ci: add Dependabot config for all demos + CI workflows#13
Merged
Conversation
Each demo README claimed "Dependabot bumps it on new releases" — but no dependabot.yml actually existed. This adds it. One Gradle ecosystem entry uses `directories:` (plural) to cover all nine demos in one block, sharing schedule/labels/commit-prefix and batching related bumps into grouped PRs: - easy-paging — every kr.devslab:easy-paging* artifact bump → one PR - ssrf-guard — same for the ssrf-guard module family - spring-boot — moves as a unit; never partial - test-tooling, database-drivers — batched to keep the queue tidy A second github-actions entry watches the CI workflows themselves. Weekly Monday 09:00 KST cadence (matches my morning queue triage).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Each demo README in this repo says "Dependabot bumps it on new releases" — but there was no `dependabot.yml` actually backing that claim. This PR adds it.
What it watches
Gradle (single ecosystem entry, `directories:` plural — covers all 9 demos):
GitHub Actions workflows in `.github/workflows/`.
Grouping strategy
Related bumps get collapsed into single PRs so the queue stays manageable as demos grow:
Schedule
Weekly, Monday 09:00 KST. PR cap of 10 open at once.
Verification
This is a config-only change, no code or build script touched. CI `detect` job should identify zero demos changed (`.github/dependabot.yml` doesn't match any `*-demo/` path), build job correctly skipped — that mirrors what PR #3 looked like.
Test plan