mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-10-03 16:02:12 +00:00
* chore(dependabot): grouped weekly updates for all shipped manifests
Until now only /frontend, /backend, /, and /python-client/wmill had
Dependabot version-update jobs; the other shipped manifests only ever
produced security alerts and never fix PRs. Frontend and backend also
received one PR per dependency.
Added (weekly, one group each with patterns ["*"]):
- /cli package-ecosystem "bun" (text bun.lock;
GA, enable-beta-ecosystems not needed)
- /windmill-yaml-validator npm (package-lock.json)
- /typescript-client npm (package-lock.json, devDependencies only)
- /multiplayer npm (package-lock.json)
Grouping of existing jobs:
- /frontend: frontend-deps (minor + patch) and frontend-majors (major),
so routine bumps land in one PR and majors can be reviewed on their
own without blocking it.
- /backend: cargo-deps (minor + patch); majors stay as individual PRs
because they usually need code changes.
open-pull-requests-limit is left at its default (5): with grouping each
manifest yields at most one or two PRs per run, so no override is needed.
Deliberately not covered:
- /rust-client: Cargo.toml is generated and gitignored
- /backend/parsers/windmill-parser-wasm: excluded from the cargo
workspace, needs nightly cargo
- /benchmarks/pulumi: being deleted in another PR
- /integration_tests: CI-only
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* chore: group dependabot security updates per manifest
---------
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
112 lines
3.1 KiB
YAML
112 lines
3.1 KiB
YAML
# Weekly, grouped version updates for every shipped manifest, plus one grouped
|
|
# security-update PR per manifest. Security-update PRs have no open-PR limit, so
|
|
# without an `applies-to: security-updates` group each alert would get its own PR.
|
|
# Bun has no security updates: /cli alerts are fixed through its version group.
|
|
#
|
|
# Deliberately NOT covered here:
|
|
# - /rust-client: Cargo.toml is generated and gitignored
|
|
# - /backend/parsers/windmill-parser-wasm: excluded from the workspace, needs nightly cargo
|
|
# - /benchmarks/pulumi: one-off load-test infrastructure, not shipped
|
|
# - /integration_tests: CI-only
|
|
|
|
version: 2
|
|
updates:
|
|
# Maintain dependencies for GitHub Actions
|
|
- package-ecosystem: "github-actions"
|
|
directory: "/"
|
|
schedule:
|
|
interval: "weekly"
|
|
|
|
# Maintain dependencies for npm
|
|
- package-ecosystem: "npm"
|
|
directory: "/frontend"
|
|
schedule:
|
|
interval: "weekly"
|
|
groups:
|
|
# minor + patch bumps in one PR; majors in their own PR so they can be
|
|
# reviewed separately without blocking the routine bumps
|
|
frontend-deps:
|
|
patterns: ["*"]
|
|
update-types: ["minor", "patch"]
|
|
frontend-majors:
|
|
patterns: ["*"]
|
|
update-types: ["major"]
|
|
frontend-security:
|
|
applies-to: security-updates
|
|
patterns: ["*"]
|
|
|
|
# Maintain dependencies for cargo
|
|
- package-ecosystem: "cargo"
|
|
directory: "/backend"
|
|
schedule:
|
|
interval: "weekly"
|
|
groups:
|
|
# majors stay as individual PRs: they usually need code changes
|
|
cargo-deps:
|
|
patterns: ["*"]
|
|
update-types: ["minor", "patch"]
|
|
cargo-security:
|
|
applies-to: security-updates
|
|
patterns: ["*"]
|
|
|
|
# Maintain dependencies for Docker
|
|
- package-ecosystem: "docker"
|
|
directory: "/"
|
|
schedule:
|
|
interval: "weekly"
|
|
|
|
# Maintain dependencies for wmill python client
|
|
- package-ecosystem: "pip"
|
|
directory: "/python-client/wmill"
|
|
schedule:
|
|
interval: "weekly"
|
|
groups:
|
|
python-client-security:
|
|
applies-to: security-updates
|
|
patterns: ["*"]
|
|
|
|
# Maintain dependencies for the CLI (bun.lock)
|
|
- package-ecosystem: "bun"
|
|
directory: "/cli"
|
|
schedule:
|
|
interval: "weekly"
|
|
groups:
|
|
cli-deps:
|
|
patterns: ["*"]
|
|
|
|
# Maintain dependencies for the YAML validator
|
|
- package-ecosystem: "npm"
|
|
directory: "/windmill-yaml-validator"
|
|
schedule:
|
|
interval: "weekly"
|
|
groups:
|
|
yaml-validator-deps:
|
|
patterns: ["*"]
|
|
yaml-validator-security:
|
|
applies-to: security-updates
|
|
patterns: ["*"]
|
|
|
|
# Maintain dependencies for the TypeScript client (devDependencies only)
|
|
- package-ecosystem: "npm"
|
|
directory: "/typescript-client"
|
|
schedule:
|
|
interval: "weekly"
|
|
groups:
|
|
typescript-client-deps:
|
|
patterns: ["*"]
|
|
typescript-client-security:
|
|
applies-to: security-updates
|
|
patterns: ["*"]
|
|
|
|
# Maintain dependencies for multiplayer
|
|
- package-ecosystem: "npm"
|
|
directory: "/multiplayer"
|
|
schedule:
|
|
interval: "weekly"
|
|
groups:
|
|
multiplayer-deps:
|
|
patterns: ["*"]
|
|
multiplayer-security:
|
|
applies-to: security-updates
|
|
patterns: ["*"]
|