Skip to content

Group Dependabot non-major NuGet updates - #1093

Open
MartinHock wants to merge 2 commits into
ardalis:mainfrom
MartinHock:fix/dependabot-group-non-major
Open

MartinHock wants to merge 2 commits into
ardalis:mainfrom
MartinHock:fix/dependabot-group-non-major

Conversation

@MartinHock

@MartinHock MartinHock commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Group non-major Dependabot NuGet updates into logical categories.
  • Keep Microsoft packages together, while routing Microsoft.NET.Test.Sdk to the test-tooling group.
  • Group test-related packages such as xUnit, NUnit, coverlet, and FluentAssertions.
  • Group all remaining non-major NuGet updates separately.
  • Leave major updates ungrouped so they continue to be reviewed individually.

Rationale

This reduces Dependabot PR noise while keeping updates easy to review by dependency area. The groups are mutually exclusive, so packages are not matched by more than one group.

Scope

This PR changes the Dependabot configuration and adds .github/dependabot.yml to the existing cross-platform workflow path filters. This is necessary because the main ruleset requires the Windows, Linux, and macOS build checks, but those checks were previously skipped for Dependabot-only changes, leaving such PRs permanently blocked.

Validation completed in my fork using the exact Dependabot configuration from this PR.

A manual Dependabot update run completed successfully and created grouped NuGet PRs:

Both PRs were created by dependabot[bot] from the commit containing this configuration.

No test-packages PR was created because there were no matching pending test-package updates in this run.

@MartinHock

Copy link
Copy Markdown
Contributor Author

The three CI checks are currently failing during dotnet restore, unrelated to the Dependabot grouping changes.

The current main branch still uses Testcontainers 4.13.0, which pulls in the vulnerable SSH.NET 2025.1.0. With warnings treated as errors this results in NU1903 on Windows, Ubuntu, and macOS.

PR #1081 updates Testcontainers and Testcontainers.MsSql to 4.14.0 and addresses this vulnerability. Once #1081 is merged and this branch is updated from main, the CI checks should be able to proceed past restore.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant