Skip to content

Configure Dependabot for npm and local GitHub Actions - #1659

Merged
aaronpowell merged 2 commits into
CommunityToolkit:mainfrom
afscrome:codex/dependabot-npm
Sep 28, 2026
Merged

aaronpowell merged 2 commits into
CommunityToolkit:mainfrom
afscrome:codex/dependabot-npm

Conversation

@afscrome

@afscrome afscrome commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Dependabot does not configure npm version updates, and its GitHub Actions configuration only scans workflows. The shared local composite action is omitted, leaving its action versions unchanged even when the same actions are updated in workflows.

Add recursive npm coverage (**/*) for examples and validation projects. Extend GitHub Actions coverage to / and /.github/actions/*, retaining the weekly schedules, existing labels, and the intentional ignore rule for compiler-managed github/gh-aw-actions/** dependencies.

The linked CI run warns about actions targeting Node.js 20, including setup-dotnet, setup-java, setup-node, setup-python, cache, setup-uv, login-action, setup-aspire, and setup-ollama. All are referenced in .github/actions/setup-runtimes-caching/action.yml, which the current root-only configuration does not scan. This change lets Dependabot propose updates there; action versions will change in subsequent update PRs.

Validation

  • Parsed .github/dependabot.yml successfully with the js-yaml CLI.
  • Checked that the configuration covers all 18 workflow files and the local composite action containing 15 action dependencies.
  • git diff --check passes.
  • Verified directory handling against Dependabot's GitHub Actions file fetcher.
  • Confirmed npm coverage includes the Nx and Turborepo lockfiles referenced by the open Dependabot alerts.

PR Checklist

  • Created a feature/dev branch in the fork
  • Based off latest main branch of toolkit at creation
  • PR does not include merge commits
  • Contains no breaking changes
  • Code follows existing configuration style

Other information

Security updates are controlled by a separate repository setting. The authenticated account has maintain access but lacks admin access, so that setting could not be verified. An administrator should confirm Dependabot security updates are enabled; this config change alone does not enable that setting.

Copilot AI lite review requested due to automatic review settings September 27, 2026 11:26
@github-actions

Copy link
Copy Markdown
Contributor

🚀 Dogfood this PR with:

⚠️ WARNING: Do not do this without first carefully reviewing the code of this PR to satisfy yourself it is safe.

curl -fsSL https://raw.githubusercontent.com/CommunityToolkit/Aspire/main/eng/scripts/dogfood-pr.sh | bash -s -- 1659

Or

  • Run remotely in PowerShell:
iex "& { $(irm https://raw.githubusercontent.com/CommunityToolkit/Aspire/main/eng/scripts/dogfood-pr.ps1) } 1659"

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The reviewed configuration change has no unresolved blocking issues.

Review effort: Lite
Findings: None

What changed in this PR

Adds weekly Dependabot npm updates for package manifests across nested project directories.

Changes:

  • Configures recursive npm dependency scanning.
  • Reuses existing weekly schedule and dependency labels.
File Description
.github/​dependabot.yml Adds recursive npm Dependabot updates.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@afscrome afscrome changed the title Enable Dependabot updates for npm dependencies Configure Dependabot for npm and local GitHub Actions Sep 27, 2026
@aaronpowell
aaronpowell merged commit aa70831 into CommunityToolkit:main Sep 28, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants