PR deliberately configures only Bundler updates.

@k0kubun k0kubun marked this pull request as ready for review August 22, 2025 16:07
@k0kubun k0kubun enabled auto-merge (squash) August 22, 2025 16:07
@k0kubun k0kubun merged commit d9d9e97 into ruby:main Aug 22, 2025
4 checks passed
@k0kubun
Copy link
Member Author

k0kubun commented Aug 22, 2025

We also don't actually run JavaScript files when running benchmarks, so we shouldn't need to spend time updating that either.
...
So this PR deliberately configures only Bundler updates.

Well, it clearly didn't work as intended 😕

@k0kubun k0kubun deleted the dependabot-config branch August 22, 2025 17:09
@k0kubun
Copy link
Member Author

k0kubun commented Aug 22, 2025

I guess it keeps coming as long as they're for "vulnerabilities".

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant