chore: add dependabot config for automated PRs - #655
Conversation
Greptile SummaryThe PR adds monthly Dependabot version-update configuration for the repository’s npm, GitHub Actions, and Xcode-managed Swift dependencies.
Confidence Score: 4/5The GitHub Actions grouping configuration should be fixed before merging because it bundles major action upgrades that the PR intends to isolate for review. The catch-all GitHub Actions group lacks the minor/patch filter present on the npm and Swift groups, so major action upgrades enter the grouped monthly pull request. Files Needing Attention: .github/dependabot.yml
|
| Filename | Overview |
|---|---|
| .github/dependabot.yml | Adds the three intended Dependabot ecosystems, but the GitHub Actions group unintentionally includes major updates despite the stated standalone-review policy. |
Reviews (1): Last reviewed commit: "chore: add dependabot config" | Re-trigger Greptile
ovitrif
left a comment
There was a problem hiding this comment.
The Dependabot config matches the repo: npm under test-push-server, Actions at root with major/minor groups for floating tags, and Swift ignores for the Synonym FFI packages that need coordinated bumps.
Description
This PR:
dependabot.ymlcovering the three package ecosystems this repo actually has — thetest-push-servernpm tree, the workflow actions, and the Xcode-managedPackage.resolvedThe repo has had Dependabot alerts enabled for a long time but has never had a Dependabot pull request — there is no config file, so nothing was ever proposed. All 30 historical alerts are closed as fixed because they were cleaned up by hand, most recently in #651. This is the piece that stops that from being manual work.
One thing this does not do on its own, and it is the important caveat: a config file only turns on version updates. Turning an advisory into a pull request is a separate repo setting, and it needs admin on the repo. Merging this alone will not make alerts arrive as pull requests. The two halves are complementary: version updates keep dependencies current so advisories land less often, security updates handle the ones that land anyway.
Admin steps to finish enabling this
Either tick Settings → Advanced Security → Dependabot security updates, or run the equivalent from the CLI. Both endpoints require admin on the repository and return
204 No Contenton success:Verify afterwards:
The dependency graph needs no action: it is on by default for public repositories and cannot be turned off.
Swift is included because it only recently became possible. Dependabot required a top-level
Package.swiftuntil 31 March 2026, when it gained the ability to discoverPackage.resolvednested inside.xcodeprojand.xcworkspacebundles and to read version rules out ofproject.pbxproj. That is exactly this repo's layout, so the ecosystem is supported here for the first time. It is also the least proven part of the change, which is why the QA notes below include a fallback to an explicitdirectories:path if the resolver does not find the manifest.Grouping is the cost control rather than a tidiness preference. Unit tests and integration tests run on every pull request with no path filter, both on
macos-15with hour-long timeouts, and the e2e suite fires on anything touchingBitkit.xcodeproj/**or its own workflow file — which a Swift bump and an actions bump respectively do. Ungrouped, a month with six updates is six full CI runs. Grouping holds it to a handful.Majors are kept out of the routine batches, but how that is expressed differs by ecosystem. For npm and swift the groups take minor and patch only, so a major bump falls through to its own pull request. Actions are a different case: every one of them is pinned to a floating major tag (
actions/checkout@v6,upload-artifact@v7, and so on), so every update Dependabot can propose for them is a major one. Restricting that group the same way would mean it never fires and each action arrives as its own pull request with its own full CI run. Instead the actions entry has two groups, minor/patch and major, both matching everything — a dependency lands in the first group it matches, so major action bumps get a dedicated pull request separate from routine updates without fanning out into eight of them.The four ignored packages are
bitkit-core,ldk-node,vss-rust-client-ffiandpaykit-rs. Two are on release candidates, one is pinned to a branch revision, and all four are bumped in lockstep with native code, so an unattended bump produces a red pull request rather than a useful one — #632 spent a cycle on exactly that failure mode. Ignoring them leaveslottie-ios,CodeScannerandswift-secp256k1updating automatically, which is the subset where an automated bump is worth reviewing. The ignore rules use globs rather than exact names because the Swift ecosystem is inconsistent about whether a dependency is identified by its bare name or its full repository URL, and an exact match that misses fails silently.No app code is touched, so there is no changelog fragment.
Linked Issues/Tasks
.xcodeprojmanifests: https://github.blog/changelog/2026-03-31-dependabot-now-supports-xcode-projects-using-swiftpm-with-xcodeproj-manifests/synonymdev/bitkit-android.github/dependabot.ymlScreenshot / Video
N/A — repository configuration only.
QA Notes
Manual Tests
lottie-ios,CodeScannerandswift-secp256k1are resolved from the Xcode-managed manifest.bitkit-core,ldk-node,vss-rust-client-ffiandpaykit-rsare skipped as ignored rather than proposed.directory: /on the swift entry withdirectories: ["/Bitkit.xcodeproj/project.xcworkspace/xcshareddata/swiftpm"]and re-run.test-push-server/package-lock.jsonand does not look at the repo root.github-actions-majorgroup, since every action here is pinned to a floating major tag;github-actions-minorproduces nothing.gh api --method PUTcommands above (or tick Settings → Advanced Security) →gh api repos/synonymdev/bitkit-ios/automated-security-fixes: returnsenabled: true,paused: false. Until this is done, advisories will not open pull requests.CHATWOOT_APIthat needs a Dependabot secret or an author guard, in a follow-up.Automated Checks
npx -y js-yaml .github/dependabot.ymlparses cleanly and yields all threeupdatesentries with the intended ecosystems, directories, groups and ignore rules.dependabot.ymlis annotated directly on the pull request, so the absence of a Dependabot annotation here is the check.