Skip to content

Commit d0dd618

Browse files
oc-tmuellerclaude
andauthored
chore: give the 4.2 maintenance branch Dependabot coverage (#626)
Nothing has ever watched the oc10 branch, which is why it drifted to 84 advisories against master's 39. Dependabot reads .github/dependabot.yml only from the default branch, so 4.2 cannot carry its own copy -- the coverage has to live here, as a second set of entries with target-branch: "4.2". Be clear on what this does and does not buy. target-branch produces weekly *version update* PRs against 4.2, which is the mechanism that keeps the branch from going stale. Dependabot security *alerts* stay default-branch-only, and GitHub does not create security updates for a target-branch at all. So 4.2 gets routine bumps but never an alert; its scanning coverage is the Trivy job added on that branch instead. Schedule, PR limit and the minor-and-patch grouping mirror the existing entries exactly, so the two branches behave the same way. Signed-off-by: Thomas Müller <323649642+oc-tmueller@users.noreply.github.com> Co-authored-by: Thomas Müller <323649642+oc-tmueller@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
1 parent 112ed2d commit d0dd618

1 file changed

Lines changed: 58 additions & 0 deletions

File tree

‎.github/dependabot.yml‎

Lines changed: 58 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,63 @@
11
version: 2
2+
3+
# The entries below are duplicated per branch on purpose. Dependabot reads this
4+
# file only from the default branch, so the oc10 maintenance branch cannot carry
5+
# its own copy - it is covered by the "target-branch: 4.2" entries here.
6+
#
7+
# Note what that does and does not buy: target-branch produces weekly *version
8+
# update* PRs against 4.2, which is what keeps the branch from going stale.
9+
# Dependabot security *alerts* remain default-branch-only, and GitHub does not
10+
# create security updates for a target-branch at all. So 4.2 gets routine bumps
11+
# but never an alert; its scanning coverage is the Trivy job on that branch.
12+
213
updates:
14+
# ---------------------------------------------------------------- master (oc11)
15+
- package-ecosystem: composer
16+
directory: "/"
17+
schedule:
18+
interval: weekly
19+
day: sunday
20+
time: '22:00'
21+
timezone: Etc/UTC
22+
open-pull-requests-limit: 5
23+
groups:
24+
minor-and-patch:
25+
update-types:
26+
- minor
27+
- patch
28+
29+
- package-ecosystem: npm
30+
directory: "/"
31+
schedule:
32+
interval: weekly
33+
day: sunday
34+
time: '22:00'
35+
timezone: Etc/UTC
36+
open-pull-requests-limit: 5
37+
groups:
38+
minor-and-patch:
39+
update-types:
40+
- minor
41+
- patch
42+
43+
- package-ecosystem: github-actions
44+
directory: "/"
45+
schedule:
46+
interval: weekly
47+
day: sunday
48+
time: '22:00'
49+
timezone: Etc/UTC
50+
open-pull-requests-limit: 5
51+
groups:
52+
minor-and-patch:
53+
update-types:
54+
- minor
55+
- patch
56+
57+
# ------------------------------------------------------------------- 4.2 (oc10)
358
- package-ecosystem: composer
459
directory: "/"
60+
target-branch: "4.2"
561
schedule:
662
interval: weekly
763
day: sunday
@@ -16,6 +72,7 @@ updates:
1672

1773
- package-ecosystem: npm
1874
directory: "/"
75+
target-branch: "4.2"
1976
schedule:
2077
interval: weekly
2178
day: sunday
@@ -30,6 +87,7 @@ updates:
3087

3188
- package-ecosystem: github-actions
3289
directory: "/"
90+
target-branch: "4.2"
3391
schedule:
3492
interval: weekly
3593
day: sunday

0 commit comments

Comments
 (0)