This is an automated email from the ASF dual-hosted git repository.
vincbeck pushed a commit to branch v3-3-test
in repository https://gitbox.apache.org/repos/asf/airflow.git
The following commit(s) were added to refs/heads/v3-3-test by this push:
new a73316c6eb3 [v3-3-test] Stop Dependabot from raising provider PRs on
v3-3-test (#73474) (#73481)
a73316c6eb3 is described below
commit a73316c6eb3ed9a90847c9f9f683e02409a3aab7
Author: github-actions[bot]
<41898282+github-actions[bot]@users.noreply.github.com>
AuthorDate: Mon Sep 21 14:58:39 2026 -0400
[v3-3-test] Stop Dependabot from raising provider PRs on v3-3-test (#73474)
(#73481)
Providers are released from main, so dependency bumps to provider
directories on a maintenance branch never reach users. The resulting PRs
are review noise on a branch whose review capacity is reserved for
backports.
(cherry picked from commit 41434c2f3fde64098b1d3c37e02ba5d55f338484)
Co-authored-by: Vincent <[email protected]>
---
.github/dependabot.yml | 52 +++++++++-----------------------------------------
1 file changed, 9 insertions(+), 43 deletions(-)
diff --git a/.github/dependabot.yml b/.github/dependabot.yml
index f96445c6845..7a48c995087 100644
--- a/.github/dependabot.yml
+++ b/.github/dependabot.yml
@@ -290,49 +290,15 @@ updates:
- dependency-name: "*"
update-types: ["version-update:semver-major"]
- # The remaining directories are mirrored onto v3-3-test as well. Dependabot
raises security
- # updates against the default branch only, so a fixed version reaches the
maintenance branch
- # through its own version updates - Dependabot resolves and regenerates the
lock file on that
- # branch, which a cherry-picked lock file diff from main cannot do. Majors
stay ignored, so a
- # fix that needs a major bump still has to be backported by hand.
- - package-ecosystem: npm
- cooldown:
- default-days: 4
- directories:
- - /providers/edge3/src/airflow/providers/edge3/plugins/www
- schedule:
- interval: "weekly"
- target-branch: v3-3-test
- groups:
- 3-3-edge-ui-package-updates:
- patterns:
- - "*"
- update-types:
- - "minor"
- - "patch"
- ignore:
- - dependency-name: "*"
- update-types: ["version-update:semver-major"]
-
- - package-ecosystem: npm
- cooldown:
- default-days: 4
- directories:
- - /providers/fab/src/airflow/providers/fab/www
- schedule:
- interval: daily
- target-branch: v3-3-test
- groups:
- 3-3-fab-ui-package-updates:
- patterns:
- - "*"
- update-types:
- - "minor"
- - "patch"
- ignore:
- - dependency-name: "*"
- update-types: ["version-update:semver-major"]
-
+ # The remaining non-provider directories are mirrored onto v3-3-test as
well. Dependabot raises
+ # security updates against the default branch only, so a fixed version
reaches the maintenance
+ # branch through its own version updates - Dependabot resolves and
regenerates the lock file on
+ # that branch, which a cherry-picked lock file diff from main cannot do.
Majors stay ignored, so
+ # a fix that needs a major bump still has to be backported by hand.
+ #
+ # Provider directories (providers/*) are deliberately NOT mirrored onto
v3-3-test: providers are
+ # released from main, so their dependencies on a maintenance branch never
ship to users and the
+ # PRs are pure review noise.
- package-ecosystem: npm
cooldown:
default-days: 4