From 8c8c5240365fe71c4ab031db0747aabcd097b698 Mon Sep 17 00:00:00 2001 From: Tim Haines Date: Thu, 23 Jul 2026 16:25:27 +1200 Subject: [PATCH] Add Dependabot config for uv and GitHub Actions updates Adds .github/dependabot.yml so uv dependencies and GitHub Actions stay current automatically, complementing the existing pre-commit.ci hook autoupdates. uv updates are ungrouped (per-package, capped at 5/week) so each can be reviewed and CI-tested on its own; Actions are grouped into one weekly PR. A short 7-day cooldown lets new releases age before a PR opens, with cryptography excluded so security fixes aren't delayed. Dependabot is also told to respect the deliberate version caps in pyproject.toml -- cryptography <49 (#859), openai <2.45 (#748), and the openai-agents ==0.14.6 migration pin -- so it doesn't open bumps past them that would only fail CI or be closed. Co-Authored-By: Claude Opus 4.8 (1M context) --- .github/dependabot.yml | 40 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 40 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 000000000..ad4aba24d --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,40 @@ +version: 2 +updates: + # Python dependencies (uv is a first-class Dependabot ecosystem). + # Ungrouped so each update is its own PR — easier to review and to run + # against CI individually; capped so the weekly volume stays sane. + - package-ecosystem: "uv" + directory: "/" + schedule: + interval: "weekly" + open-pull-requests-limit: 5 + cooldown: + default-days: 7 # let a new release age a little before a PR opens + exclude: ["cryptography"] # ...but security-critical patches land fast + ignore: + # Respect the deliberate version caps in pyproject.toml so Dependabot + # doesn't open bumps past them (they'd only fail CI or be closed). + # In-range (patch/minor) updates below each cap still flow normally. + - dependency-name: "cryptography" + versions: [">=49"] # 49.x drops the universal2 macOS wheel (#859) + - dependency-name: "openai" + versions: [">=2.45"] # fresh-install compatibility cap (#748) + - dependency-name: "openai-agents" + versions: [">0.14.6"] # exact-pinned during the SDK migration + + # GitHub Actions in the release workflow — grouped into one weekly PR. + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" + groups: + actions: + patterns: ["*"] + cooldown: + default-days: 7 + + # Sandbox image base — enable once it's pinned off ':latest'. + # - package-ecosystem: "docker" + # directory: "/containers" + # schedule: + # interval: "weekly"