Skip to content

Bump dependencies & introduce Dependabot for automated updates #123

@msbelaid

Description

@msbelaid

Summary

Manually update Kotlin, Gradle, Coil, Koin, and other outdated dependencies, then introduce a Dependabot configuration to automate future dependency update PRs.

Checklist

Ensure all of the following pass before merging:

  • Debug build
  • Release build
  • Unit tests
  • Ktlint
  • Screenshot tests
  • UI tests

Dependabot Configuration

  • Weekly schedule (Mondays)
  • Gradle and GitHub Actions ecosystems both covered
  • Dependencies grouped by ecosystem (AndroidX, Compose, Kotlin, Koin, Coil…)
  • Major version bumps ignored for AGP
  • Meaningful labels added (dependencies, android, ci)
  • Conventional commit prefix set (chore for deps, ci for actions)
  • Branch protection rule requires CI to pass before Dependabot PRs can merge

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions