Skip to content

Run Dependabot independently on each branch - #158361

Open
hugovk wants to merge 1 commit into
python:mainfrom
hugovk:dependabot-multibranch
Open

hugovk wants to merge 1 commit into
python:mainfrom
hugovk:dependabot-multibranch

Conversation

@hugovk

@hugovk hugovk commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Rather than backporting Dependabot updates, which will pretty much always have conflicts due to different workflows, and which we often forget to do (causing more conflicts), let's have Dependabot run on each branch.

The config belongs in main, and unfortunately needs repeating, but each block is fairly small.

(Renovate would allow us to use a regex and avoid the repetition, but that's a bigger move involving installing a new app. But I'm a happy Renovate user in other projects, so it's always an option for later.)

@ezio-melotti ezio-melotti left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's unfortunate that there's no easy way to do it (unless target-branch: "3.*" works, but it's not documented).

This feature has been requested upstream before:

Here is the relevant documentation: https://docs.github.com/en/code-security/tutorials/secure-your-dependencies/customizing-dependabot-prs#targeting-pull-requests-against-a-non-default-branch

Also note this:

Dependabot raises pull requests for security updates against the default branch only. If you use target-branch, then as a result, all configuration settings for that package manager will then only apply to version updates, and not security updates.

Comment thread .github/dependabot.yml
cooldown:
default-days: 14

- package-ecosystem: "pip"

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would move this to the top, so that all the main sections are together. Perhaps it should also be duplicated for all branches.

Comment thread .github/dependabot.yml
Comment on lines +29 to +35
labels:
- "skip issue"
- "skip news"
groups:
actions:
patterns:
- "*"

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since we are duplicating all lines and readability is less of a concern, maybe we could use this compact form instead:

Suggested change
labels:
- "skip issue"
- "skip news"
groups:
actions:
patterns:
- "*"
labels: ["skip issue", "skip news"]
groups:
actions:
patterns: ["*"]

These could be further reduced to this if we wanted to:

Suggested change
labels:
- "skip issue"
- "skip news"
groups:
actions:
patterns:
- "*"
labels: ["skip issue", "skip news"]
groups: { actions: { patterns: ["*"] } }

If we applied the latter to the whole block, each block will only take 7 lines (instead of 14)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

awaiting merge infra CI, GitHub Actions, buildbots, Dependabot, etc. skip issue skip news

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants