Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
90 commits
Select commit Hold shift + click to select a range
2d5bc7e
build(deps): bump github.com/open-policy-agent/opa from 1.16.2 to 1.1…
dependabot[bot] May 29, 2026
902f9ac
Apply PQC policy to bundle endpoint and prometheus server (#6995)
sorindumitru May 29, 2026
0df1cd1
build(deps): bump the aws-sdk group with 2 updates (#6996)
dependabot[bot] May 29, 2026
59e0b74
fix: use structured logger for rebootstrap messages and fix typos (#7…
immanuwell May 29, 2026
3c5d120
Fix stale proto directory layout in CONTRIBUTING.md (#7011)
amartinezfayo Jun 1, 2026
62fda0a
build(deps): bump github.com/sigstore/sigstore from 1.10.6 to 1.10.7 …
dependabot[bot] Jun 1, 2026
18b8e10
build(deps): bump cloud.google.com/go/security (#7004)
dependabot[bot] Jun 1, 2026
298133e
build(deps): bump github.com/aws/aws-sdk-go-v2/service/autoscaling (#…
dependabot[bot] Jun 1, 2026
1e4647f
Add Copilot repository custom instructions (#7009)
amartinezfayo Jun 2, 2026
10cad40
Add support for two more PQC curves (#6999)
sorindumitru Jun 2, 2026
a462c23
build(deps): bump google.golang.org/api in the google-cloud-sdk group…
dependabot[bot] Jun 3, 2026
05698c9
build(deps): bump github.com/sigstore/sigstore from 1.10.7 to 1.10.8 …
dependabot[bot] Jun 3, 2026
64e67b6
agent: add `log_selectors` config item (#6981)
c4rlo Jun 3, 2026
a45ea23
build(deps): bump github.com/shirou/gopsutil/v4 from 4.26.4 to 4.26.5…
dependabot[bot] Jun 3, 2026
b02cfba
build(deps): bump the aws-sdk group with 7 updates (#7013)
dependabot[bot] Jun 3, 2026
1ab08d5
build(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#7024)
dependabot[bot] Jun 4, 2026
141c66b
build(deps): bump github.com/jackc/pgx/v5 from 5.9.2 to 5.10.0 (#7026)
dependabot[bot] Jun 4, 2026
d301cb7
Retry image builds to tolerate transient base image pull failures (#7…
amartinezfayo Jun 4, 2026
468edab
build(deps): bump github.com/aws/smithy-go from 1.27.0 to 1.27.1 in t…
dependabot[bot] Jun 4, 2026
ac5a342
Datastore config doc updates (#7023)
c4rlo Jun 4, 2026
600e783
Retry container image pulls in integration tests to reduce CI flakine…
amartinezfayo Jun 4, 2026
e19c791
Upgrade go-spiffe to 2.7.0 (#7035)
sorindumitru Jun 4, 2026
b9c51cd
Remove the unused kind configuration from the cert-manager integratio…
amartinezfayo Jun 5, 2026
3559c5a
Add assignee rotation with ball-in-court tracking for pull requests (…
amartinezfayo Jun 5, 2026
a68b347
Fix assign-reviewer not setting an assignee on open (#7043)
amartinezfayo Jun 5, 2026
dd636b2
build(deps): bump github.com/mattn/go-sqlite3 from 1.14.44 to 1.14.45…
dependabot[bot] Jun 6, 2026
90319cf
build(deps): bump github.com/google/go-tpm-tools from 0.4.8 to 0.4.9 …
dependabot[bot] Jun 6, 2026
3cac6db
build(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azcore from 1…
dependabot[bot] Jun 6, 2026
302b5cc
test: Add x509util certificate coverage (#7029)
keeganwitt Jun 6, 2026
9b83def
Add SPIRE-backed Prometheus TLS identity and SPIFFE allowlist (#6812)
aviralgarg05 Jun 6, 2026
7122d48
test(common/idutil): Expand IDFromProto coverage (#7028)
keeganwitt Jun 6, 2026
410548b
Correct the stale actions/upload-artifact version comment to v7.0.1 (…
amartinezfayo Jun 9, 2026
9f3880f
Update the review ball-in-court on fork PRs via workflow_run (#7052)
amartinezfayo Jun 10, 2026
e3ea3af
build(deps): bump the aws-sdk group across 1 directory with 2 updates…
dependabot[bot] Jun 10, 2026
7238748
build(deps): bump google.golang.org/api from 0.283.0 to 0.284.0 in th…
dependabot[bot] Jun 10, 2026
e85ad21
build(deps): bump github.com/open-policy-agent/opa from 1.17.0 to 1.1…
dependabot[bot] Jun 10, 2026
163f90a
agent: treat failure of all attestation plugins as overall failure & …
c4rlo Jun 10, 2026
eaa0771
fix: validate missing Workload API endpoint in spire upstreamauthorit…
immanuwell Jun 10, 2026
4542f81
build(deps): bump actions/github-script from 7.0.1 to 9.0.0 (#7047)
dependabot[bot] Jun 10, 2026
00c520e
build(deps): bump the golang-org-x group across 1 directory with 3 up…
dependabot[bot] Jun 11, 2026
f777492
Prefer determining pod and container ids from cgroup file (#7060)
sorindumitru Jun 11, 2026
f4070d8
build(deps): bump github.com/sigstore/cosign/v3 from 3.0.6 to 3.1.1 (…
dependabot[bot] Jun 11, 2026
0216449
Fix Azure IMDS Plugin Signature Validation (#6960)
ChanghengGu Jun 11, 2026
23c5d03
Switch Dependabot to grouped weekly PRs and drop the auto-merge workf…
amartinezfayo Jun 12, 2026
136bd26
build(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.306…
dependabot[bot] Jun 12, 2026
273849f
build(deps): bump regclient/actions from c70ad64367908075211b10dcd2ab…
dependabot[bot] Jun 12, 2026
a29e472
build(deps): bump actions/github-script from 7.0.1 to 9.0.0 (#7062)
dependabot[bot] Jun 12, 2026
7a306ff
Fix http_challenge agent name validation regex (#7066)
kanywst Jun 13, 2026
5d1e6a3
Upgrade to Go 1.26.4 (#7069)
sorindumitru Jun 13, 2026
480812b
[gcp_kms] add small sleep to get public key (#6924)
daescha Jun 14, 2026
7f3b7be
Add spire-agent workload API rate limiting by pod UID with OS UID fal…
terahertz5k Jun 14, 2026
d18c1e8
Update dario.cat/merge dependency (#7083)
sorindumitru Jun 18, 2026
e0ddab9
build(deps): bump the minor-and-patch group across 1 directory with 2…
dependabot[bot] Jun 19, 2026
06cf96c
Fix data races in built-in BundlePublisher plugins on dynamic reconfi…
amartinezfayo Jun 19, 2026
87e9acc
Fix flaky `gcp_kms` key manager tests caused by mock clock handling a…
amartinezfayo Jun 19, 2026
dce33a4
events: keep previous first/lastEvent information when reloading (#6994)
sorindumitru Jun 20, 2026
832aae4
feat: Support for optional verification of client cert IPs (x509pop) …
jsnctl Jun 20, 2026
2aa5525
migrate use of github.com/docker/docker dependencies to github.com/mo…
daescha Jun 20, 2026
80acd65
refactor: use standard `fs.FS` to simplify code (#7046)
c4rlo Jun 20, 2026
73215a3
Copilot instructions: tell it about new(EXPR) form (#7086)
c4rlo Jun 22, 2026
f32a624
Fetch updated attested nodes in bulk (#7022)
nweisenauer-sap Jun 23, 2026
dbb9d50
Tolerate mountinfo lines with an empty mount source (#7044)
arpitjain099 Jun 24, 2026
5a7b5d0
build(deps): bump the minor-and-patch group with 10 updates (#7091)
dependabot[bot] Jun 28, 2026
ebbd3d9
build(deps): bump regclient/actions from 14f9d37db17b5dc41fefd1ffdd1a…
dependabot[bot] Jun 28, 2026
5a7bba8
build(deps): bump actions/checkout from 6.0.3 to 7.0.0 (#7089)
dependabot[bot] Jun 28, 2026
065b474
build(deps): bump msys2/setup-msys2 from 2.31.1 to 2.32.0 in the mino…
dependabot[bot] Jun 28, 2026
8a546c9
fix: correct TTL logging in delegated identity X.509 SVID subscriber …
immanuwell Jun 28, 2026
81e7273
Document the ball-in-court review process in the pull request templat…
amartinezfayo Jun 28, 2026
2b4b8d9
spire-agent: implement logger service (#7017)
sorindumitru Jun 28, 2026
ca8b211
fix: cascade-delete registered_entries on attested node deletion (#6946)
angabini Jun 30, 2026
455df3c
Add tag-based key discovery support in the `aws_kms` KeyManager plugi…
amartinezfayo Jun 30, 2026
5150b7c
Fix data race in spiretest log assertion helper (#7096)
amartinezfayo Jun 30, 2026
2a1dbb9
spire-agent: try to enable SE_DEBUG_PRIVILEGE at startup on windows (…
sorindumitru Jun 30, 2026
12c8be5
Fix azure_imds node attestation for standalone VMs (#6807)
ravishen Jul 1, 2026
27f276f
Fix flaky fetch-jwt-svids integration test by waiting for the restart…
amartinezfayo Jul 1, 2026
9a3b3d0
Add azure_imds network interface unmarshal regression test (#7106)
amartinezfayo Jul 1, 2026
0a60280
Add force-push guidance to the PR template and reference it from CONT…
amartinezfayo Jul 1, 2026
1056789
build(deps): bump the minor-and-patch group with 10 updates (#7109)
dependabot[bot] Jul 1, 2026
47fc7aa
build(deps): bump the minor-and-patch group with 2 updates (#7101)
dependabot[bot] Jul 1, 2026
4601876
build(deps): bump actions/cache from 5.0.5 to 6.1.0 (#7102)
dependabot[bot] Jul 1, 2026
406735f
Implement SPIFFE Broker Endpoint & API (#6915)
matheuscscp Jul 2, 2026
656b64d
Fix k8s workload attestor Broker API config docs and remove dead code…
amartinezfayo Jul 2, 2026
dbbbaf6
Fix Dependabot Milestone workflow by granting pull-requests: write (#…
amartinezfayo Jul 2, 2026
2be070d
Add disable_group_name_selectors option to Windows workload attestor …
jananiarunachalam Jul 2, 2026
9274936
datastore: UNION ALL for mysql list entries query (#7113)
zmt Jul 2, 2026
23bcf0d
build(deps): bump regclient/actions/regctl-installer from 4b4db1dcc7d…
dependabot[bot] Jul 2, 2026
9f3095f
Make attested-node prune batch size configurable (#7100)
terahertz5k Jul 2, 2026
fc9f1ac
refactor: replace abandoned github.com/imkira/go-observer dependency …
mvanhorn Jul 2, 2026
e78e2ee
Changelog 1.15.2 (#7136)
MarcosDY Jul 9, 2026
9bc0505
Merge tag 'a7e490ee' into feature/bump-upstream-v1.15.2
zzzz465 Jul 16, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 18 additions & 0 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,24 @@ https://github.com/spiffe/spire/blob/main/CONTRIBUTING.md

2. Please remember to include a DCO on every commit (`git commit -s`)
https://github.com/apps/dco

3. How the review process works ("ball in court"):
- When you open this PR (or mark it ready for review), a maintainer is
automatically assigned to it. The assignee shows whose turn it is to act
next, so you can always see who currently holds the ball.
- Pushing new commits does not automatically reassign the PR to the
maintainer. Once you are done addressing comments, re-request a review
from the assigned maintainer (the "Reviewers" section of the PR has a
refresh icon next to their name). This puts the ball back in their court
so they know it is ready for another look.
- When addressing review comments, please add new commits rather than
force-pushing. Individual commits that address comments are easier to
review than a single commit containing all the changes again. Pull
requests are squashed at merge time, so there is no need to squash and
force-push in the PR.
- Please also look at any comments from Copilot and address them if needed.
Posting a short reply to each one helps reviewers see whether it has been
addressed or consciously considered, even when no code change is needed.
-->

**Pull Request check list**
Expand Down
230 changes: 230 additions & 0 deletions .github/copilot-instructions.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,230 @@
# Copilot instructions for SPIRE

SPIRE is the reference implementation of the SPIFFE APIs. It issues SPIFFE
identities (SVIDs) to workloads in the SVID formats defined by the SPIFFE
specifications. The codebase is Go and is organized around two long-running
processes, the SPIRE Server and the SPIRE Agent, plus a plugin system.

When reviewing or generating code, weigh the concerns covered below. All of
them matter, and more than one often applies to the same change: compatibility
guarantees, SPIFFE spec conformance, security and usability, and project
conventions.

## Review checklist

These questions come from the SPIRE maintainer review guidelines in
`MAINTAINERS.md` and are advisory prompts to surface issues, not a rigid gate:

- Is the use case the change addresses clearly understood?
- Does the change break any current user's expectations of behavior (a
regression)?
- Can the change be misconfigured, and if so what is the impact?
- Does the change adhere to the SPIRE compatibility guarantee (see the
Compatibility guarantees section below)?
- What are the failure modes? Can SPIRE keep running?
- If something goes wrong, will it be clear to the operator what happened and
how to fix it?
- If the change introduces additional configurables, could some or all of them
be replaced with a programmatic decision?

Changes to particularly sensitive areas, such as the agent's cache manager or
the server's CA, warrant extra scrutiny.

## Compatibility guarantees

SPIRE makes strong compatibility promises documented in `doc/upgrading.md`.
Treat a violation of these as a blocking issue.

- **Server-to-server version skew.** Servers in the same cluster must operate
within +/- 1 minor version of each other. Do not introduce a change that
breaks a server one minor version behind or ahead (for example a new field or
RPC that an adjacent server cannot produce or understand).
- **Agent-to-server version skew.** Agents may be up to one minor version older
than the oldest server and must never be newer than the oldest server. Do not
add behavior that requires an agent and server to be the same version, or that
breaks an agent one minor version behind.
- **Upgrade and downgrade paths.** Only single-minor-version jumps are
supported, servers upgrade before agents, and SPIRE supports zero-downtime
rolling upgrades when more than one server is present. Do not assume state
written by a version more than one minor prior.
- **Built-in plugin config and behavior compatibility.** A backwards-incompatible
change to a built-in plugin (config semantics, selectors produced, etc.) must
log a deprecation warning and keep backwards compatibility for one minor
version. Do not rename, retype, or remove a config key without a deprecation
cycle.
- **Plugin interface compatibility.** A breaking change to a plugin interface
must keep existing plugins working for one minor version cycle, with warnings.
- **Deprecation log markers.** Deprecation warnings must include the structured
field `alert=true`. Configuration deprecations add `alert_type=deprecated_config`
and deprecated plugin services add `alert_type=deprecated_service`.
- **Datastore/SQL changes.** Datastore schema changes must ship in at least one
full minor release cycle before any code change depends on them.
- **Experimental features.** Features gated behind the `experimental` config
section are exempt from the guarantees above. If a change touches a feature
that was experimental, confirm the experimental marker is still accurate.

## SPIFFE specification conformance

SPIRE implements the SPIFFE specifications. The canonical, authoritative set of
specs lives at https://github.com/spiffe/spiffe/tree/main/standards. The set of
specifications and SVID profiles evolves over time, and new profiles are added,
so do not assume the specs are limited to the ones you already know from
training.

When a change touches spec-defined behavior (an SVID format, trust domain
parsing, the Workload API request/response shape, federation bundle format,
etc.), treat the specs in that repository as authoritative and verify
conformance against them rather than relying on prior knowledge, which may be
stale or incomplete. If you cannot consult the spec, raise spec-conformance
concerns as questions rather than asserting a defect. Likewise, flag
reinterpretations of ambiguous spec areas as questions for maintainers rather
than as defects.

## Security and usability

SPIRE is security-critical infrastructure. Watch for changes that could weaken
identity issuance, trust domain or bundle handling, SVID validation, key
management, or authentication and authorization between components. Consider
whether a change could be misconfigured, and what the impact of misconfiguration
would be. Vulnerabilities are reported privately to security@spiffe.io, not via
public issues or PRs.

SPIRE solves a complicated problem, so features, configurables, log and error
messages, documentation, and naming must stay accessible to people who are not
deeply familiar with SPIFFE or authentication systems. The maintainer guidelines
in `MAINTAINERS.md` set these expectations:

- **Secure by default, then "it just works".** Decisions should favor secure
defaults first and ease of use second, in that order.
- **Minimize configurables.** Keep the number of configuration options as small
as possible, especially when many users would need to set the option, or when
its value (and its extremes) could significantly affect SPIRE performance,
reliability, or security. Prefer a programmatic decision over a new
configurable where one is feasible.
- **The beginner measure.** A beginner should be able to quickly understand a
feature or configurable and its impacts, and should be able to troubleshoot
and be clearly informed when something important goes wrong. Favor clear,
actionable log and error messages over silent failure.

## Repository layout

- `cmd/{spire-server,spire-agent}/`: CLI implementations of the server and
agent commands.
- `pkg/{agent,server}/`: main logic of the agent and server processes and their
support packages.
- `pkg/common/`: functionality shared by agent, server, and plugins.
- `pkg/{agent,server}/plugin/<name>/`: built-in plugin implementations.
- `proto/spire/common/`: shared protobuf definitions (package `spire.common`),
with plugin-related common types under `proto/spire/common/plugin/`.
- `proto/private/`: internal protobuf definitions that are not part of the
public API, for example `proto/private/server/journal/`.

The public gRPC API and plugin interface protobufs live in separate
repositories ([`spire-api-sdk`](https://github.com/spiffe/spire-api-sdk) and
[`spire-plugin-sdk`](https://github.com/spiffe/spire-plugin-sdk), both
dependencies in `go.mod`), not in this repository.

Packages should be exported through interfaces, and interaction with a package
should go through its interface. Define an interface in its own lowercase file
named after the interface.

Platform-specific code is split across files guarded by build constraints, by
convention named `<name>_posix.go` and `<name>_windows.go`. A change to one
platform's file usually needs a corresponding change in its sibling so that
behavior and validation stay consistent across platforms.

## Go conventions

- Write idiomatic Go. Prefer standard library and existing helpers over manual
plumbing, and match the patterns in sibling files (error wrapping, validation,
output formatting).
- Errors start with a lower case letter. Neither error messages nor log
messages end with a period.
- Log messages use structured logging fields to convey context rather than
string formatting, which increases message cardinality and hinders
aggregation. Field names should be the constants defined in
`pkg/common/telemetry/names.go` rather than ad-hoc strings. Log message text
itself uses standard casing.

### Language version

This project targets a modern Go toolchain, and the toolchain is updated
periodically. Treat the `.go-version` file at the repository root as the single
source of truth for the language version: assume all language and standard
library features up to that version are available, and do not flag valid modern
Go as an error based on an assumed older version. Do not hardcode a version
assumption from this document. In particular, do not raise any of the following
(all valid in the toolchain this project uses):

- **Ranging over an integer.** `for range n` and `for i := range n` where `n`
is an integer are valid since Go 1.22. Do not claim `range` cannot iterate
over an `int` or that such code does not compile.
- **Per-iteration loop variables.** Since Go 1.22 each loop iteration gets a
fresh copy of the loop variable. A goroutine or closure that captures a `for`
loop variable does not observe later iterations' values, so do not flag the
classic "loop variable captured by reference" race for plain `for range` or
three-clause `for` loops. (Variables declared inside the loop body with `:=`
were already per-iteration before 1.22.)
- **`min`, `max`, and `clear` builtins**, and other features introduced up to
the toolchain's version.
- **`new(x)`** where `x` is an expression rather than a type.

If you believe a construct fails to compile, prefer assuming it is valid modern
Go rather than reporting a build error based on an older language version.

## Metrics

- Label names should be the constants defined in the `telemetry` package
(`pkg/common/telemetry/names.go`), and metrics should be defined centrally in
`telemetry` or its subpackages.
- Count in aggregate: accumulate counts in a loop and emit a single metric after
the loop rather than emitting one metric per iteration.
- Labels must be singular: a label name appears at most once per metric, its
value is never an array or slice, and a given label must appear on every
instance of a metric rather than conditionally.
- Keep `doc/telemetry/telemetry.md` up to date when metrics change, and unit
test metrics where reasonable.

## Testing

- Prefer fake implementations over generated mocks. Mocks encode specific call
patterns and are brittle; fakes implement the assumed behavior of a dependency
in one maintainable place.
- Use table-driven tests when there is more than one case, with a `name` field
per case.
- Never use `time.Sleep` to synchronize tests. Use proper synchronization such
as `require.Eventually`, channels, sync primitives, mock clocks, or explicit
control like `os.Chtimes`.
- Include tests and regression coverage for behavior changes.
- Before flagging a data race or test flakiness caused by "parallel execution"
(for example a package-level variable mutated by a test), confirm the affected
tests actually run in parallel by calling `t.Parallel()`. Tests run serially
within a package unless they opt in, and SPIRE intentionally uses package-level
test hooks in some places, so do not assert a parallel-execution race without
that evidence.

## Building, testing, and linting

A Makefile drives common tasks and installs the required toolchain as needed.

- `make build` builds the binaries; `make all` builds, lints, and runs the unit
tests.
- `make test` runs the unit tests, and `make race-test` runs them with the race
detector. Validate code changes with these before considering them done.
- `make lint` runs the linters: `lint-code` (golangci-lint, configured in
`.golangci.yml`) and `lint-md` (markdown). Code and docs should pass lint.
- `make generate` regenerates the protobuf code (`.pb.go`) from `.proto` files
using the pinned `spire-plugin-sdk` version, and `make generate-check` verifies
the generated code is current. After changing a `.proto` file, run
`make generate` and commit the regenerated output.

## Contribution mechanics

- Every commit must be signed off with a DCO (`git commit -s`).
- Substantial changes should be tied to a triaged issue.
- Update documentation when behavior or configuration changes. Check whether a
relevant file under `doc/` needs to be updated (for example a plugin's
reference doc).
- When a change adds, removes, or modifies a configuration setting, update the
full reference config files as well: `conf/agent/agent_full.conf` for agent
settings and `conf/server/server_full.conf` for server settings.
60 changes: 31 additions & 29 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,38 +3,24 @@ updates:
- package-ecosystem: gomod
directory: "/"
schedule:
interval: "daily"
interval: "weekly"
time: "09:00"
timezone: "America/Los_Angeles"
# Wait for new releases to age before opening update PRs, preserving
# a window for the ecosystem to detect and report a compromised
# release before it is proposed for review.
cooldown:
default-days: 7
# Collapse all minor and patch updates into a single weekly PR.
# Major bumps remain ungrouped and each one opens its own PR, so
# each breaking change can be reviewed independently.
groups:
actions:
minor-and-patch:
patterns:
- "github.com/actions/*"
aws-sdk:
patterns:
- "github.com/aws/aws-sdk-go-v2/*"
- "github.com/aws/smithy-go"
azure-sdk:
patterns:
- "github.com/Azure/azure-sdk-for-go/*"
google-cloud-sdk:
patterns:
- "cloud.google.com/go/*"
- "google.golang.org/api"
- "google.golang.org/grpc"
- "github.com/googleapis/*"
golang.org/x:
patterns:
- "golang.org/x/*"
hashicorp-vault:
patterns:
- "github.com/hashicorp/vault/*"
k8s.io:
patterns:
- "k8s.io/*"
sigs.k8s.io:
patterns:
- "sigs.k8s.io/*"
- "*"
update-types:
- "minor"
- "patch"
ignore:
- dependency-name: "github.com/spiffe/spire-api-sdk"
- dependency-name: "github.com/spiffe/spire-plugin-sdk"
Expand All @@ -49,5 +35,21 @@ updates:
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: daily
interval: "weekly"
# Wait for new action releases to age before opening update PRs, so
# that a compromised release has a window to be detected and reported
# by the ecosystem before it is proposed for review (e.g. the March
# 2025 tj-actions/changed-files compromise was reverted within days).
cooldown:
default-days: 7
# Collapse all minor and patch updates into a single weekly PR.
# Major bumps remain ungrouped and each one opens its own PR, so
# each breaking change can be reviewed independently.
groups:
minor-and-patch:
patterns:
- "*"
update-types:
- "minor"
- "patch"
open-pull-requests-limit: 20
7 changes: 7 additions & 0 deletions .github/reviewer-pool.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
{
"reviewers": [
"amartinezfayo",
"sorindumitru",
"MarcosDY"
]
}
Loading
Loading