Skip to content

Conversation

@karrui
Copy link
Collaborator

@karrui karrui commented Nov 17, 2025

This pull request updates the Dependabot configuration to improve dependency update management and enhance security. The main changes group related dependencies for updates, introduce a cooldown period to slow down update frequency, and remove the previous ignore list in favor of these new groups.

Dependabot configuration improvements:

  • Switched the update interval from daily to weekly and added a 7-day cooldown to reduce update frequency and mitigate supply chain attack risks.

Dependency grouping:

  • Replaced the ignore list with explicit update groups for related dependencies (such as prisma, react, react-query, storybook, tailwindcss, trpc, turbo, and oui), ensuring that related packages are updated together to avoid breaking changes.

@vercel
Copy link

vercel bot commented Nov 17, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Preview Comments Updated (UTC)
starter-kit Ready Ready Preview Comment Nov 17, 2025 6:01am

@karrui karrui merged commit b43d14d into main Nov 17, 2025
12 checks passed
@karrui karrui deleted the update-dependabot branch November 17, 2025 06:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant