Files
AIPass/.github/dependabot.yml
T
AIOSAI 3071ea8eac ci(deps): bump codeql-action init+analyze to v4.36.3 together + group future bumps
The split Dependabot PRs (#init, #analyze) each bumped one path in security.yml,
leaving the sibling at v4.36.2 -> CodeQL fails 'init and analyze must match'.
Bump both to v4.36.3 (SHA 54f647b) in one commit, and add a dependabot groups
block so codeql-action (init/analyze/upload-sarif, one monorepo release) always
lands as a single grouped PR. Fixes the two red Security Scan runs.
2026-07-05 02:07:18 -07:00

33 lines
905 B
YAML

version: 2
updates:
- package-ecosystem: "pip"
directory: "/"
schedule:
interval: "weekly"
labels:
- "dependencies"
open-pull-requests-limit: 5
commit-message:
prefix: "deps"
prefix-development: "deps"
include: "scope"
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
labels:
- "ci"
open-pull-requests-limit: 5
commit-message:
prefix: "ci"
include: "scope"
# codeql-action is a monorepo (init/analyze/upload-sarif share one release).
# Bumping them in separate PRs leaves mismatched versions in security.yml and
# CodeQL hard-fails "init and analyze must be the same version". Group them so
# every codeql-action bump lands as a single PR that moves all paths together.
groups:
codeql-action:
patterns:
- "github/codeql-action*"