From a7bd4b5529c421f135da7bd511961d9ea11b2c95 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Moritz=20M=C3=A4hr?= <14755525+maehr@users.noreply.github.com> Date: Wed, 12 Aug 2026 23:38:12 +0200 Subject: [PATCH] ci(deps): point Dependabot version updates at staging (#32) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `main` only moves at release time, by squash-merging `staging`. A bump that lands on `main` alone is reverted by the next release, because the squash applies staging's tree against a merge base that predates it — which is how ten dependabot PRs accumulated against a branch that could not keep them. Also adds the npm ecosystem, which had no entry at all: every npm PR in the queue arrived as a security update rather than a version update, so ordinary dependency drift was only ever caught by an advisory. Astro, Starlight and their plugins are grouped, since they resolve together. Security updates still target the default branch — `target-branch` does not apply to them — so advisory PRs will keep appearing against `main`. --- .github/dependabot.yml | 30 ++++++++++++++++++++++++++++++ 1 file changed, 30 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index f94564f..cf2d947 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,10 +1,40 @@ +# Version updates target `staging`, not the default branch. +# +# `main` only moves at release time, by squash-merging `staging`. A bump landed +# on `main` alone is therefore reverted by the next release: the squash applies +# staging's tree against a merge base that predates the bump. Everything that +# should survive a release has to reach `main` through `staging`. +# +# Note that `target-branch` governs version updates only — Dependabot security +# updates are always raised against the default branch, so advisory-driven PRs +# will still appear against `main` and still need folding into `staging` by +# hand. version: 2 updates: - package-ecosystem: github-actions directory: / + target-branch: staging schedule: interval: weekly groups: github-actions: patterns: - '*' + + - package-ecosystem: npm + directory: / + target-branch: staging + schedule: + interval: weekly + groups: + # Astro, Starlight and their plugins move in lockstep and are upgraded + # together or not at all; a lone bump here usually fails to resolve. + astro: + patterns: + - 'astro' + - '@astrojs/*' + - 'starlight*' + # First match wins, so this picks up everything else in one PR. + npm: + patterns: + - '*'