Skip to content

chore(ci): improve dependabot config and group coupled gradle deps#403

Merged
maxlambrecht merged 1 commit intospiffe:mainfrom
maxlambrecht:chore/update-dependabot
Feb 17, 2026
Merged

chore(ci): improve dependabot config and group coupled gradle deps#403
maxlambrecht merged 1 commit intospiffe:mainfrom
maxlambrecht:chore/update-dependabot

Conversation

@maxlambrecht
Copy link
Member

What

Update Dependabot configuration for the Java SPIFFE repo:

  • Switch Gradle and GitHub Actions updates to weekly cadence
  • Add Conventional Commit prefixes
  • Group only tightly coupled dependency stacks:
    • gRPC / Netty
    • Protobuf toolchain
    • Test dependencies
  • Leave all other dependencies ungrouped for isolated PRs

Why

  • Reduce PR noise while keeping risky dependencies independently reviewable
  • Keep related libraries upgraded together to avoid version skew

Signed-off-by: Max Lambrecht <maxlambrecht@gmail.com>
@maxlambrecht maxlambrecht changed the title chore(ci): simplify dependabot config and group coupled gradle deps chore(ci): improve dependabot config and group coupled gradle deps Feb 14, 2026
@maxlambrecht maxlambrecht merged commit 753812a into spiffe:main Feb 17, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

Comments