Run Dependabot updates weekly and group CodeQL updates#1748
Conversation
We now review dependency updates weekly rather than daily, so daily update runs only generate churn. Check for updates once a week on Monday morning instead. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Dependabot treats the github/codeql-action subpath actions (init, analyze, autobuild) as separate dependencies and opens a separate PR for each. CI fails unless they are all updated together. Group them so that they arrive as a single PR. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Warning Review limit reached
Next review available in: 58 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
Updates Dependabot configuration to reduce update noise by moving from daily to weekly dependency PRs, and to avoid CI breakage by grouping CodeQL action updates that must land together.
Changes:
- Switched the npm Dependabot schedule from daily to weekly on Mondays.
- Switched the GitHub Actions Dependabot schedule from daily to weekly on Mondays.
- Added a Dependabot group to bundle
github/codeql-actionsubpath updates into a single PR.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| schedule: | ||
| interval: daily | ||
| interval: weekly | ||
| day: monday | ||
| time: '14:00' |
| schedule: | ||
| interval: daily | ||
| interval: weekly | ||
| day: monday | ||
| time: '14:00' |
| codeql: | ||
| patterns: | ||
| - github/codeql-action* |
We now review dependency updates weekly rather than daily, so switch every Dependabot update schedule to weekly on Monday mornings.
Also group the github/codeql-action subpath actions (init, analyze, autobuild): Dependabot treats them as separate dependencies and opens a separate PR for each, but CI fails unless they are all updated together. Grouping them makes the updates arrive as a single PR.
🤖 Generated with Claude Code