From 693727014c568272a39d8930237197a7bf4d45e6 Mon Sep 17 00:00:00 2001 From: Mark Ridley <210189+maudlin@users.noreply.github.com> Date: Mon, 22 Jun 2026 11:59:49 +0100 Subject: [PATCH] ci: add a scoped Dependabot config (Actions + Docker base) (#111) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Version updates for the only two ecosystems safe to auto-bump here: GitHub Actions and the Docker base image (FROM tag). Weekly, grouped per ecosystem. Deliberately excludes the bundled security tools — they are pinned by exact version and SHA256-verified as `RUN curl` steps (the download-verification ADR), not FROM lines, so Dependabot neither sees nor should touch them. No root npm/pip/go/cargo manifests, so no app-dependency ecosystem to manage. Closes #111. Co-Authored-By: Claude Opus 4.8 (1M context) --- .github/dependabot.yml | 36 ++++++++++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..a3d381b --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,36 @@ +# Dependabot — version updates, deliberately scoped (#111). +# +# Only the two ecosystems that are safe to auto-bump on this repo: +# - the GitHub Actions used in the workflows +# - the Docker base image (a `FROM` tag) in the Dockerfiles +# +# Explicitly NOT managed — the bundled security tools (gitleaks, semgrep, scc, +# lizard, …) are pinned by exact version AND SHA256-verified as `RUN curl` steps +# inside the Dockerfiles (the download-verification ADR). Those are not `FROM` +# lines, so Dependabot never sees them — and must not, since bumping a tool out +# from under its `sha256sum -c` check would break the build by design. There are +# also no npm/pip/go/cargo manifests at the repo root, so there is no application- +# dependency ecosystem to manage. +# +# Weekly cadence, grouped into one PR per ecosystem to keep the noise low. +version: 2 +updates: + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" + groups: + github-actions: + patterns: ["*"] + commit-message: + prefix: "ci" + + - package-ecosystem: "docker" + directory: "/" + schedule: + interval: "weekly" + groups: + docker: + patterns: ["*"] + commit-message: + prefix: "build"