This is an automated email from the ASF dual-hosted git repository.

vincbeck pushed a commit to branch v3-3-test
in repository https://gitbox.apache.org/repos/asf/airflow.git


The following commit(s) were added to refs/heads/v3-3-test by this push:
     new a73316c6eb3 [v3-3-test] Stop Dependabot from raising provider PRs on 
v3-3-test (#73474) (#73481)
a73316c6eb3 is described below

commit a73316c6eb3ed9a90847c9f9f683e02409a3aab7
Author: github-actions[bot] 
<41898282+github-actions[bot]@users.noreply.github.com>
AuthorDate: Mon Sep 21 14:58:39 2026 -0400

    [v3-3-test] Stop Dependabot from raising provider PRs on v3-3-test (#73474) 
(#73481)
    
    Providers are released from main, so dependency bumps to provider
    directories on a maintenance branch never reach users. The resulting PRs
    are review noise on a branch whose review capacity is reserved for
    backports.
    (cherry picked from commit 41434c2f3fde64098b1d3c37e02ba5d55f338484)
    
    Co-authored-by: Vincent <[email protected]>
---
 .github/dependabot.yml | 52 +++++++++-----------------------------------------
 1 file changed, 9 insertions(+), 43 deletions(-)

diff --git a/.github/dependabot.yml b/.github/dependabot.yml
index f96445c6845..7a48c995087 100644
--- a/.github/dependabot.yml
+++ b/.github/dependabot.yml
@@ -290,49 +290,15 @@ updates:
       - dependency-name: "*"
         update-types: ["version-update:semver-major"]
 
-  # The remaining directories are mirrored onto v3-3-test as well. Dependabot 
raises security
-  # updates against the default branch only, so a fixed version reaches the 
maintenance branch
-  # through its own version updates - Dependabot resolves and regenerates the 
lock file on that
-  # branch, which a cherry-picked lock file diff from main cannot do. Majors 
stay ignored, so a
-  # fix that needs a major bump still has to be backported by hand.
-  - package-ecosystem: npm
-    cooldown:
-      default-days: 4
-    directories:
-      - /providers/edge3/src/airflow/providers/edge3/plugins/www
-    schedule:
-      interval: "weekly"
-    target-branch: v3-3-test
-    groups:
-      3-3-edge-ui-package-updates:
-        patterns:
-          - "*"
-        update-types:
-          - "minor"
-          - "patch"
-    ignore:
-      - dependency-name: "*"
-        update-types: ["version-update:semver-major"]
-
-  - package-ecosystem: npm
-    cooldown:
-      default-days: 4
-    directories:
-      - /providers/fab/src/airflow/providers/fab/www
-    schedule:
-      interval: daily
-    target-branch: v3-3-test
-    groups:
-      3-3-fab-ui-package-updates:
-        patterns:
-          - "*"
-        update-types:
-          - "minor"
-          - "patch"
-    ignore:
-      - dependency-name: "*"
-        update-types: ["version-update:semver-major"]
-
+  # The remaining non-provider directories are mirrored onto v3-3-test as 
well. Dependabot raises
+  # security updates against the default branch only, so a fixed version 
reaches the maintenance
+  # branch through its own version updates - Dependabot resolves and 
regenerates the lock file on
+  # that branch, which a cherry-picked lock file diff from main cannot do. 
Majors stay ignored, so
+  # a fix that needs a major bump still has to be backported by hand.
+  #
+  # Provider directories (providers/*) are deliberately NOT mirrored onto 
v3-3-test: providers are
+  # released from main, so their dependencies on a maintenance branch never 
ship to users and the
+  # PRs are pure review noise.
   - package-ecosystem: npm
     cooldown:
       default-days: 4

Reply via email to