Skip to content

Update dependabot.yml#207

Merged
glenn-jocher merged 1 commit intomainfrom
glenn-jocher-patch-1
Nov 1, 2025
Merged

Update dependabot.yml#207
glenn-jocher merged 1 commit intomainfrom
glenn-jocher-patch-1

Conversation

@glenn-jocher
Copy link
Member

@glenn-jocher glenn-jocher commented Nov 1, 2025

🛠️ PR Summary

Made with ❤️ by Ultralytics Actions

🌟 Summary

Dependabot update cadence is increased from monthly to weekly for Swift and GitHub Actions dependencies ⏱️🔄

📊 Key Changes

  • Dependabot schedule changed from monthly to weekly for:
    • Swift package ecosystem at repository root
    • GitHub Actions in .github/workflows
  • Check time remains 04:00; open PR limit stays at 3
  • Existing labels and configuration untouched

🎯 Purpose & Impact

  • Faster delivery of dependency updates and security patches ⚡
  • Smaller, more frequent PRs that are easier to review and merge ✅
  • Improved CI reliability by keeping GitHub Actions up to date 🔧
  • Slightly higher PR volume; maintainers may need to triage updates weekly 📬
  • No app code changes; no direct user-facing impact today, but better long-term stability and security 🔒

Signed-off-by: Glenn Jocher <glenn.jocher@ultralytics.com>
@glenn-jocher glenn-jocher temporarily deployed to Release - TestFlight November 1, 2025 05:17 — with GitHub Actions Inactive
@UltralyticsAssistant UltralyticsAssistant added dependencies Dependencies and packages devops GitHub Devops or MLops labels Nov 1, 2025
@UltralyticsAssistant
Copy link
Member

👋 Hello @glenn-jocher, thank you for submitting a ultralytics/yolo-ios-app 🚀 PR! This is an automated message; an engineer will assist shortly. To ensure a seamless integration of your work, please review the following checklist:

  • Define a Purpose: Clearly explain the purpose of your fix or feature in your PR description, and link to any relevant issues. Ensure your commit messages are clear, concise, and adhere to the project's conventions.
  • Synchronize with Source: Confirm your PR is synchronized with the ultralytics/yolo-ios-app main branch. If it's behind, update it by clicking the 'Update branch' button or by running git pull and git merge main locally.
  • Ensure CI Checks Pass: Verify all Ultralytics Continuous Integration (CI) checks are passing. If any checks fail, please address the issues.
  • Update Documentation: Update the relevant documentation for any new or modified features.
  • Add Tests: If applicable, include or update tests to cover your changes, and confirm that all tests are passing.
  • Sign the CLA: Please ensure you have signed our Contributor License Agreement if this is your first Ultralytics PR by writing "I have read the CLA Document and I sign the CLA" in a new message.
  • Minimize Changes: Limit your changes to the minimum necessary for your bug fix or feature addition. "It is not daily increase but daily decrease, hack away the unessential. The closer to the source, the less wastage there is." — Bruce Lee

For more guidance, please refer to our Contributing Guide. Don't hesitate to leave a comment if you have any questions. Thank you for contributing to Ultralytics! 🚀

Copy link
Member

@UltralyticsAssistant UltralyticsAssistant left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 PR Review

Made with ❤️ by Ultralytics Actions

Looks good! Thanks for increasing our Dependabot cadence to weekly.

@codecov
Copy link

codecov bot commented Nov 1, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@glenn-jocher glenn-jocher merged commit afcb4fe into main Nov 1, 2025
8 checks passed
@glenn-jocher glenn-jocher deleted the glenn-jocher-patch-1 branch November 1, 2025 05:19
@UltralyticsAssistant
Copy link
Member

Merged with momentum! 🚀 Huge thanks, @glenn-jocher, for elevating our maintenance cadence in PR #207.

“Great things are done by a series of small things brought together.” — Vincent van Gogh

Shifting Dependabot to weekly keeps our Swift and GitHub Actions dependencies fresh, security patches flowing, and CI humming—smaller, faster reviews that compound into long-term stability. Appreciate the thoughtful guardrails (04:00 checks, PR limit of 3) to balance speed with signal. 🙌

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependencies and packages devops GitHub Devops or MLops

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants