Skip to content

ci: remove the Dependabot configuration - #457

Merged
angeloashmore merged 1 commit into
masterfrom
claude/remove-dependabot-config
Sep 25, 2026
Merged

angeloashmore merged 1 commit into
masterfrom
claude/remove-dependabot-config

Conversation

@angeloashmore

@angeloashmore angeloashmore commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Resolves:

Description

Before this PR, Dependabot and a Claude routine could both update dependencies, which produced overlapping pull requests.

After this PR, Dependabot opens no version update pull requests. One Claude routine keeps a single dependency pull request, from claude/dependencies, and lists anything it cannot update in a "Dependency decisions" issue.

Dependabot alerts stay on, so GitHub Security still reports vulnerabilities. Dependabot security updates are a repository setting and are turned off separately.

Checklist

  • If my changes require tests, I added them.
  • If my changes affect backward compatibility, it has been discussed.
  • If my changes require an update to the CONTRIBUTING.md guide, I updated it.

Preview

How to QA 1

🤖 Generated with Claude Code

https://claude.ai/code/session_01ByzsghFd9sFtgiXeU31kZZ


Generated by Claude Code


Note

Low Risk
Repository automation only—no runtime or dependency resolution logic changes; security alerting remains enabled per the PR description.

Overview
Removes automated Dependabot version-update PRs by deleting .github/dependabot.yml, which had weekly npm scans, grouped security/minor-patch/major updates, and an ignore rule for major bumps of @prismicio/types-internal.

Dependency bumps are expected to come from the existing Claude routine on claude/dependencies instead, so two bots no longer open competing update PRs. Dependabot vulnerability alerts are unchanged; only the config-driven version-update workflow is gone.

Reviewed by Cursor Bugbot for commit 590b0c0. Bugbot is set up for automated code reviews on this repo. Configure here.

Footnotes

  1. Please use these labels when submitting a review:
    ❓ #ask: Ask a question.
    💡 #idea: Suggest an idea.
    ⚠️ #issue: Strongly suggest a change.
    🎉 #nice: Share a compliment. ↩

Dependency updates now come from a single Claude routine, which keeps one
dependency pull request per repository. Dependabot alerts stay on, so GitHub
Security still reports vulnerabilities. Dependabot no longer opens version
update pull requests.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ByzsghFd9sFtgiXeU31kZZ
@angeloashmore
angeloashmore merged commit f454a10 into master Sep 25, 2026
13 of 15 checks passed
@angeloashmore
angeloashmore deleted the claude/remove-dependabot-config branch September 25, 2026 21:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants