Skip to content

Dependabot: Don't ignore GHA minor+patch updates - #158332

Merged
StanFromIreland merged 1 commit into
python:mainfrom
hugovk:unskip-dependabot-gha
Sep 28, 2026
Merged

StanFromIreland merged 1 commit into
python:mainfrom
hugovk:unskip-dependabot-gha

Conversation

@hugovk

@hugovk hugovk commented Sep 28, 2026

Copy link
Copy Markdown
Member

Four years ago, we configured Dependabot to only bump GitHub Actions for major versions, because we used @major version like @v5 rather than @major.minor.patch like @v5.6.0, and @v5 would float so we'd always be on the latest v5.x.x:

Six months ago, we switched from @major to hash-pinned references, to improve security:

However, we do want minor and patch fixes to come through when Dependabot updates. So let's remove these skips.

For example, this will allow mheap/github-action-required-labels to upgrade from v5.5.2 to v5.6.0 and clear the Node deprecation warnings (as seen in #158331).

@StanFromIreland
StanFromIreland merged commit 3efe703 into python:main Sep 28, 2026
59 checks passed
@StanFromIreland

Copy link
Copy Markdown
Member

I don't think we need to backport, considering it'll only ever use the configuration on the default branch.

@hugovk
hugovk deleted the unskip-dependabot-gha branch September 28, 2026 11:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants