Grouped Security PRs for Dependabot Public Beta Feedback #78188
Unanswered
carogalvin
asked this question in
Code Security
Replies: 2 comments 2 replies
-
How long does it take to group existing PRs after the feature is enabled ? |
Beta Was this translation helpful? Give feedback.
1 reply
-
💯 Nice! Are there any examples of how to configure this? I can't find any relevant fields in the |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Select Topic Area
General
Body
We want YOUR feedback on Dependabot grouped security updates!
We know Dependabot is noisy. We see the memes. And we get it! Resolving Dependabot’s pull requests can feel like a Sisyphean task - never ending toil where you close one PR and several more pop up in their place. This is where grouped updates come in - single PRs that resolve multiple updates at once.
We already released grouped updates for scheduled version updates, and now we have released the public beta for grouping for security updates.
If you’ve had a chance to try it out, we'd love to hear your feedback on 1) what's working for you, 2) what needs to change, and 3) what you'd like us to tackle next!
What are grouped security updates?
Dependabot will collect all available security updates in a repository and attempt to open one pull request with all of them, per ecosystem, across directories. There is no further configuration available yet.
groups
configuration independabot.yml
will NOT apply to security updates📖 Helpful information:
Beta Was this translation helpful? Give feedback.
All reactions