Conversation
A groups entry without applies-to covers version updates only, so security advisories were still arriving one PR per advisory. This adds a *-security group per ecosystem that sets applies-to: security-updates. The security groups match all patterns and so include major bumps, since declining a security fix because it is a major is not a real option. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LpZM2dqedR4fXiLn7272XQ
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
OpenTofu Format and Style
|
|
Superseded by the Dependabot consolidation, now merged on the default branch. That config already includes a This PR is also based on the pre-consolidation file, so it would conflict rather than apply cleanly. The reasoning it documented is preserved in the new config's header comments, including the point that a group without |
Groups Dependabot's security-advisory PRs, which the existing config does not cover.
A
groupsentry withoutapplies-todefaults toversion-updatesonly. So while minor/patch version updates have been arriving grouped since the last PR merged, security advisories still open one PR per advisory. This adds a second group per ecosystem that setsapplies-to: security-updates.Groups after this change
terraformterraformterraform-securitygithub-actionsgithub-actionsgithub-actions-securityNotes
patterns: ["*"], so they include major bumps. That is deliberate — declining a security fix on the grounds that it is a major version bump is not a real option.🤖 Generated with Claude Code
https://claude.ai/code/session_01LpZM2dqedR4fXiLn7272XQ