Skip to content

Define a sustainable strategy for using Dependabot effectively #671

@JulianKniephoff

Description

@JulianKniephoff

Dependabot pull requests (both security updates and version updates) have been temporarily disabled.

Currently, security updates are only created against the default branch. While version updates can be configured for additional branches, our forward-merging strategy means that enabling Dependabot across multiple branches would generate a high number of duplicate pull requests for the same dependency changes.

This creates unnecessary noise and overhead in reviewing and managing PRs.

Until we find a better configuration or workflow that avoids duplication, Dependabot PRs will remain disabled.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions