ci(dependabot): remove grouping of production deps to be updated - #36469
Open
PaulGMardling wants to merge 4 commits into
Open
ci(dependabot): remove grouping of production deps to be updated#36469PaulGMardling wants to merge 4 commits into
PaulGMardling wants to merge 4 commits into
Conversation
📊 Bundle size report✅ No changes found |
|
Pull request demo site: URL |
PaulGMardling
marked this pull request as ready for review
July 31, 2026 13:45
PaulGMardling
marked this pull request as draft
July 31, 2026 14:14
Keep development, security, and GitHub Actions grouping while disabling routine production npm version updates. Restore the manual Dependabot rollup workflow and documentation.
Keep the manual rollup skill unchanged so it continues to recognize existing production dependency group pull requests.
Persist source PR metadata in rollup PR bodies and add a guarded cleanup mode that refreshes only open Dependabot-authored PRs after the rollup merges.
PaulGMardling
marked this pull request as ready for review
July 31, 2026 15:49
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Previous Behavior
Dependabot grouped development, production, GitHub Actions, and security dependency updates into consolidated pull requests. This included routine production dependency bumps, which could create unnecessary release and customer churn.
Manual rollups also had no reusable process for refreshing their source Dependabot PRs after merge.
New Behavior
Dependabot no longer creates routine production dependency version updates.
This PR:
/dependabot-rollupskill and its documentation./dependabot-rollup --cleanup <rollup-pr>for post-merge cleanup.Related Issue(s)
Follow-up to #36394.