Skip to content

CCM-23641: Updating Dependabot config - #723

Merged
karlmcgi merged 1 commit into
mainfrom
feature/CCM-22644_Dependabot_Config_Updates
Oct 8, 2026
Merged

karlmcgi merged 1 commit into
mainfrom
feature/CCM-22644_Dependabot_Config_Updates

Conversation

@karlmcgi

@karlmcgi karlmcgi commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Description

Introducing the following changes:

  • Adding grouping according to major and minor/patch semver versions for each package ecosystem
  • Updating each ecosystem to refer to directories for recursive scanning
  • Grouping specific npm ecosystem groups for aws-sdk, eslint and plugins, jest and typescript packages
  • Adding a catchall group in the npm ecosystem for any other packages in the major or minor/patch groupings
  • Adding ignores specifically for eslint, typescript and nodejs major versions as these will be handled manually

Context

Eases burden on dependancy management and reduces number of overall PRs raised for dependancy updates

Type of changes

  • Refactoring (non-breaking change)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would change existing functionality)
  • Bug fix (non-breaking change which fixes an issue)

Checklist

  • I am familiar with the contributing guidelines
  • I have followed the code style of the project
  • I have added tests to cover my changes
  • I have updated the documentation accordingly
  • This PR is a result of pair or mob programming

DT3-Specific Checklist

  • If I have added a new resource (SQS, Lambda, Gateway, DDB table, etc), I have created the appropriate alarms

Sensitive Information Declaration

To ensure the utmost confidentiality and protect your and others privacy, we kindly ask you to NOT including PII (Personal Identifiable Information) / PID (Personal Identifiable Data) or any other sensitive data in this PR (Pull Request) and the codebase changes. We will remove any PR that do contain any sensitive information. We really appreciate your cooperation in this matter.

  • I confirm that neither PII/PID nor sensitive data are included in this PR and the codebase changes.

@karlmcgi
karlmcgi requested a review from a team as a code owner October 7, 2026 15:37
@sonarqubecloud

sonarqubecloud Bot commented Oct 7, 2026

Copy link
Copy Markdown

Comment thread .github/dependabot.yaml
@karlmcgi
karlmcgi enabled auto-merge (squash) October 7, 2026 16:26
@karlmcgi
karlmcgi merged commit d2a7ef7 into main Oct 8, 2026
41 checks passed
@karlmcgi
karlmcgi deleted the feature/CCM-22644_Dependabot_Config_Updates branch October 8, 2026 11:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants