Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
49 changes: 41 additions & 8 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -1,15 +1,34 @@
# Dependabot — weekly grouped updates, single PR per ecosystem.
# Dependabot — weekly grouped updates; minor/patch batched, majors isolated.
#
# Rationale (HIVE-115 follow-up, 2026-05-22):
# - We pin ``mcp >= 1.26, < 2.0`` in pyproject.toml because
# - We pin ``mcp >= 1.27, < 3.0`` in pyproject.toml because
# src/hive/_compat.py monkey-patches private internals of
# mcp.shared.session.RequestResponder (upstream tracker:
# modelcontextprotocol/python-sdk#2610). Dependabot's `ignore`
# modelcontextprotocol/python-sdk#2416). Dependabot's `ignore`
# block below keeps it from trying to lift that cap automatically;
# any mcp bump must be a deliberate code review against the shim.
Comment thread
coderabbitai[bot] marked this conversation as resolved.
# - Grouping all routine bumps into ONE PR per ecosystem per week
# avoids the "20 stale Dependabot PRs" noise pattern. Pairs with
# - Grouping routine bumps per ecosystem per week avoids the
# "20 stale Dependabot PRs" noise pattern. Pairs with
# release-please for ergonomic batch merges.
#
# Amended 2026-08-07 (#334): a `*`-pattern group restricted to
# minor+patch does not merely batch majors — it EXCLUDES them. `pip`
# and `npm` had one such group each, so no major bump could reach
# either ecosystem, including a security bump that requires one. That
# is how a high-severity `cryptography` advisory (48.0.1 -> 50.0.0,
# transitive via authlib <- fastmcp) sat with no PR while an earlier
# *patch* advisory on the same package had sailed through (#137).
#
# Fix: a second group per affected ecosystem, matching the same `*`
# but claiming `major` only. Two groups with identical patterns are
# non-overlapping when their update-types are disjoint, so minors stay
# batched while a major arrives as its OWN reviewable PR — which is
# what a breaking bump deserves. `open-pull-requests-limit` is raised
# to 2 so the two groups do not compete for one slot; the noise
# ceiling stays bounded (2 per ecosystem, not 20).
Comment on lines +14 to +28

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

repo="$(gh repo view --json nameWithOwner -q .nameWithOwner)"

rg -n -A 12 -B 2 \
  'python-all|python-major|site-all|site-major|open-pull-requests-limit' \
  .github/dependabot.yml

gh api "repos/${repo}/dependabot/alerts/57" \
  --jq '[.dependabot_alert.number, .dependency.package.name, .state, .security_advisory.severity] | `@tsv`'

gh pr list \
  --repo "$repo" \
  --state all \
  --search 'author:app/dependabot cryptography' \
  --json number,title,state,url \
  --jq '.[] | [.number, .state, .title, .url] | `@tsv`'

Repository: mlorentedev/hive

Length of output: 3835


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

python3 - <<'PY'
from pathlib import Path
p = Path('.github/dependabot.yml')
text = p.read_text().splitlines()
for i, line in enumerate(text, start=1):
    if i in {14,24,65,121}:
        print(f'{i}: {line}')
PY

Repository: mlorentedev/hive

Length of output: 451


🌐 Web query:

GitHub Dependabot groups update-types major patches minor patch does not update major version

💡 Result:

In GitHub Dependabot, the update-types configuration within a groups rule is used to filter which semantic versioning (SemVer) updates are included in a specific grouped pull request [1][2]. When you configure update-types to include only minor and patch updates, the intended and documented behavior is that Dependabot should group these specific updates while continuing to open separate, individual pull requests for any major version updates [3][4]. However, users have reported issues (such as GitHub issue #14202) where dependencies that match a group's patterns but have a major update available are sometimes silently suppressed rather than receiving an individual pull request [4]. Because of this, relying solely on update-types to filter major updates may not always result in the creation of individual major-version pull requests [4]. To explicitly prevent or control major version updates while using grouping, the recommended approach is to combine update-types with an ignore condition in your dependabot.yml [5][3]: version: 2 updates: - package-ecosystem: "npm" directory: "/" groups: minor-and-patch: patterns: - "" update-types: - "minor" - "patch" ignore: - dependency-name: "" update-types: ["version-update:semver-major"] By using an ignore condition, you explicitly tell Dependabot not to propose major updates, which avoids the uncertainty of whether they will be opened as individual pull requests or suppressed [5][3].

Citations:


🌐 Web query:

Dependabot security updates open pull requests limit global version updates security updates separate limit

💡 Result:

Dependabot treats version updates and security updates differently regarding open pull request limits [1][2]. The open-pull-requests-limit configuration option specifically controls the maximum number of open pull requests for version updates [1][3]. The default limit for version updates is five [1][2][4]. If this limit is reached, Dependabot will not open further version update pull requests until existing ones are merged or closed [1][2][4]. Setting this limit to zero effectively disables version updates for that package manager [1][5][6]. Security update pull requests operate under a different system and are not constrained by the open-pull-requests-limit [1][7]. They do not count toward the version update limit [1][8]. While some historical documentation (such as for GitHub Enterprise Server 3.5) mentioned an internal limit for security updates [4], current authoritative GitHub documentation states that there is no limit on the number of open pull requests for security updates [1][7][8]. Security updates are triggered by vulnerability advisories rather than the schedule that governs version updates [3][9]. If you wish to manage the volume of security update pull requests, you can use the grouping feature in your dependabot.yml file [5][3]. By using the groups option with the applies-to: security-updates key, you can consolidate multiple security updates into a single pull request [5][10][9].

Citations:


Correct the Dependabot grouping notes.

A minor/patch group does not exclude major updates, so the python-major and site-major notes should not say majors were excluded. These groups group schedule-driven major version updates while minors/patches stay batched. The open-pull-requests-limit change also does not address security updates directly.

[correct_review_comment]

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/dependabot.yml around lines 14 - 28, The Dependabot comments around
the grouping configuration incorrectly claim that minor/patch groups exclude
major and that open-pull-requests-limit addresses security updates. Rewrite the
notes to state that python-major and site-major group scheduled major updates
separately while minor and patch updates remain batched, and remove the
implication that the PR limit directly fixes security-update handling.

#
# github-actions and docker were already unfiltered and so unaffected;
# they are deliberately left with a single all-types group.
# - github-actions ecosystem is included so CI workflows stay
# on supported runners + action versions.
# - site/ has its own package.json (Astro + Starlight); covered as a
Expand All @@ -30,7 +49,7 @@ updates:
day: "monday"
time: "07:00"
timezone: "America/Denver"
open-pull-requests-limit: 1
open-pull-requests-limit: 2
commit-message:
prefix: "chore(deps)"
include: "scope"
Expand All @@ -43,10 +62,18 @@ updates:
update-types:
- "minor"
- "patch"
# Disjoint update-types from python-all, so majors are isolated
# into their own PR rather than excluded entirely (#334).
python-major:
patterns:
- "*"
update-types:
- "major"
ignore:
# _compat.py patches mcp internals; major bumps must be reviewed
# by hand against tests/test_compat_shim.py. Track upstream at
# modelcontextprotocol/python-sdk#2610.
# modelcontextprotocol/python-sdk#2416 (NOT #2610 — the __exit__
# patch for that one was removed; see hive#127 and hive#336).
- dependency-name: "mcp"
update-types:
- "version-update:semver-major"
Expand Down Expand Up @@ -78,7 +105,7 @@ updates:
day: "monday"
time: "07:00"
timezone: "America/Denver"
open-pull-requests-limit: 1
open-pull-requests-limit: 2
commit-message:
prefix: "chore(site)"
include: "scope"
Expand All @@ -91,6 +118,12 @@ updates:
update-types:
- "minor"
- "patch"
# Same fix as python-major (#334): majors were excluded, not batched.
site-major:
patterns:
- "*"
update-types:
- "major"

# ── Docker base image (Dockerfile) ────────────────────────────
- package-ecosystem: "docker"
Expand Down
Loading