Skip to content

Enable dependabot updates#273

Merged
szegedi merged 3 commits intomainfrom
enable-dependabot
Feb 17, 2026
Merged

Enable dependabot updates#273
szegedi merged 3 commits intomainfrom
enable-dependabot

Conversation

@szegedi
Copy link

@szegedi szegedi commented Feb 16, 2026

What does this PR do?:
Enable Dependabot for updates.

Motivation:
We'd prefer to use Dependabot instead of campaignbot.

Additional Notes:
This is based on very little exploration of the docs. It might need to be refined over time.

Jira: PROF-13759

@szegedi szegedi added the semver-patch Bug or security fixes, mainly label Feb 16, 2026
@github-actions
Copy link

github-actions bot commented Feb 16, 2026

Overall package size

Self size: 1.77 MB
Deduped: 2.14 MB
No deduping: 2.14 MB

Dependency sizes | name | version | self size | total size | |------|---------|-----------|------------| | source-map | 0.7.6 | 185.63 kB | 185.63 kB | | pprof-format | 2.2.1 | 163.06 kB | 163.06 kB | | p-limit | 3.1.0 | 7.75 kB | 13.78 kB | | node-gyp-build | 3.9.0 | 8.81 kB | 8.81 kB |

🤖 This report was automatically generated by heaviest-objects-in-the-universe

@pr-commenter
Copy link

pr-commenter bot commented Feb 16, 2026

Benchmarks

Benchmark execution time: 2026-02-17 11:44:58

Comparing candidate commit 986ee7e in PR branch enable-dependabot with baseline commit e7bcdef in branch main.

Found 0 performance improvements and 0 performance regressions! Performance is the same for 91 metrics, 29 unstable metrics.

nsavoire
nsavoire previously approved these changes Feb 17, 2026
directory: "/"
# Check the npm registry for updates every day (weekdays)
schedule:
interval: "daily"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This could create a lot of noise, why not weekly?
Also, I think that we should ignore the internal dependency pprof-format

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

that all makes sense, will update

szegedi and others added 3 commits February 17, 2026 12:40
- weekly checks
- ignore pprof-format
- add "dependabot" and "semver-patch" labels
@szegedi
Copy link
Author

szegedi commented Feb 17, 2026

Alright, updated it to weekly, added pprof-format to exclusions, and customized the labels so we don't have to manually add semver-patch.

@szegedi szegedi requested a review from IlyasShabi February 17, 2026 11:48
Copy link

@IlyasShabi IlyasShabi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@szegedi szegedi merged commit b3844dd into main Feb 17, 2026
68 checks passed
@szegedi szegedi deleted the enable-dependabot branch February 17, 2026 16:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

semver-patch Bug or security fixes, mainly

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants