From 5e148a4cff3bcdf230186e7e0ceddea94ba43ee9 Mon Sep 17 00:00:00 2001 From: Nikita Kalyazin Date: Mon, 28 Sep 2026 17:38:48 +0100 Subject: [PATCH] ci: group Dependabot's action updates into one pull request Ungrouped, Dependabot files one pull request per action path. The three codeql-action paths share a revision and the action refuses a run whose halves disagree, so the split bumps arrived red and could not land individually. The shape test's allowlist compares dependabot.yml whole, so it moves in the same commit. Signed-off-by: Nikita Kalyazin --- .github/dependabot.yml | 3 +++ .github/scripts/security-workflow.test.py | 3 ++- 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index a71cb44..12a5971 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -5,3 +5,6 @@ updates: schedule: interval: "weekly" day: "monday" + groups: + actions: + patterns: ["*"] diff --git a/.github/scripts/security-workflow.test.py b/.github/scripts/security-workflow.test.py index 2337a08..dd76873 100755 --- a/.github/scripts/security-workflow.test.py +++ b/.github/scripts/security-workflow.test.py @@ -121,7 +121,8 @@ # lockfile owning dependency versions. DEPENDABOT = { "version": 2, - "updates": [{"package-ecosystem": "github-actions", "directory": "/", "schedule": {"interval": "weekly", "day": "monday"}}], + "updates": [{"package-ecosystem": "github-actions", "directory": "/", "schedule": {"interval": "weekly", "day": "monday"}, + "groups": {"actions": {"patterns": ["*"]}}}], } failures = []