Configure Dependabot for npm and local GitHub Actions - #1659
Merged
aaronpowell merged 2 commits intoSep 28, 2026
Merged
Conversation
Contributor
|
🚀 Dogfood this PR with:
curl -fsSL https://raw.githubusercontent.com/CommunityToolkit/Aspire/main/eng/scripts/dogfood-pr.sh | bash -s -- 1659Or
iex "& { $(irm https://raw.githubusercontent.com/CommunityToolkit/Aspire/main/eng/scripts/dogfood-pr.ps1) } 1659" |
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The reviewed configuration change has no unresolved blocking issues.
Review effort: Lite
Findings: None
What changed in this PR
Adds weekly Dependabot npm updates for package manifests across nested project directories.
Changes:
- Configures recursive npm dependency scanning.
- Reuses existing weekly schedule and dependency labels.
| File | Description |
|---|---|
.github/dependabot.yml |
Adds recursive npm Dependabot updates. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
aaronpowell
approved these changes
Sep 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Dependabot does not configure npm version updates, and its GitHub Actions configuration only scans workflows. The shared local composite action is omitted, leaving its action versions unchanged even when the same actions are updated in workflows.
Add recursive npm coverage (
**/*) for examples and validation projects. Extend GitHub Actions coverage to/and/.github/actions/*, retaining the weekly schedules, existing labels, and the intentional ignore rule for compiler-managedgithub/gh-aw-actions/**dependencies.The linked CI run warns about actions targeting Node.js 20, including setup-dotnet, setup-java, setup-node, setup-python, cache, setup-uv, login-action, setup-aspire, and setup-ollama. All are referenced in
.github/actions/setup-runtimes-caching/action.yml, which the current root-only configuration does not scan. This change lets Dependabot propose updates there; action versions will change in subsequent update PRs.Validation
.github/dependabot.ymlsuccessfully with the js-yaml CLI.git diff --checkpasses.PR Checklist
Other information
Security updates are controlled by a separate repository setting. The authenticated account has maintain access but lacks admin access, so that setting could not be verified. An administrator should confirm Dependabot security updates are enabled; this config change alone does not enable that setting.