Skip to content

Feat/ FLY 2050/ Update dependabot config#378

Merged
AndresQuijano merged 1 commit intomasterfrom
feat/fly2050/dependabot_config
Dec 3, 2025
Merged

Feat/ FLY 2050/ Update dependabot config#378
AndresQuijano merged 1 commit intomasterfrom
feat/fly2050/dependabot_config

Conversation

@AndresQuijano
Copy link
Copy Markdown
Contributor

What

Updates dependabot config:

  • Changed regular dependency updates from daily to weekly.
  • Added 10-day cooldown period for regular updates
  • Implemented separate daily checks for security updates with 1-day cooldown
  • Adde labels for better PR categorization
  • Applied these improvements across all three package ecosystems: Go modules, GitHub Actions, and Docker

Why

Reduce the number of routine dependency PRs while maintaining rapid response to security vulnerabilities.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change
  • Documentation update
  • Refactoring (no functional changes, no api changes)
  • Performance improvement
  • Test updates
  • Security fix
  • Deployment/Infrastructure changes

Affected part of the project

  • Management UI / API
  • PegIn flow
  • PegOut flow
  • Utility scripts
  • Configuration files
  • Metrics and alerting

Related Issues

FLY-2050

@AndresQuijano AndresQuijano requested a review from a team as a code owner December 3, 2025 17:49
@github-actions
Copy link
Copy Markdown

github-actions bot commented Dec 3, 2025

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails

Scanned Files

@AndresQuijano AndresQuijano merged commit e8e124d into master Dec 3, 2025
6 checks passed
@AndresQuijano AndresQuijano deleted the feat/fly2050/dependabot_config branch December 3, 2025 18:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants