Skip to content

[MAINT]: Group Dependabot security minor patch updates#91

Merged
romanlutz merged 1 commit into
microsoft:mainfrom
spencrr:dev/spencrr/dependabot-security-groups
Jun 18, 2026
Merged

[MAINT]: Group Dependabot security minor patch updates#91
romanlutz merged 1 commit into
microsoft:mainfrom
spencrr:dev/spencrr/dependabot-security-groups

Conversation

@spencrr

@spencrr spencrr commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

Description

Adds explicit Dependabot security-minor-and-patch groups for configured ecosystems so minor and patch security updates can be grouped separately from normal version updates. Mirrors microsoft/PyRIT#2018.

This follows up on the recent separate Dependabot security PRs #85, #87, #88, #89, and #90. Those PRs were opened one dependency at a time because Dependabot groups.applies-to defaults to version-updates when omitted. GitHub's Dependabot options reference documents that applies-to supports both version-updates and security-updates.

The existing uv minor-and-patch group is preserved for normal version updates. This change adds a matching security-only minor/patch group for uv, plus security-only minor/patch groups for github-actions and pre-commit.

Major security updates are intentionally left ungrouped so higher-risk updates remain isolated for review.

References:

Breaking changes

None.

Checklist

  • pre-commit run --all-files passes
  • Tests added or updated for changes
  • Documentation updated

@spencrr spencrr requested a review from a team June 17, 2026 16:51
@romanlutz romanlutz merged commit 559fae8 into microsoft:main Jun 18, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants