This is an automated email from the ASF dual-hosted git repository.
hubcio pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/iggy.git
The following commit(s) were added to refs/heads/master by this push:
new 9835136d5 ci: one dependabot PR per component for all update types
(#3467)
9835136d5 is described below
commit 9835136d54c9af83c420e568ab63e448a8bbc5e5
Author: Hubert Gruszecki <[email protected]>
AuthorDate: Mon Jun 15 11:52:41 2026 +0200
ci: one dependabot PR per component for all update types (#3467)
---
.github/dependabot.yml | 66 ++++++++++++----------------
.github/workflows/issue-labeler-assigner.yml | 2 +-
2 files changed, 29 insertions(+), 39 deletions(-)
diff --git a/.github/dependabot.yml b/.github/dependabot.yml
index 74c872c16..b0b56e7f5 100644
--- a/.github/dependabot.yml
+++ b/.github/dependabot.yml
@@ -15,6 +15,10 @@
# specific language governing permissions and limitations
# under the License.
+# Version updates: every entry uses a single group covering ALL update
+# types, so each ecosystem entry opens at most one version-update PR
+# per cycle. Security updates bypass these groups and may still open
+# individual PRs.
version: 2
updates:
- package-ecosystem: "cargo"
@@ -39,12 +43,9 @@ updates:
cooldown:
default-days: 7
groups:
- minor-and-patch:
+ rust:
patterns:
- "*"
- update-types:
- - "minor"
- - "patch"
- package-ecosystem: "github-actions"
directory: "/"
@@ -59,17 +60,14 @@ updates:
- "apache/iggy-committers"
labels:
- "dependencies"
- - "github_actions"
+ - "github-actions"
- "CI/CD"
cooldown:
default-days: 7
groups:
- minor-and-patch:
+ github-actions:
patterns:
- "*"
- update-types:
- - "minor"
- - "patch"
- package-ecosystem: "uv"
directories:
@@ -92,12 +90,15 @@ updates:
cooldown:
default-days: 7
groups:
- minor-and-patch:
+ # Load-bearing for Python, not just tidiness: the three projects
+ # share apache-iggy via a path dependency, so each uv.lock embeds
+ # the SDK's requirement metadata. Majors escaped the previous
+ # minor-and-patch group as per-directory PRs that rewrote that
+ # embedded metadata without the manifest change it was derived
+ # from, and could never pass the lockfile check (see #3451).
+ python:
patterns:
- "*"
- update-types:
- - "minor"
- - "patch"
- package-ecosystem: "npm"
directories:
@@ -119,12 +120,9 @@ updates:
cooldown:
default-days: 7
groups:
- minor-and-patch:
+ javascript:
patterns:
- "*"
- update-types:
- - "minor"
- - "patch"
- package-ecosystem: "gomod"
directories:
@@ -146,12 +144,9 @@ updates:
cooldown:
default-days: 7
groups:
- minor-and-patch:
+ go:
patterns:
- "*"
- update-types:
- - "minor"
- - "patch"
- package-ecosystem: "nuget"
directories:
@@ -176,12 +171,9 @@ updates:
- dependency-name: "Microsoft.SourceLink.GitHub"
- dependency-name: "Microsoft.Extensions.Logging.Abstractions"
groups:
- minor-and-patch:
+ csharp:
patterns:
- "*"
- update-types:
- - "minor"
- - "patch"
- package-ecosystem: "gradle"
directories:
@@ -203,12 +195,9 @@ updates:
cooldown:
default-days: 7
groups:
- minor-and-patch:
+ java:
patterns:
- "*"
- update-types:
- - "minor"
- - "patch"
- package-ecosystem: "docker"
directories:
@@ -243,13 +232,17 @@ updates:
- "docker"
cooldown:
default-days: 7
+ ignore:
+ # The Python interpreter version is pinned and synced across SDK
+ # files, CI, and Dockerfiles by
+ # scripts/ci/sync-python-interpreter-version.sh; a Dependabot bump
+ # of the base image alone would fail that check.
+ - dependency-name: "python"
+ - dependency-name: "mcr.microsoft.com/devcontainers/python"
groups:
- minor-and-patch:
+ docker:
patterns:
- "*"
- update-types:
- - "minor"
- - "patch"
- package-ecosystem: "bazel"
directory: "/foreign/cpp"
@@ -264,13 +257,10 @@ updates:
- "apache/iggy-committers"
labels:
- "dependencies"
- - "C++"
+ - "cpp"
cooldown:
default-days: 7
groups:
- minor-and-patch:
+ cpp:
patterns:
- "*"
- update-types:
- - "minor"
- - "patch"
diff --git a/.github/workflows/issue-labeler-assigner.yml
b/.github/workflows/issue-labeler-assigner.yml
index 17de263e9..a1c3dab03 100644
--- a/.github/workflows/issue-labeler-assigner.yml
+++ b/.github/workflows/issue-labeler-assigner.yml
@@ -67,7 +67,7 @@ jobs:
'Python SDK': 'python',
'C# SDK': 'csharp',
'Node.js SDK': 'javascript',
- 'C++ SDK': 'C++',
+ 'C++ SDK': 'cpp',
'PHP SDK': 'php',
'CLI': 'tui',
'Web UI': 'web',