From f910f7d8a35c9cf531812c30b2e38b3a6a63c8f2 Mon Sep 17 00:00:00 2001 From: Shuxin Lin Date: Tue, 6 Oct 2026 16:11:59 -0400 Subject: [PATCH] chore: run Renovate weekly and leave security PRs to Dependabot IBM's enforced security configuration keeps Dependabot security updates on, and the repo cannot turn them off. Renovate was also opening security PRs, so the same package got two PRs. - schedule:weekly: version update PRs only before 4am UTC on Mondays - group:allNonMajor: one PR for all minor/patch updates; majors stay separate - :maintainLockFilesWeekly: weekly uv.lock refresh to pick up patched transitive dependencies - vulnerabilityAlerts disabled: Dependabot owns security PRs Signed-off-by: Shuxin Lin --- renovate.json | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/renovate.json b/renovate.json index 5db72dd6a..fed352737 100644 --- a/renovate.json +++ b/renovate.json @@ -1,6 +1,12 @@ { "$schema": "https://docs.renovatebot.com/renovate-schema.json", "extends": [ - "config:recommended" - ] + "config:recommended", + "schedule:weekly", + "group:allNonMajor", + ":maintainLockFilesWeekly" + ], + "vulnerabilityAlerts": { + "enabled": false + } }