Skip to content

Keep Dependabot to alerts, with no update pull requests - #91

Merged
Th3FenrisWolf merged 2 commits into
mainfrom
chore/dependabot-alerts-only
Oct 7, 2026
Merged

Th3FenrisWolf merged 2 commits into
mainfrom
chore/dependabot-alerts-only

Conversation

@Th3FenrisWolf

@Th3FenrisWolf Th3FenrisWolf commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

Why

Replatform Phase 7 (#73) turned on Dependabot version updates. Since 2026-09-30 they have opened grouped NuGet pull requests every week (#76, #77, #79, #87, #88, #89). The repository was set up for Dependabot alerts only, and Dependabot security updates stay off.

Alerts alone never reached NuGet here. The dependency graph reads every NuGet package as >= 0, because the versions live in Directory.Packages.props, and all 99 alerts so far are npm.

What changes

  • .github/dependabot.yml keeps one nuget entry with open-pull-requests-limit: 0. It opens no pull requests. It starts GitHub's automatic dependency submission for NuGet, which the root's .slnx does not, so the graph gets real versions and NuGet alerts can fire.
  • The npm, Docker, Compose and Actions entries and the Font Awesome registry go. npm and Actions alerts come from their manifests and need no entry. Docker images have no alerts.
  • docs/hosting/runbook.md: §6 step 3 swaps the Dependabot secrets for the alert settings, and the Updates bullet describes bumps by hand, the Dockerfile FROM lines and the cloudflared and Caddy tags included.
  • Spec §13.6 matches.

#88 and #89 are closed with a pointer here.

Owner steps

  • Settings → Advanced Security → Dependency graph → Automatic dependency submission → Enabled. It needs Actions, which this repository has, and uses Actions minutes.
  • Optional: delete the three Dependabot secrets under Settings → Secrets and variables → Dependabot. No workflow reads them once Dependabot opens no pull requests.

Checks

Row Result
D1 dotnet build KitchenCommandCenter.slnx -c Release 0 warnings, 0 errors
D2 yarn build:all Built
D4 node tests/scripts/run.mjs 1679 passed · 0 failed · 0 skipped across 6 suites
D10 docs Runbook and spec §13.6 updated. The Phase 7 plan stays as the record of what it built
CodeRabbit Round 1: review_completed, 0 findings

The submission already works: an Automatic Dependency Submission (NuGet) run succeeded on main at 2026-10-07 16:23 UTC, started by the nuget entry main has today. The dependency graph now lists all 593 NuGet packages, transitive ones included, with real versions, Umbraco.Cms at 17.7.0 among them. No NuGet alert is open.

Dependabot version updates opened two grouped NuGet pull requests a week. The one nuget entry left opens none
and only starts GitHub's automatic dependency submission, so the dependency graph gets the versions in
Directory.Packages.props and NuGet alerts can fire. The runbook and spec §13.6 now describe updates by hand.
@Th3FenrisWolf
Th3FenrisWolf merged commit 9715076 into main Oct 7, 2026
3 checks passed
@Th3FenrisWolf
Th3FenrisWolf deleted the chore/dependabot-alerts-only branch October 7, 2026 17:01
Th3FenrisWolf added a commit that referenced this pull request Oct 7, 2026
Dependabot version updates opened two grouped NuGet pull requests a week. The one nuget entry left opens none
and only starts GitHub's automatic dependency submission, so the dependency graph gets the versions in
Directory.Packages.props and NuGet alerts can fire. The runbook and spec §13.6 now describe updates by hand.
twinright-bzs pushed a commit that referenced this pull request Oct 7, 2026
Dependabot version updates opened two grouped NuGet pull requests a week. The one nuget entry left opens none and only starts GitHub's automatic dependency submission, so the dependency graph gets the versions in Directory.Packages.props and NuGet alerts can fire. The runbook and spec §13.6 now describe updates by hand.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant