Repository navigation
Keep Dependabot to alerts, with no update pull requests - #91
Merged
Merged
Conversation
Dependabot version updates opened two grouped NuGet pull requests a week. The one nuget entry left opens none and only starts GitHub's automatic dependency submission, so the dependency graph gets the versions in Directory.Packages.props and NuGet alerts can fire. The runbook and spec §13.6 now describe updates by hand.
This was referenced Oct 7, 2026
Th3FenrisWolf
added a commit
that referenced
this pull request
Oct 7, 2026
Dependabot version updates opened two grouped NuGet pull requests a week. The one nuget entry left opens none and only starts GitHub's automatic dependency submission, so the dependency graph gets the versions in Directory.Packages.props and NuGet alerts can fire. The runbook and spec §13.6 now describe updates by hand.
twinright-bzs
pushed a commit
that referenced
this pull request
Oct 7, 2026
Dependabot version updates opened two grouped NuGet pull requests a week. The one nuget entry left opens none and only starts GitHub's automatic dependency submission, so the dependency graph gets the versions in Directory.Packages.props and NuGet alerts can fire. The runbook and spec §13.6 now describe updates by hand.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Replatform Phase 7 (#73) turned on Dependabot version updates. Since 2026-09-30 they have opened grouped NuGet pull requests every week (#76, #77, #79, #87, #88, #89). The repository was set up for Dependabot alerts only, and Dependabot security updates stay off.
Alerts alone never reached NuGet here. The dependency graph reads every NuGet package as
>= 0, because the versions live inDirectory.Packages.props, and all 99 alerts so far are npm.What changes
.github/dependabot.ymlkeeps onenugetentry withopen-pull-requests-limit: 0. It opens no pull requests. It starts GitHub's automatic dependency submission for NuGet, which the root's.slnxdoes not, so the graph gets real versions and NuGet alerts can fire.docs/hosting/runbook.md: §6 step 3 swaps the Dependabot secrets for the alert settings, and the Updates bullet describes bumps by hand, the DockerfileFROMlines and the cloudflared and Caddy tags included.#88 and #89 are closed with a pointer here.
Owner steps
Checks
dotnet build KitchenCommandCenter.slnx -c Releaseyarn build:allnode tests/scripts/run.mjsreview_completed, 0 findingsThe submission already works: an
Automatic Dependency Submission (NuGet)run succeeded onmainat 2026-10-07 16:23 UTC, started by thenugetentrymainhas today. The dependency graph now lists all 593 NuGet packages, transitive ones included, with real versions,Umbraco.Cmsat17.7.0among them. No NuGet alert is open.