Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
version: 2

updates:
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

anyway to look for new tags/new releases? not sure if replicating head commit is a good practice - we might accidentally take in bad commits etc.

Copy link
Member Author

@hwei0 hwei0 Dec 11, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This doesn't seem to be supported by dependabot natively, although they are tracking it as an unresolved issue: dependabot/dependabot-core#1639

I think if we want to do any customization (eg do it on triggered basis, only track specific directories in the boto3/botocore dependencies, track specific release tags) then we will need to find another 3rd party bot/action or make our own action. E.g. https://docs.renovatebot.com/modules/manager/git-submodules/ seems like a decent 3p alternative

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah, action will offer more customizability. the part taking time would be to setup a bot account and let it create a PR, but there might be actions already automated this

- package-ecosystem: gitsubmodule
schedule:
interval: "weekly"
directory: /