Skip to content

chore: remove Dependabot in favour of Renovate#13

Merged
shionit merged 2 commits into
mainfrom
chore/remove-dependabot
May 10, 2026
Merged

chore: remove Dependabot in favour of Renovate#13
shionit merged 2 commits into
mainfrom
chore/remove-dependabot

Conversation

@shionit
Copy link
Copy Markdown
Owner

@shionit shionit commented May 10, 2026

Summary

  • Removes .github/dependabot.yml — eliminates duplicate update PRs with Renovate
  • Bumps actions/checkout to v6.0.2 (de0fac2e...) across all three workflows — resolves the version mismatch between devcontainer-ci.yml (was v4.2.2) and the other two (were v4.3.1)

Why remove Dependabot

Both Dependabot and Renovate were tracking Docker and GitHub Actions updates, producing duplicate PRs for the same changes. Renovate is kept because it provides SHA digest pinning, grouped updates, automerge policies, and granular scheduling that Dependabot does not.

The dependency-review and scorecards workflows are unaffected — they scan for vulnerabilities and score supply-chain posture independently of which updater is in use.

Why align actions/checkout

With all three workflows on the same SHA, Renovate will batch future updates into a single grouped PR (per the groupName: "GitHub Actions" rule in renovate.json) instead of opening separate PRs per workflow.

shionit added 2 commits May 10, 2026 17:35
Both Dependabot and Renovate were updating Docker and GitHub Actions
dependencies, producing duplicate PRs. Renovate provides the same
coverage with better grouping, SHA pinning, and automerge control,
so Dependabot is removed.

The dependency-review and scorecards workflows are unaffected — they
scan for vulnerabilities and score supply-chain posture independently
of which updater is in use.
Aligns the three workflows to the same actions/checkout SHA
(de0fac2e4500dabe0009e67214ff5f5447ce83dd) so Renovate can update
them as a single grouped PR going forward.
@shionit shionit merged commit aa7e6d1 into main May 10, 2026
2 checks passed
@shionit shionit deleted the chore/remove-dependabot branch May 10, 2026 10:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant