From 9b80971a39e8d250dcf147b1bd75ce026ca6ba45 Mon Sep 17 00:00:00 2001 From: Hugo van Kemenade <1324225+hugovk@users.noreply.github.com> Date: Mon, 28 Sep 2026 20:02:08 +0300 Subject: [PATCH 1/5] Run Dependabot independently on each branch --- .github/dependabot.yml | 95 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 95 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index dca3e12ec18270..95e8243d250a02 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -16,6 +16,101 @@ updates: # Cooldowns protect against supply chain attacks by avoiding the # highest-risk window immediately after new releases. default-days: 14 + + # Release branches: Dependabot only reads this file from the default + # branch, so each branch that should get its own actions bumps needs an + # entry here with `target-branch`. Add one when a new release branch is + # created, and remove when the branch reaches end-of-life. + - package-ecosystem: "github-actions" + target-branch: "3.15" + directory: "/" + schedule: + interval: "quarterly" + labels: + - "skip issue" + - "skip news" + groups: + actions: + patterns: + - "*" + cooldown: + default-days: 14 + + - package-ecosystem: "github-actions" + target-branch: "3.14" + directory: "/" + schedule: + interval: "quarterly" + labels: + - "skip issue" + - "skip news" + groups: + actions: + patterns: + - "*" + cooldown: + default-days: 14 + + - package-ecosystem: "github-actions" + target-branch: "3.13" + directory: "/" + schedule: + interval: "quarterly" + labels: + - "skip issue" + - "skip news" + groups: + actions: + patterns: + - "*" + cooldown: + default-days: 14 + + - package-ecosystem: "github-actions" + target-branch: "3.12" + directory: "/" + schedule: + interval: "quarterly" + labels: + - "skip issue" + - "skip news" + groups: + actions: + patterns: + - "*" + cooldown: + default-days: 14 + + - package-ecosystem: "github-actions" + target-branch: "3.11" + directory: "/" + schedule: + interval: "quarterly" + labels: + - "skip issue" + - "skip news" + groups: + actions: + patterns: + - "*" + cooldown: + default-days: 14 + + - package-ecosystem: "github-actions" + target-branch: "3.10" + directory: "/" + schedule: + interval: "quarterly" + labels: + - "skip issue" + - "skip news" + groups: + actions: + patterns: + - "*" + cooldown: + default-days: 14 + - package-ecosystem: "pip" directory: "/Tools/" schedule: From 857e76726f168164e52a388cf03c8c797b69b634 Mon Sep 17 00:00:00 2001 From: Hugo van Kemenade <1324225+hugovk@users.noreply.github.com> Date: Tue, 29 Sep 2026 10:14:51 +0300 Subject: [PATCH 2/5] Compact Co-authored-by: Ezio Melotti --- .github/dependabot.yml | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 95e8243d250a02..2649e127e6d5be 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -26,13 +26,10 @@ updates: directory: "/" schedule: interval: "quarterly" - labels: - - "skip issue" - - "skip news" + labels: ["skip issue", "skip news"] groups: actions: - patterns: - - "*" + patterns: ["*"] cooldown: default-days: 14 From 04735ae781fc71e84f9edfa79f49299baf9b380a Mon Sep 17 00:00:00 2001 From: Hugo van Kemenade <1324225+hugovk@users.noreply.github.com> Date: Tue, 29 Sep 2026 10:17:18 +0300 Subject: [PATCH 3/5] Repeat for backport branches --- .github/dependabot.yml | 35 ++++++++++------------------------- 1 file changed, 10 insertions(+), 25 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 2649e127e6d5be..904788653be6eb 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -38,13 +38,10 @@ updates: directory: "/" schedule: interval: "quarterly" - labels: - - "skip issue" - - "skip news" + labels: ["skip issue", "skip news"] groups: actions: - patterns: - - "*" + patterns: ["*"] cooldown: default-days: 14 @@ -53,13 +50,10 @@ updates: directory: "/" schedule: interval: "quarterly" - labels: - - "skip issue" - - "skip news" + labels: ["skip issue", "skip news"] groups: actions: - patterns: - - "*" + patterns: ["*"] cooldown: default-days: 14 @@ -68,13 +62,10 @@ updates: directory: "/" schedule: interval: "quarterly" - labels: - - "skip issue" - - "skip news" + labels: ["skip issue", "skip news"] groups: actions: - patterns: - - "*" + patterns: ["*"] cooldown: default-days: 14 @@ -83,13 +74,10 @@ updates: directory: "/" schedule: interval: "quarterly" - labels: - - "skip issue" - - "skip news" + labels: ["skip issue", "skip news"] groups: actions: - patterns: - - "*" + patterns: ["*"] cooldown: default-days: 14 @@ -98,13 +86,10 @@ updates: directory: "/" schedule: interval: "quarterly" - labels: - - "skip issue" - - "skip news" + labels: ["skip issue", "skip news"] groups: actions: - patterns: - - "*" + patterns: ["*"] cooldown: default-days: 14 From 8fb84968bdc228d070677c8c33fda5ca936fdb19 Mon Sep 17 00:00:00 2001 From: Hugo van Kemenade <1324225+hugovk@users.noreply.github.com> Date: Tue, 29 Sep 2026 10:21:24 +0300 Subject: [PATCH 4/5] Group pip updates into a single PR --- .github/dependabot.yml | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 904788653be6eb..6bb9aab6fd5fee 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -97,8 +97,9 @@ updates: directory: "/Tools/" schedule: interval: "quarterly" - labels: - - "skip issue" - - "skip news" + labels: ["skip issue", "skip news"] + groups: + pip: + patterns: ["*"] cooldown: default-days: 14 From 11747cda13966e08d4f2aef6b5c306352e9ec05a Mon Sep 17 00:00:00 2001 From: Hugo van Kemenade <1324225+hugovk@users.noreply.github.com> Date: Tue, 29 Sep 2026 10:25:58 +0300 Subject: [PATCH 5/5] Do pip updates for bugfix branches --- .github/dependabot.yml | 38 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 6bb9aab6fd5fee..5f9e3c323e30b8 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -17,6 +17,17 @@ updates: # highest-risk window immediately after new releases. default-days: 14 + - package-ecosystem: "pip" + directory: "/Tools/" + schedule: + interval: "quarterly" + labels: ["skip issue", "skip news"] + groups: + pip: + patterns: ["*"] + cooldown: + default-days: 14 + # Release branches: Dependabot only reads this file from the default # branch, so each branch that should get its own actions bumps needs an # entry here with `target-branch`. Add one when a new release branch is @@ -93,7 +104,34 @@ updates: cooldown: default-days: 14 + # Only bump bugfix branches for pip. Remove + # the entry when branch goes security-only. + - package-ecosystem: "pip" + target-branch: "3.15" + directory: "/Tools/" + schedule: + interval: "quarterly" + labels: ["skip issue", "skip news"] + groups: + pip: + patterns: ["*"] + cooldown: + default-days: 14 + + - package-ecosystem: "pip" + target-branch: "3.14" + directory: "/Tools/" + schedule: + interval: "quarterly" + labels: ["skip issue", "skip news"] + groups: + pip: + patterns: ["*"] + cooldown: + default-days: 14 + - package-ecosystem: "pip" + target-branch: "3.13" directory: "/Tools/" schedule: interval: "quarterly"