Skip to content

Build: Group Dependabot npm security update PRs - #5920

Merged
mgol merged 1 commit into
jquery:mainfrom
mgol:group-dependabot-security-prs
Oct 5, 2026
Merged

mgol merged 1 commit into
jquery:mainfrom
mgol:group-dependabot-security-prs

Conversation

@mgol

@mgol mgol commented Sep 30, 2026

Copy link
Copy Markdown
Member

Summary

We already have automatic Dependabot monthly updates of GitHub actions in a group but we haven't enabled automatic update PRs for npm packages as the volume would be too large; we only enabled security update PRs for those packages. Still, often we get multiple such security update PRs; this PR changes the logic to group them into a single PR as well.

In order for this config to not enable non-security automatic updates of all npm packages, we set open-pull-requests-limit to 0.

You can see an example grouped security update PR in my fork where I experimented first with this config: mgol#20

Checklist

We already have automatic Dependabot monthly updates of GitHub actions in
a group but we haven't enabled automatic update PRs for npm packages as the
volume would be too large; we only enabled security update PRs for those
packages. Still, often we get multiple such security update PRs; this PR changes
the logic to group them into a single PR as well.

In order for this config to not enable non-security automatic updates of all
npm packages, we set `open-pull-requests-limit` to 0.
@mgol

mgol commented Sep 30, 2026

Copy link
Copy Markdown
Member Author

Screenshot for posterity:
Screenshot 2026-09-30 at 23 29 19

@mgol mgol added the Discuss in Meeting Reserved for Issues and PRs that anyone would like to discuss in the weekly meeting. label Oct 1, 2026
@timmywil timmywil removed the Discuss in Meeting Reserved for Issues and PRs that anyone would like to discuss in the weekly meeting. label Oct 5, 2026
@mgol
mgol merged commit c2f2786 into jquery:main Oct 5, 2026
16 checks passed
@mgol mgol removed the Needs review label Oct 5, 2026
@mgol
mgol deleted the group-dependabot-security-prs branch October 5, 2026 22:06
mgol added a commit that referenced this pull request Oct 6, 2026
We already have automatic Dependabot monthly updates of GitHub actions in
a group but we haven't enabled automatic update PRs for npm packages as the
volume would be too large; we only enabled security update PRs for those
packages. Still, often we get multiple such security update PRs; this PR changes
the logic to group them into a single PR as well.

In order for this config to not enable non-security automatic updates of all
npm packages, we set `open-pull-requests-limit` to 0.

Closes gh-5920

(cherry picked from commit c2f2786)
@mgol

mgol commented Oct 6, 2026

Copy link
Copy Markdown
Member Author

Landed on main in c2f2786 & on 3.x-stable in afed296.

@mgol mgol added this to the 3.8.0 milestone Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Development

Successfully merging this pull request may close these issues.

2 participants