Skip to content

Run Dependabot independently on each branch - #158361

Merged
hugovk merged 5 commits into
python:mainfrom
hugovk:dependabot-multibranch
Sep 29, 2026
Merged

hugovk merged 5 commits into
python:mainfrom
hugovk:dependabot-multibranch

Conversation

@hugovk

@hugovk hugovk commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Rather than backporting Dependabot updates, which will pretty much always have conflicts due to different workflows, and which we often forget to do (causing more conflicts), let's have Dependabot run on each branch.

The config belongs in main, and unfortunately needs repeating, but each block is fairly small.

(Renovate would allow us to use a regex and avoid the repetition, but that's a bigger move involving installing a new app. But I'm a happy Renovate user in other projects, so it's always an option for later.)

@ezio-melotti ezio-melotti left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's unfortunate that there's no easy way to do it (unless target-branch: "3.*" works, but it's not documented).

This feature has been requested upstream before:

Here is the relevant documentation: https://docs.github.com/en/code-security/tutorials/secure-your-dependencies/customizing-dependabot-prs#targeting-pull-requests-against-a-non-default-branch

Also note this:

Dependabot raises pull requests for security updates against the default branch only. If you use target-branch, then as a result, all configuration settings for that package manager will then only apply to version updates, and not security updates.

Comment thread .github/dependabot.yml
cooldown:
default-days: 14

- package-ecosystem: "pip"

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would move this to the top, so that all the main sections are together. Perhaps it should also be duplicated for all branches.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Duplicated for bugfix branches only: updating mypy for security branches may need code changes which we don't want to do for security. Hypothesis is the other pip thing, which I'm not sure needs regular updates for security either. We can do manual backports if something is needed?

Moved to the top, so we have:

  • GHA main
  • pip main
  • GHA bugfix+security
  • pip bugfix

I also added grouping for pip updates, so we get a single PR per branch instead of several per branch.

Comment thread .github/dependabot.yml Outdated
@hugovk

hugovk commented Sep 29, 2026

Copy link
Copy Markdown
Member Author

It's unfortunate that there's no easy way to do it (unless target-branch: "3.*" works, but it's not documented).

Yeah. If this becomes a pain, we can switch to Renovate and replace the repetition with a regex.

Also note this:

Dependabot raises pull requests for security updates against the default branch only. If you use target-branch, then as a result, all configuration settings for that package manager will then only apply to version updates, and not security updates.

Good to know. So we might need to do our own backports of those.

@hugovk
hugovk merged commit 1407bb9 into python:main Sep 29, 2026
49 checks passed
@hugovk
hugovk deleted the dependabot-multibranch branch September 29, 2026 08:23
@hugovk

hugovk commented Sep 29, 2026

Copy link
Copy Markdown
Member Author

This worked :)

We do need to edit the titles to prefix [3.15] and so on, but much easier than manually backporting and fixing conflicts.

And because it's a fresh update, Dependabot updates all files, which are easier to miss when manually backporting. Plus the title counts are accurate. Compare:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

infra CI, GitHub Actions, buildbots, Dependabot, etc. skip issue skip news

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants