Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,9 @@ updates:
directory: /
schedule:
interval: weekly
ignore:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium critique confident

Do not ignore patch updates for GitHub Actions

The same wildcard is applied to the GitHub Actions update group, so patch releases of actions used by CI are never proposed. That can leave workflow actions on outdated patch versions despite the repository's stated weekly Dependabot maintenance and supply-chain checks. Remove this blanket ignore or enumerate only actions whose patch updates have been deliberately excluded.


Additional critique observation

priority medium confident

Do not ignore every patch update

[RULE] ignore-all-patch-updates

This wildcard suppresses patch updates for every dependency in the group, including patch releases containing bug fixes or non-security corrections. The repository's weekly Dependabot configuration will therefore leave dependencies and actions stale until a minor/major release or a manual update occurs. Restrict the ignore rule to explicitly reviewed dependencies, or remove it so patch updates continue to be proposed.


Additional security observation

priority medium confident

Do not suppress patch updates for every dependency

[RULE] dependency-update-suppression

This wildcard ignore applies to every dependency in the Cargo and GitHub Actions update groups, preventing normal patch-level updates from being proposed. Patch releases commonly contain bug fixes and security fixes that may not be surfaced as Dependabot security updates, so this can leave the repository running vulnerable or broken dependency versions indefinitely. Remove the blanket ignore or scope it to specific dependencies with a documented compatibility reason.


Additional security observation

priority medium confident

Continue proposing patch updates for GitHub Actions

[RULE] dependency-update-suppression

The same blanket suppression is added to the GitHub Actions update group, so patch updates to CI actions such as checkout, toolchain, caching, and supply-chain checks will no longer be proposed. This delays action security and correctness fixes across the repository's CI boundary. Keep patch updates enabled or restrict the ignore rule to an explicitly reviewed action.

[RULE] ignore-all-patch-updates ·

- dependency-name: "*"
update-types: ["version-update:semver-patch"]
open-pull-requests-limit: 5
commit-message:
prefix: "deps"
Expand All @@ -18,6 +21,9 @@ updates:
directory: /
schedule:
interval: weekly
ignore:
- dependency-name: "*"
update-types: ["version-update:semver-patch"]
open-pull-requests-limit: 5
commit-message:
prefix: "ci"
Expand Down
Loading