Skip to content

chore: tame Dependabot — one grouped PR, no auto major bumps#41

Merged
ahmed-sekka merged 1 commit into
mainfrom
chore/tame-dependabot
May 25, 2026
Merged

chore: tame Dependabot — one grouped PR, no auto major bumps#41
ahmed-sekka merged 1 commit into
mainfrom
chore/tame-dependabot

Conversation

@ahmed-sekka
Copy link
Copy Markdown
Contributor

The first dependabot.yml run opened ~12 individual PRs because most dependencies matched no group. Rework it so updates arrive as a single grouped Maven PR (plus one for GitHub Actions), minor+patch only, and ignore all major version bumps — Boot 4 / Spring Framework 7 / Spring AI 2.0 are deliberate migrations, not bot-driven.

The first dependabot.yml run opened ~12 individual PRs because most
dependencies matched no group. Rework it so updates arrive as a single
grouped Maven PR (plus one for GitHub Actions), minor+patch only, and
ignore all major version bumps — Boot 4 / Spring Framework 7 / Spring AI 2.0
are deliberate migrations, not bot-driven.
@ahmed-sekka ahmed-sekka merged commit 11a7f80 into main May 25, 2026
3 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants