dependabot-config
Installation
SKILL.md
Dependabot config
A Dependabot config is read far more often than it is written, and it is read when something is wrong — a flood of PRs on a Monday, or a package that never gets bumped. Write it so both questions are answerable from the file itself.
Two things carry most of the value: a plain weekly schedule, and groups that match how the packages actually release. Everything else is detail.
Non-negotiables
| Rule | Why |
|---|---|
interval: weekly |
Daily is noise. Weekly is the rhythm dependency review actually happens on. |
No day:, time: or timezone: unless asked for |
See below — they are defaults to leave alone, not keys to fill in. |
| Every ecosystem in the repo gets an entry | A config that covers npm but not github-actions silently rots the CI pipeline. |
| Nothing ungrouped that has a family | Ungrouped means one PR per package per week. |
version: 2 at the top |
v1 is long dead. |