Skip to content

chore: group Dependabot security updates and add a 3-day cooldown - #120

Merged
arodiss merged 1 commit into
mainfrom
gleb/dependabot-security-groups-cooldown
Oct 6, 2026
Merged

arodiss merged 1 commit into
mainfrom
gleb/dependabot-security-groups-cooldown

Conversation

@arodiss

@arodiss arodiss commented Oct 6, 2026

Copy link
Copy Markdown

Summary

  • Security updates are grouped for npm, uv and GitHub Actions. An advisory burst now lands as one PR per ecosystem instead of one per package. Docker, docker-compose and Terraform get no security group, because GitHub publishes no advisories for those ecosystems.
  • Every entry has a 3-day cooldown. A new release has to be public for 3 days before Dependabot proposes it, so a hijacked version is usually pulled from the registry first. Cooldown never delays a security update.

This matches the same change in opencodos/AITaaS#2910.

Verification

  • uvx check-jsonschema --builtin-schema vendor.dependabot passes on the new file. A copy with typos in both new keys fails it, so the schema does check them.

🤖 Generated with Claude Code

Security updates were the one Dependabot path with no groups, so an
advisory burst opened one pull request per package. npm, uv and GitHub
Actions now group them into one pull request per ecosystem.

Every entry now also waits 3 days before proposing a new release. A
hijacked version is usually pulled from the registry within that window.
Cooldown never delays a security update.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Warning

Review paused — included plan limit reached

Keep your review moving with free on-demand reviews.

  • Run this review for free

On-demand reviews are free for the next 4 days.

  • Ask an admin to make reviews automatic

Open in CodeRabbit

Reviews can continue after your included limit without a manual trigger. An admin must approve usage-based billing.

Promotion and pricing details

On-demand reviews are free for the next 4 days. After that, they cost $0.25 per reviewed file.

Review limit details

Or wait 58 minutes for your next included review.

Check out review usage here.

Limit details: You’ve used all 2 included reviews currently available. Your 81 included PR review attempts over the past 7 days set your current allowance at 2 reviews per hour.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Team
  • Run ID: 0cf0a470-ce57-4ca0-bc6a-cbc78ef064d3
📥 Commits

Reviewing files that changed from the base of the PR and between 6808370 and a9735de.

📒 Files selected for processing (1)
  • .github/dependabot.yml
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@codos-reviewer codos-reviewer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking: 0 · Non-blocking: 0

The security groups target security updates separately from the existing version-update groups, and the cooldown is supported across the configured ecosystems without delaying security updates. Note: GitHub already applies a three-day default cooldown to version updates, so these entries make that policy explicit rather than changing the current delay.

@arodiss
arodiss merged commit bb9c9e3 into main Oct 6, 2026
11 checks passed
@arodiss
arodiss deleted the gleb/dependabot-security-groups-cooldown branch October 6, 2026 16:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant