Skip to content

chore: configure grouped dependency updates #9

Description

@enliven17

Problem

Dependencies span npm, Python, Rust, Stellar, and Noir ecosystems and currently have no update policy.

Scope

Implement this as one focused change in devx. Keep unrelated refactors out of the pull request.

Acceptance Criteria

  • Configure automated dependency update checks for npm, pip, Cargo, and GitHub Actions
  • Group low-risk patch updates
  • Keep Stellar, Noir, and proof-system updates separate for focused review
  • Set a conservative schedule and PR limit

Test Plan

  • Validate the configuration and document how maintainers can pause or ignore an update.
  • Existing checks for the affected workspace pass.

Out of Scope

  • Unrelated product features or broad dependency upgrades.
  • Production deployment or changes to live credentials.

Drips Wave

Complexity: trivial

Before starting, apply through Drips Wave and wait to be assigned. The pull request must include Closes #, test evidence, and any relevant screenshots or security notes.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar Wave programarea/devxDeveloper experience, CI, and documentationcomplexity/trivial100 points - small, bounded changehelp wantedExtra attention is neededtype/ciCI/CD pipeline

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions