From fc0a77641b9ba5f3c7f96c4f7da0938241d7b98e Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Sat, 2 May 2026 17:29:58 -0400 Subject: [PATCH] Add Dependabot version update configuration standards Documents the org-wide policy for dependabot.yml files: ecosystem selection, standard templates for single/multi-ecosystem repos and SAM projects, auto-assignment, and merge guidance. --- github-standards.md | 86 +++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 86 insertions(+) diff --git a/github-standards.md b/github-standards.md index 7bc658a..1a517ea 100644 --- a/github-standards.md +++ b/github-standards.md @@ -6,6 +6,92 @@ - Every repo gets a one-line description - Default to `private` visibility for org repos - Dependabot alerts and security updates enabled on all active repos +- Org-level defaults auto-enable alerts and security updates on new repos +- Every repo with dependencies gets a `.github/dependabot.yml` for weekly version updates + +## Dependabot Configuration + +Every active repo with package dependencies must have a `.github/dependabot.yml` that covers all relevant ecosystems. All entries must assign PRs to `amoussa1229`. + +### Ecosystem Selection + +Choose ecosystems based on what dependency files exist in the repo: + +| File | Ecosystem | +|------|-----------| +| `package.json` | `npm` | +| `requirements.txt` | `pip` | +| `.csproj` | `nuget` | +| `.github/workflows/*.yml` | `github-actions` | + +### Standard Templates + +**Single ecosystem (npm or pip):** + +```yaml +version: 2 +updates: + - package-ecosystem: "npm" # or "pip", "nuget", "github-actions" + directory: "/" + schedule: + interval: "weekly" + assignees: + - "amoussa1229" +``` + +**SAM project with per-function `requirements.txt`:** + +Add a separate entry for each directory containing a `requirements.txt`: + +```yaml +version: 2 +updates: + - package-ecosystem: "pip" + directory: "/src/processor" + schedule: + interval: "weekly" + assignees: + - "amoussa1229" + - package-ecosystem: "pip" + directory: "/src/receiver" + schedule: + interval: "weekly" + assignees: + - "amoussa1229" +``` + +**Mixed ecosystems (e.g., CDK in JS with Python Lambdas, or repos with GitHub Actions):** + +Add one entry per ecosystem/directory: + +```yaml +version: 2 +updates: + - package-ecosystem: "npm" + directory: "/" + schedule: + interval: "weekly" + assignees: + - "amoussa1229" + - package-ecosystem: "pip" + directory: "/src" + schedule: + interval: "weekly" + assignees: + - "amoussa1229" + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" + assignees: + - "amoussa1229" +``` + +### Merging Dependabot PRs + +- **Patch and minor bumps:** Safe to merge without review in most cases +- **Major version bumps:** Review changelog for breaking changes before merging +- When merging multiple Dependabot PRs, merge one at a time — subsequent PRs will auto-rebase ## Branch Protection