This is an automated email from the ASF dual-hosted git repository.

hubcio pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/iggy.git


The following commit(s) were added to refs/heads/master by this push:
     new 9835136d5 ci: one dependabot PR per component for all update types 
(#3467)
9835136d5 is described below

commit 9835136d54c9af83c420e568ab63e448a8bbc5e5
Author: Hubert Gruszecki <[email protected]>
AuthorDate: Mon Jun 15 11:52:41 2026 +0200

    ci: one dependabot PR per component for all update types (#3467)
---
 .github/dependabot.yml                       | 66 ++++++++++++----------------
 .github/workflows/issue-labeler-assigner.yml |  2 +-
 2 files changed, 29 insertions(+), 39 deletions(-)

diff --git a/.github/dependabot.yml b/.github/dependabot.yml
index 74c872c16..b0b56e7f5 100644
--- a/.github/dependabot.yml
+++ b/.github/dependabot.yml
@@ -15,6 +15,10 @@
 # specific language governing permissions and limitations
 # under the License.
 
+# Version updates: every entry uses a single group covering ALL update
+# types, so each ecosystem entry opens at most one version-update PR
+# per cycle. Security updates bypass these groups and may still open
+# individual PRs.
 version: 2
 updates:
   - package-ecosystem: "cargo"
@@ -39,12 +43,9 @@ updates:
     cooldown:
       default-days: 7
     groups:
-      minor-and-patch:
+      rust:
         patterns:
           - "*"
-        update-types:
-          - "minor"
-          - "patch"
 
   - package-ecosystem: "github-actions"
     directory: "/"
@@ -59,17 +60,14 @@ updates:
       - "apache/iggy-committers"
     labels:
       - "dependencies"
-      - "github_actions"
+      - "github-actions"
       - "CI/CD"
     cooldown:
       default-days: 7
     groups:
-      minor-and-patch:
+      github-actions:
         patterns:
           - "*"
-        update-types:
-          - "minor"
-          - "patch"
 
   - package-ecosystem: "uv"
     directories:
@@ -92,12 +90,15 @@ updates:
     cooldown:
       default-days: 7
     groups:
-      minor-and-patch:
+      # Load-bearing for Python, not just tidiness: the three projects
+      # share apache-iggy via a path dependency, so each uv.lock embeds
+      # the SDK's requirement metadata. Majors escaped the previous
+      # minor-and-patch group as per-directory PRs that rewrote that
+      # embedded metadata without the manifest change it was derived
+      # from, and could never pass the lockfile check (see #3451).
+      python:
         patterns:
           - "*"
-        update-types:
-          - "minor"
-          - "patch"
 
   - package-ecosystem: "npm"
     directories:
@@ -119,12 +120,9 @@ updates:
     cooldown:
       default-days: 7
     groups:
-      minor-and-patch:
+      javascript:
         patterns:
           - "*"
-        update-types:
-          - "minor"
-          - "patch"
 
   - package-ecosystem: "gomod"
     directories:
@@ -146,12 +144,9 @@ updates:
     cooldown:
       default-days: 7
     groups:
-      minor-and-patch:
+      go:
         patterns:
           - "*"
-        update-types:
-          - "minor"
-          - "patch"
 
   - package-ecosystem: "nuget"
     directories:
@@ -176,12 +171,9 @@ updates:
       - dependency-name: "Microsoft.SourceLink.GitHub"
       - dependency-name: "Microsoft.Extensions.Logging.Abstractions"
     groups:
-      minor-and-patch:
+      csharp:
         patterns:
           - "*"
-        update-types:
-          - "minor"
-          - "patch"
 
   - package-ecosystem: "gradle"
     directories:
@@ -203,12 +195,9 @@ updates:
     cooldown:
       default-days: 7
     groups:
-      minor-and-patch:
+      java:
         patterns:
           - "*"
-        update-types:
-          - "minor"
-          - "patch"
 
   - package-ecosystem: "docker"
     directories:
@@ -243,13 +232,17 @@ updates:
       - "docker"
     cooldown:
       default-days: 7
+    ignore:
+      # The Python interpreter version is pinned and synced across SDK
+      # files, CI, and Dockerfiles by
+      # scripts/ci/sync-python-interpreter-version.sh; a Dependabot bump
+      # of the base image alone would fail that check.
+      - dependency-name: "python"
+      - dependency-name: "mcr.microsoft.com/devcontainers/python"
     groups:
-      minor-and-patch:
+      docker:
         patterns:
           - "*"
-        update-types:
-          - "minor"
-          - "patch"
 
   - package-ecosystem: "bazel"
     directory: "/foreign/cpp"
@@ -264,13 +257,10 @@ updates:
       - "apache/iggy-committers"
     labels:
       - "dependencies"
-      - "C++"
+      - "cpp"
     cooldown:
       default-days: 7
     groups:
-      minor-and-patch:
+      cpp:
         patterns:
           - "*"
-        update-types:
-          - "minor"
-          - "patch"
diff --git a/.github/workflows/issue-labeler-assigner.yml 
b/.github/workflows/issue-labeler-assigner.yml
index 17de263e9..a1c3dab03 100644
--- a/.github/workflows/issue-labeler-assigner.yml
+++ b/.github/workflows/issue-labeler-assigner.yml
@@ -67,7 +67,7 @@ jobs:
               'Python SDK': 'python',
               'C# SDK': 'csharp',
               'Node.js SDK': 'javascript',
-              'C++ SDK': 'C++',
+              'C++ SDK': 'cpp',
               'PHP SDK': 'php',
               'CLI': 'tui',
               'Web UI': 'web',

Reply via email to