From 3bdfcaa8ee661d56a5502ac0dbc49cee67f3df59 Mon Sep 17 00:00:00 2001 From: saurabh dave <87791567+saurabh12571257@users.noreply.github.com> Date: Sat, 25 Apr 2026 02:34:36 +0530 Subject: [PATCH] Add Dependabot config for uv dependencies and GitHub Actions (#167) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ## Summary Adds a Dependabot configuration to automate weekly update PRs for: - `uv`-managed Python dependencies - GitHub Actions used in CI workflows ## Why This repository already relies on pinned dependency state via `uv.lock` and pinned GitHub Action revisions in CI. Adding Dependabot helps keep both current with small, reviewable update PRs instead of larger manual catch-up updates. ## What this changes - Adds `.github/dependabot.yml` - Configures weekly version update checks for the repo root - Groups minor and patch dependency updates to reduce PR noise - Enables automatic update PRs for GitHub Actions references in workflows ## Used `uv` instead of `pip` This project uses `uv` directly (`uv.lock`, `uv run`, and repo instructions based on `uv`), so configuring Dependabot with the `uv` ecosystem matches the repository’s actual package management workflow more closely than a generic `pip` entry. ## Risk Low. This is a configuration only change and does not affect application runtime behavior . --- .github/dependabot.yml | 13 +++++++++++++ 1 file changed, 13 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 00000000..776459cf --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,13 @@ +version: 2 +updates: + - package-ecosystem: "uv" + directory: "/" + schedule: + interval: "weekly" + groups: + minor-and-patch: + update-types: ["minor", "patch"] + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly"