The split Dependabot PRs (#init, #analyze) each bumped one path in security.yml, leaving the sibling at v4.36.2 -> CodeQL fails 'init and analyze must match'. Bump both to v4.36.3 (SHA 54f647b) in one commit, and add a dependabot groups block so codeql-action (init/analyze/upload-sarif, one monorepo release) always lands as a single grouped PR. Fixes the two red Security Scan runs.
33 lines
905 B
YAML
33 lines
905 B
YAML
version: 2
|
|
updates:
|
|
- package-ecosystem: "pip"
|
|
directory: "/"
|
|
schedule:
|
|
interval: "weekly"
|
|
labels:
|
|
- "dependencies"
|
|
open-pull-requests-limit: 5
|
|
commit-message:
|
|
prefix: "deps"
|
|
prefix-development: "deps"
|
|
include: "scope"
|
|
|
|
- package-ecosystem: "github-actions"
|
|
directory: "/"
|
|
schedule:
|
|
interval: "weekly"
|
|
labels:
|
|
- "ci"
|
|
open-pull-requests-limit: 5
|
|
commit-message:
|
|
prefix: "ci"
|
|
include: "scope"
|
|
# codeql-action is a monorepo (init/analyze/upload-sarif share one release).
|
|
# Bumping them in separate PRs leaves mismatched versions in security.yml and
|
|
# CodeQL hard-fails "init and analyze must be the same version". Group them so
|
|
# every codeql-action bump lands as a single PR that moves all paths together.
|
|
groups:
|
|
codeql-action:
|
|
patterns:
|
|
- "github/codeql-action*"
|