Skip to content

chore(deps): let renovate own the github-actions bumps - #108

Merged
GSTJ merged 1 commit into
mainfrom
chore/drop-dependabot
Jul 27, 2026
Merged

chore(deps): let renovate own the github-actions bumps#108
GSTJ merged 1 commit into
mainfrom
chore/drop-dependabot

Conversation

@GSTJ

@GSTJ GSTJ commented Jul 27, 2026

Copy link
Copy Markdown
Owner

renovate.json already extends github>GSTJ/magic, and that preset carries a matchManagers: ["github-actions"] rule grouping every action bump into one automerged PR. The dependabot.yml here declared the same ecosystem on the same directory, so both bots watched the same manifests.

Not theoretical — #107 was opened by Dependabot minutes ago to bump rharkor/caching-for-turbo, a bump Renovate was already going to make. Two bots, two PRs, two CI runs, one dependency.

Drops the Dependabot config and leaves Renovate as the single updater. Dependabot security alerts stay on; Renovate reads them and raises its own PRs.

Closing #107 alongside this.

Claude-Session: https://claude.ai/code/session_01Fe92vvdc4R3F4BDBFoLcw1

renovate.json already extends github>GSTJ/magic, and that preset carries a
matchManagers: ["github-actions"] rule which groups every action bump into
one automerged PR. The dependabot.yml here declared the same ecosystem on
the same directory, so both bots watched the same manifests.

That is not theoretical: #107 was opened by dependabot minutes ago to bump
rharkor/caching-for-turbo, a bump renovate was already going to make. Two
bots, two PRs, two CI runs, one dependency.

Drop the dependabot config and leave renovate as the single updater.
Dependabot security alerts stay on — renovate reads them.

Claude-Session: https://claude.ai/code/session_01Fe92vvdc4R3F4BDBFoLcw1
@GSTJ
GSTJ merged commit 4ef266b into main Jul 27, 2026
3 checks passed
@GSTJ
GSTJ deleted the chore/drop-dependabot branch July 27, 2026 21:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant