From 41a1b80009bae3eb5bdde0d33966e82180bcd5ff Mon Sep 17 00:00:00 2001 From: Andrii Bodnar <29282228+andrii-bodnar@users.noreply.github.com> Date: Tue, 22 Sep 2026 12:01:26 +0300 Subject: [PATCH] chore: add Dependabot configuration Add monthly, grouped Dependabot updates for Gradle dependencies and GitHub Actions, so version bumps arrive as a single reviewable PR per ecosystem instead of surfacing later as security alerts. Routine version updates are limited to minor and patch, since the library targets Java 8 and major bumps of the test dependencies cannot merge. Security updates are grouped separately without that limit, so a fix released only in a major version still reaches us. Commit prefixes are set to chore and ci so the generated PR titles pass the semantic pull request title lint. Co-Authored-By: Claude Opus 5 (1M context) --- .github/dependabot.yml | 44 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 44 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 00000000..991cfb70 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,44 @@ +version: 2 + +updates: + # Gradle dependencies declared in build.gradle + - package-ecosystem: "gradle" + directory: "/" + schedule: + interval: "monthly" + commit-message: + prefix: "chore" + groups: + # One PR a month for all routine bumps. Major versions are left out: + # the library targets Java 8, so major bumps of the test dependencies + # cannot merge and would come back every month as noise. + gradle: + applies-to: version-updates + patterns: + - "*" + update-types: + - "minor" + - "patch" + # Security fixes are alert-driven, not monthly, and are not limited to + # minor/patch so a fix released only in a major version still arrives. + gradle-security: + applies-to: security-updates + patterns: + - "*" + + # Actions used by the workflows in .github/workflows + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "monthly" + commit-message: + prefix: "ci" + groups: + github-actions: + applies-to: version-updates + patterns: + - "*" + github-actions-security: + applies-to: security-updates + patterns: + - "*"