chore: add dependabot config for automated PRs - #655

Merged
jvsena42 merged 2 commits into
masterfrom
chore/dependabot-automated-prs
Aug 5, 2026
Merged

chore: add dependabot config for automated PRs#655
jvsena42 merged 2 commits into
masterfrom
chore/dependabot-automated-prs

Conversation

@jvsena42

@jvsena42jvsena42 commented Aug 5, 2026

Copy link
Copy Markdown
Member

Description

This PR:

  1. Adds a dependabot.yml covering the three package ecosystems this repo actually has — the test-push-server npm tree, the workflow actions, and the Xcode-managed Package.resolved
  2. Groups each ecosystem into a single monthly PR to keep the CI cost of automated updates bounded
  3. Excludes the Synonym-owned FFI packages, which cannot be bumped unattended

The repo has had Dependabot alerts enabled for a long time but has never had a Dependabot pull request — there is no config file, so nothing was ever proposed. All 30 historical alerts are closed as fixed because they were cleaned up by hand, most recently in #651. This is the piece that stops that from being manual work.

One thing this does not do on its own, and it is the important caveat: a config file only turns on version updates. Turning an advisory into a pull request is a separate repo setting, and it needs admin on the repo. Merging this alone will not make alerts arrive as pull requests. The two halves are complementary: version updates keep dependencies current so advisories land less often, security updates handle the ones that land anyway.

Admin steps to finish enabling this

Either tick Settings → Advanced Security → Dependabot security updates, or run the equivalent from the CLI. Both endpoints require admin on the repository and return 204 No Content on success:

# Dependabot alerts — already on here, but idempotent and safe to re-run
gh api --method PUT repos/synonymdev/bitkit-ios/vulnerability-alerts
# Dependabot security updates — this is the one that turns an alert into a pull request
gh api --method PUT repos/synonymdev/bitkit-ios/automated-security-fixes

Verify afterwards:

# expect {"enabled": true, "paused": false}
gh api repos/synonymdev/bitkit-ios/automated-security-fixes
# expect HTTP/2.0 204 — a 404 means either disabled or the caller is not an admin
gh api repos/synonymdev/bitkit-ios/vulnerability-alerts --include | head -1

The dependency graph needs no action: it is on by default for public repositories and cannot be turned off.

Swift is included because it only recently became possible. Dependabot required a top-level Package.swift until 31 March 2026, when it gained the ability to discover Package.resolved nested inside .xcodeproj and .xcworkspace bundles and to read version rules out of project.pbxproj. That is exactly this repo's layout, so the ecosystem is supported here for the first time. It is also the least proven part of the change, which is why the QA notes below include a fallback to an explicit directories: path if the resolver does not find the manifest.

Grouping is the cost control rather than a tidiness preference. Unit tests and integration tests run on every pull request with no path filter, both on macos-15 with hour-long timeouts, and the e2e suite fires on anything touching Bitkit.xcodeproj/** or its own workflow file — which a Swift bump and an actions bump respectively do. Ungrouped, a month with six updates is six full CI runs. Grouping holds it to a handful.

Majors are kept out of the routine batches, but how that is expressed differs by ecosystem. For npm and swift the groups take minor and patch only, so a major bump falls through to its own pull request. Actions are a different case: every one of them is pinned to a floating major tag (actions/checkout@v6, upload-artifact@v7, and so on), so every update Dependabot can propose for them is a major one. Restricting that group the same way would mean it never fires and each action arrives as its own pull request with its own full CI run. Instead the actions entry has two groups, minor/patch and major, both matching everything — a dependency lands in the first group it matches, so major action bumps get a dedicated pull request separate from routine updates without fanning out into eight of them.

The four ignored packages are bitkit-core, ldk-node, vss-rust-client-ffi and paykit-rs. Two are on release candidates, one is pinned to a branch revision, and all four are bumped in lockstep with native code, so an unattended bump produces a red pull request rather than a useful one — #632 spent a cycle on exactly that failure mode. Ignoring them leaves lottie-ios, CodeScanner and swift-secp256k1 updating automatically, which is the subset where an automated bump is worth reviewing. The ignore rules use globs rather than exact names because the Swift ecosystem is inconsistent about whether a dependency is identified by its bare name or its full repository URL, and an exact match that misses fails silently.

No app code is touched, so there is no changelog fragment.

Linked Issues/Tasks

Screenshot / Video

N/A — repository configuration only.

QA Notes

Manual Tests

Dependabot reads dependabot.yml from the default branch only, so none of these can run until this merges. Each row in the Dependabot tab has a Check for updates button that forces a run without waiting for the monthly schedule.

  • 1. Insights → Dependency graph → Dependabot: three rows listed (npm, GitHub Actions, Swift), each with a Last checked timestamp and no config error banner.
  • 2a. Dependabot tab → Swift row → Check for updates → open the job log: lottie-ios, CodeScanner and swift-secp256k1 are resolved from the Xcode-managed manifest.
    • 2b. Same log: bitkit-core, ldk-node, vss-rust-client-ffi and paykit-rs are skipped as ignored rather than proposed.
    • 2c. If the log reports no manifest found, replace directory: / on the swift entry with directories: ["/Bitkit.xcodeproj/project.xcworkspace/xcshareddata/swiftpm"] and re-run.
  • 3. Dependabot tab → npm row → Check for updates: resolves test-push-server/package-lock.json and does not look at the repo root.
  • 4a. Dependabot tab → GitHub Actions row → Check for updates: proposes one grouped pull request rather than one per action.
    • 4b. That pull request is the github-actions-major group, since every action here is pinned to a floating major tag; github-actions-minor produces nothing.
  • 5. Repo admin → run the two gh api --method PUT commands above (or tick Settings → Advanced Security) → gh api repos/synonymdev/bitkit-ios/automated-security-fixes: returns enabled: true, paused: false. Until this is done, advisories will not open pull requests.
  • 6. First grouped pull request Dependabot opens → unit-tests and integration-tests: both green. Dependabot pull requests run with a read-only token and no repository secrets, so if the e2e suite fails for want of CHATWOOT_API that needs a Dependabot secret or an author guard, in a follow-up.

Automated Checks

  • No Swift or app code changed, so no test coverage was added, modified or removed.
  • npx -y js-yaml .github/dependabot.yml parses cleanly and yields all three updates entries with the intended ecosystems, directories, groups and ignore rules.
  • Schema validity is enforced by GitHub rather than locally: an invalid dependabot.yml is annotated directly on the pull request, so the absence of a Dependabot annotation here is the check.
  • Ecosystem resolution and grouping behaviour can only be observed once the config is on the default branch (after merge); that is what the manual steps above cover.
  • CI: standard checks run by the PR bot.

@greptile-apps

Copy link
Copy Markdown

Greptile Summary

The PR adds monthly Dependabot version-update configuration for the repository’s npm, GitHub Actions, and Xcode-managed Swift dependencies.

  • Groups routine dependency updates by ecosystem to limit CI usage.
  • Excludes four native Swift dependencies that require coordinated manual upgrades.
  • Configures ecosystem-specific commit prefixes and pull-request limits.

Confidence Score: 4/5

The GitHub Actions grouping configuration should be fixed before merging because it bundles major action upgrades that the PR intends to isolate for review.

The catch-all GitHub Actions group lacks the minor/patch filter present on the npm and Swift groups, so major action upgrades enter the grouped monthly pull request.

Files Needing Attention: .github/dependabot.yml

Important Files Changed

FilenameOverview
.github/dependabot.ymlAdds the three intended Dependabot ecosystems, but the GitHub Actions group unintentionally includes major updates despite the stated standalone-review policy.

Reviews (1): Last reviewed commit: "chore: add dependabot config" | Re-trigger Greptile

Comment thread.github/dependabot.yml
@jvsena42jvsena42 self-assigned this Aug 5, 2026

@ovitrifovitrif left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Dependabot config matches the repo: npm under test-push-server, Actions at root with major/minor groups for floating tags, and Swift ignores for the Synonym FFI packages that need coordinated bumps.

@jvsena42
jvsena42 merged commit 6791e8d into masterAug 5, 2026
11 checks passed
@jvsena42
jvsena42 deleted the chore/dependabot-automated-prs branch August 5, 2026 18:59
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jvsena42@ovitrif
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore: add dependabot config for automated PRs - #655

Merged
jvsena42 merged 2 commits into
masterfrom
chore/dependabot-automated-prs
Aug 5, 2026
Merged

chore: add dependabot config for automated PRs#655
jvsena42 merged 2 commits into
masterfrom
chore/dependabot-automated-prs

Conversation

@jvsena42

@jvsena42jvsena42 commented Aug 5, 2026

Copy link
Copy Markdown
Member

Description

This PR:

  1. Adds a dependabot.yml covering the three package ecosystems this repo actually has — the test-push-server npm tree, the workflow actions, and the Xcode-managed Package.resolved
  2. Groups each ecosystem into a single monthly PR to keep the CI cost of automated updates bounded
  3. Excludes the Synonym-owned FFI packages, which cannot be bumped unattended

The repo has had Dependabot alerts enabled for a long time but has never had a Dependabot pull request — there is no config file, so nothing was ever proposed. All 30 historical alerts are closed as fixed because they were cleaned up by hand, most recently in #651. This is the piece that stops that from being manual work.

One thing this does not do on its own, and it is the important caveat: a config file only turns on version updates. Turning an advisory into a pull request is a separate repo setting, and it needs admin on the repo. Merging this alone will not make alerts arrive as pull requests. The two halves are complementary: version updates keep dependencies current so advisories land less often, security updates handle the ones that land anyway.

Admin steps to finish enabling this

Either tick Settings → Advanced Security → Dependabot security updates, or run the equivalent from the CLI. Both endpoints require admin on the repository and return 204 No Content on success:

# Dependabot alerts — already on here, but idempotent and safe to re-run
gh api --method PUT repos/synonymdev/bitkit-ios/vulnerability-alerts
# Dependabot security updates — this is the one that turns an alert into a pull request
gh api --method PUT repos/synonymdev/bitkit-ios/automated-security-fixes

Verify afterwards:

# expect {"enabled": true, "paused": false}
gh api repos/synonymdev/bitkit-ios/automated-security-fixes
# expect HTTP/2.0 204 — a 404 means either disabled or the caller is not an admin
gh api repos/synonymdev/bitkit-ios/vulnerability-alerts --include | head -1

The dependency graph needs no action: it is on by default for public repositories and cannot be turned off.

Swift is included because it only recently became possible. Dependabot required a top-level Package.swift until 31 March 2026, when it gained the ability to discover Package.resolved nested inside .xcodeproj and .xcworkspace bundles and to read version rules out of project.pbxproj. That is exactly this repo's layout, so the ecosystem is supported here for the first time. It is also the least proven part of the change, which is why the QA notes below include a fallback to an explicit directories: path if the resolver does not find the manifest.

Grouping is the cost control rather than a tidiness preference. Unit tests and integration tests run on every pull request with no path filter, both on macos-15 with hour-long timeouts, and the e2e suite fires on anything touching Bitkit.xcodeproj/** or its own workflow file — which a Swift bump and an actions bump respectively do. Ungrouped, a month with six updates is six full CI runs. Grouping holds it to a handful.

Majors are kept out of the routine batches, but how that is expressed differs by ecosystem. For npm and swift the groups take minor and patch only, so a major bump falls through to its own pull request. Actions are a different case: every one of them is pinned to a floating major tag (actions/checkout@v6, upload-artifact@v7, and so on), so every update Dependabot can propose for them is a major one. Restricting that group the same way would mean it never fires and each action arrives as its own pull request with its own full CI run. Instead the actions entry has two groups, minor/patch and major, both matching everything — a dependency lands in the first group it matches, so major action bumps get a dedicated pull request separate from routine updates without fanning out into eight of them.

The four ignored packages are bitkit-core, ldk-node, vss-rust-client-ffi and paykit-rs. Two are on release candidates, one is pinned to a branch revision, and all four are bumped in lockstep with native code, so an unattended bump produces a red pull request rather than a useful one — #632 spent a cycle on exactly that failure mode. Ignoring them leaves lottie-ios, CodeScanner and swift-secp256k1 updating automatically, which is the subset where an automated bump is worth reviewing. The ignore rules use globs rather than exact names because the Swift ecosystem is inconsistent about whether a dependency is identified by its bare name or its full repository URL, and an exact match that misses fails silently.

No app code is touched, so there is no changelog fragment.

Linked Issues/Tasks

Screenshot / Video

N/A — repository configuration only.

QA Notes

Manual Tests

Dependabot reads dependabot.yml from the default branch only, so none of these can run until this merges. Each row in the Dependabot tab has a Check for updates button that forces a run without waiting for the monthly schedule.

  • 1. Insights → Dependency graph → Dependabot: three rows listed (npm, GitHub Actions, Swift), each with a Last checked timestamp and no config error banner.
  • 2a. Dependabot tab → Swift row → Check for updates → open the job log: lottie-ios, CodeScanner and swift-secp256k1 are resolved from the Xcode-managed manifest.
    • 2b. Same log: bitkit-core, ldk-node, vss-rust-client-ffi and paykit-rs are skipped as ignored rather than proposed.
    • 2c. If the log reports no manifest found, replace directory: / on the swift entry with directories: ["/Bitkit.xcodeproj/project.xcworkspace/xcshareddata/swiftpm"] and re-run.
  • 3. Dependabot tab → npm row → Check for updates: resolves test-push-server/package-lock.json and does not look at the repo root.
  • 4a. Dependabot tab → GitHub Actions row → Check for updates: proposes one grouped pull request rather than one per action.
    • 4b. That pull request is the github-actions-major group, since every action here is pinned to a floating major tag; github-actions-minor produces nothing.
  • 5. Repo admin → run the two gh api --method PUT commands above (or tick Settings → Advanced Security) → gh api repos/synonymdev/bitkit-ios/automated-security-fixes: returns enabled: true, paused: false. Until this is done, advisories will not open pull requests.
  • 6. First grouped pull request Dependabot opens → unit-tests and integration-tests: both green. Dependabot pull requests run with a read-only token and no repository secrets, so if the e2e suite fails for want of CHATWOOT_API that needs a Dependabot secret or an author guard, in a follow-up.

Automated Checks

  • No Swift or app code changed, so no test coverage was added, modified or removed.
  • npx -y js-yaml .github/dependabot.yml parses cleanly and yields all three updates entries with the intended ecosystems, directories, groups and ignore rules.
  • Schema validity is enforced by GitHub rather than locally: an invalid dependabot.yml is annotated directly on the pull request, so the absence of a Dependabot annotation here is the check.
  • Ecosystem resolution and grouping behaviour can only be observed once the config is on the default branch (after merge); that is what the manual steps above cover.
  • CI: standard checks run by the PR bot.

@greptile-apps

Copy link
Copy Markdown

Greptile Summary

The PR adds monthly Dependabot version-update configuration for the repository’s npm, GitHub Actions, and Xcode-managed Swift dependencies.

  • Groups routine dependency updates by ecosystem to limit CI usage.
  • Excludes four native Swift dependencies that require coordinated manual upgrades.
  • Configures ecosystem-specific commit prefixes and pull-request limits.

Confidence Score: 4/5

The GitHub Actions grouping configuration should be fixed before merging because it bundles major action upgrades that the PR intends to isolate for review.

The catch-all GitHub Actions group lacks the minor/patch filter present on the npm and Swift groups, so major action upgrades enter the grouped monthly pull request.

Files Needing Attention: .github/dependabot.yml

Important Files Changed

FilenameOverview
.github/dependabot.ymlAdds the three intended Dependabot ecosystems, but the GitHub Actions group unintentionally includes major updates despite the stated standalone-review policy.

Reviews (1): Last reviewed commit: "chore: add dependabot config" | Re-trigger Greptile

Comment thread.github/dependabot.yml
@jvsena42jvsena42 self-assigned this Aug 5, 2026

@ovitrifovitrif left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Dependabot config matches the repo: npm under test-push-server, Actions at root with major/minor groups for floating tags, and Swift ignores for the Synonym FFI packages that need coordinated bumps.

@jvsena42
jvsena42 merged commit 6791e8d into masterAug 5, 2026
11 checks passed
@jvsena42
jvsena42 deleted the chore/dependabot-automated-prs branch August 5, 2026 18:59
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jvsena42@ovitrif
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: add dependabot config for automated PRs - #655

Merged
jvsena42 merged 2 commits into
masterfrom
chore/dependabot-automated-prs
Aug 5, 2026
Merged

chore: add dependabot config for automated PRs#655
jvsena42 merged 2 commits into
masterfrom
chore/dependabot-automated-prs

Conversation

@jvsena42

@jvsena42jvsena42 commented Aug 5, 2026

Copy link
Copy Markdown
Member

Description

This PR:

  1. Adds a dependabot.yml covering the three package ecosystems this repo actually has — the test-push-server npm tree, the workflow actions, and the Xcode-managed Package.resolved
  2. Groups each ecosystem into a single monthly PR to keep the CI cost of automated updates bounded
  3. Excludes the Synonym-owned FFI packages, which cannot be bumped unattended

The repo has had Dependabot alerts enabled for a long time but has never had a Dependabot pull request — there is no config file, so nothing was ever proposed. All 30 historical alerts are closed as fixed because they were cleaned up by hand, most recently in #651. This is the piece that stops that from being manual work.

One thing this does not do on its own, and it is the important caveat: a config file only turns on version updates. Turning an advisory into a pull request is a separate repo setting, and it needs admin on the repo. Merging this alone will not make alerts arrive as pull requests. The two halves are complementary: version updates keep dependencies current so advisories land less often, security updates handle the ones that land anyway.

Admin steps to finish enabling this

Either tick Settings → Advanced Security → Dependabot security updates, or run the equivalent from the CLI. Both endpoints require admin on the repository and return 204 No Content on success:

# Dependabot alerts — already on here, but idempotent and safe to re-run
gh api --method PUT repos/synonymdev/bitkit-ios/vulnerability-alerts
# Dependabot security updates — this is the one that turns an alert into a pull request
gh api --method PUT repos/synonymdev/bitkit-ios/automated-security-fixes

Verify afterwards:

# expect {"enabled": true, "paused": false}
gh api repos/synonymdev/bitkit-ios/automated-security-fixes
# expect HTTP/2.0 204 — a 404 means either disabled or the caller is not an admin
gh api repos/synonymdev/bitkit-ios/vulnerability-alerts --include | head -1

The dependency graph needs no action: it is on by default for public repositories and cannot be turned off.

Swift is included because it only recently became possible. Dependabot required a top-level Package.swift until 31 March 2026, when it gained the ability to discover Package.resolved nested inside .xcodeproj and .xcworkspace bundles and to read version rules out of project.pbxproj. That is exactly this repo's layout, so the ecosystem is supported here for the first time. It is also the least proven part of the change, which is why the QA notes below include a fallback to an explicit directories: path if the resolver does not find the manifest.

Grouping is the cost control rather than a tidiness preference. Unit tests and integration tests run on every pull request with no path filter, both on macos-15 with hour-long timeouts, and the e2e suite fires on anything touching Bitkit.xcodeproj/** or its own workflow file — which a Swift bump and an actions bump respectively do. Ungrouped, a month with six updates is six full CI runs. Grouping holds it to a handful.

Majors are kept out of the routine batches, but how that is expressed differs by ecosystem. For npm and swift the groups take minor and patch only, so a major bump falls through to its own pull request. Actions are a different case: every one of them is pinned to a floating major tag (actions/checkout@v6, upload-artifact@v7, and so on), so every update Dependabot can propose for them is a major one. Restricting that group the same way would mean it never fires and each action arrives as its own pull request with its own full CI run. Instead the actions entry has two groups, minor/patch and major, both matching everything — a dependency lands in the first group it matches, so major action bumps get a dedicated pull request separate from routine updates without fanning out into eight of them.

The four ignored packages are bitkit-core, ldk-node, vss-rust-client-ffi and paykit-rs. Two are on release candidates, one is pinned to a branch revision, and all four are bumped in lockstep with native code, so an unattended bump produces a red pull request rather than a useful one — #632 spent a cycle on exactly that failure mode. Ignoring them leaves lottie-ios, CodeScanner and swift-secp256k1 updating automatically, which is the subset where an automated bump is worth reviewing. The ignore rules use globs rather than exact names because the Swift ecosystem is inconsistent about whether a dependency is identified by its bare name or its full repository URL, and an exact match that misses fails silently.

No app code is touched, so there is no changelog fragment.

Linked Issues/Tasks

Screenshot / Video

N/A — repository configuration only.

QA Notes

Manual Tests

Dependabot reads dependabot.yml from the default branch only, so none of these can run until this merges. Each row in the Dependabot tab has a Check for updates button that forces a run without waiting for the monthly schedule.

  • 1. Insights → Dependency graph → Dependabot: three rows listed (npm, GitHub Actions, Swift), each with a Last checked timestamp and no config error banner.
  • 2a. Dependabot tab → Swift row → Check for updates → open the job log: lottie-ios, CodeScanner and swift-secp256k1 are resolved from the Xcode-managed manifest.
    • 2b. Same log: bitkit-core, ldk-node, vss-rust-client-ffi and paykit-rs are skipped as ignored rather than proposed.
    • 2c. If the log reports no manifest found, replace directory: / on the swift entry with directories: ["/Bitkit.xcodeproj/project.xcworkspace/xcshareddata/swiftpm"] and re-run.
  • 3. Dependabot tab → npm row → Check for updates: resolves test-push-server/package-lock.json and does not look at the repo root.
  • 4a. Dependabot tab → GitHub Actions row → Check for updates: proposes one grouped pull request rather than one per action.
    • 4b. That pull request is the github-actions-major group, since every action here is pinned to a floating major tag; github-actions-minor produces nothing.
  • 5. Repo admin → run the two gh api --method PUT commands above (or tick Settings → Advanced Security) → gh api repos/synonymdev/bitkit-ios/automated-security-fixes: returns enabled: true, paused: false. Until this is done, advisories will not open pull requests.
  • 6. First grouped pull request Dependabot opens → unit-tests and integration-tests: both green. Dependabot pull requests run with a read-only token and no repository secrets, so if the e2e suite fails for want of CHATWOOT_API that needs a Dependabot secret or an author guard, in a follow-up.

Automated Checks

  • No Swift or app code changed, so no test coverage was added, modified or removed.
  • npx -y js-yaml .github/dependabot.yml parses cleanly and yields all three updates entries with the intended ecosystems, directories, groups and ignore rules.
  • Schema validity is enforced by GitHub rather than locally: an invalid dependabot.yml is annotated directly on the pull request, so the absence of a Dependabot annotation here is the check.
  • Ecosystem resolution and grouping behaviour can only be observed once the config is on the default branch (after merge); that is what the manual steps above cover.
  • CI: standard checks run by the PR bot.

@greptile-apps

Copy link
Copy Markdown

Greptile Summary

The PR adds monthly Dependabot version-update configuration for the repository’s npm, GitHub Actions, and Xcode-managed Swift dependencies.

  • Groups routine dependency updates by ecosystem to limit CI usage.
  • Excludes four native Swift dependencies that require coordinated manual upgrades.
  • Configures ecosystem-specific commit prefixes and pull-request limits.

Confidence Score: 4/5

The GitHub Actions grouping configuration should be fixed before merging because it bundles major action upgrades that the PR intends to isolate for review.

The catch-all GitHub Actions group lacks the minor/patch filter present on the npm and Swift groups, so major action upgrades enter the grouped monthly pull request.

Files Needing Attention: .github/dependabot.yml

Important Files Changed

FilenameOverview
.github/dependabot.ymlAdds the three intended Dependabot ecosystems, but the GitHub Actions group unintentionally includes major updates despite the stated standalone-review policy.

Reviews (1): Last reviewed commit: "chore: add dependabot config" | Re-trigger Greptile

Comment thread.github/dependabot.yml
@jvsena42jvsena42 self-assigned this Aug 5, 2026

@ovitrifovitrif left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Dependabot config matches the repo: npm under test-push-server, Actions at root with major/minor groups for floating tags, and Swift ignores for the Synonym FFI packages that need coordinated bumps.

@jvsena42
jvsena42 merged commit 6791e8d into masterAug 5, 2026
11 checks passed
@jvsena42
jvsena42 deleted the chore/dependabot-automated-prs branch August 5, 2026 18:59
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jvsena42@ovitrif
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: add dependabot config for automated PRs - #655

Merged
jvsena42 merged 2 commits into
masterfrom
chore/dependabot-automated-prs
Aug 5, 2026
Merged

chore: add dependabot config for automated PRs#655
jvsena42 merged 2 commits into
masterfrom
chore/dependabot-automated-prs

Conversation

@jvsena42

@jvsena42jvsena42 commented Aug 5, 2026

Copy link
Copy Markdown
Member

Description

This PR:

  1. Adds a dependabot.yml covering the three package ecosystems this repo actually has — the test-push-server npm tree, the workflow actions, and the Xcode-managed Package.resolved
  2. Groups each ecosystem into a single monthly PR to keep the CI cost of automated updates bounded
  3. Excludes the Synonym-owned FFI packages, which cannot be bumped unattended

The repo has had Dependabot alerts enabled for a long time but has never had a Dependabot pull request — there is no config file, so nothing was ever proposed. All 30 historical alerts are closed as fixed because they were cleaned up by hand, most recently in #651. This is the piece that stops that from being manual work.

One thing this does not do on its own, and it is the important caveat: a config file only turns on version updates. Turning an advisory into a pull request is a separate repo setting, and it needs admin on the repo. Merging this alone will not make alerts arrive as pull requests. The two halves are complementary: version updates keep dependencies current so advisories land less often, security updates handle the ones that land anyway.

Admin steps to finish enabling this

Either tick Settings → Advanced Security → Dependabot security updates, or run the equivalent from the CLI. Both endpoints require admin on the repository and return 204 No Content on success:

# Dependabot alerts — already on here, but idempotent and safe to re-run
gh api --method PUT repos/synonymdev/bitkit-ios/vulnerability-alerts
# Dependabot security updates — this is the one that turns an alert into a pull request
gh api --method PUT repos/synonymdev/bitkit-ios/automated-security-fixes

Verify afterwards:

# expect {"enabled": true, "paused": false}
gh api repos/synonymdev/bitkit-ios/automated-security-fixes
# expect HTTP/2.0 204 — a 404 means either disabled or the caller is not an admin
gh api repos/synonymdev/bitkit-ios/vulnerability-alerts --include | head -1

The dependency graph needs no action: it is on by default for public repositories and cannot be turned off.

Swift is included because it only recently became possible. Dependabot required a top-level Package.swift until 31 March 2026, when it gained the ability to discover Package.resolved nested inside .xcodeproj and .xcworkspace bundles and to read version rules out of project.pbxproj. That is exactly this repo's layout, so the ecosystem is supported here for the first time. It is also the least proven part of the change, which is why the QA notes below include a fallback to an explicit directories: path if the resolver does not find the manifest.

Grouping is the cost control rather than a tidiness preference. Unit tests and integration tests run on every pull request with no path filter, both on macos-15 with hour-long timeouts, and the e2e suite fires on anything touching Bitkit.xcodeproj/** or its own workflow file — which a Swift bump and an actions bump respectively do. Ungrouped, a month with six updates is six full CI runs. Grouping holds it to a handful.

Majors are kept out of the routine batches, but how that is expressed differs by ecosystem. For npm and swift the groups take minor and patch only, so a major bump falls through to its own pull request. Actions are a different case: every one of them is pinned to a floating major tag (actions/checkout@v6, upload-artifact@v7, and so on), so every update Dependabot can propose for them is a major one. Restricting that group the same way would mean it never fires and each action arrives as its own pull request with its own full CI run. Instead the actions entry has two groups, minor/patch and major, both matching everything — a dependency lands in the first group it matches, so major action bumps get a dedicated pull request separate from routine updates without fanning out into eight of them.

The four ignored packages are bitkit-core, ldk-node, vss-rust-client-ffi and paykit-rs. Two are on release candidates, one is pinned to a branch revision, and all four are bumped in lockstep with native code, so an unattended bump produces a red pull request rather than a useful one — #632 spent a cycle on exactly that failure mode. Ignoring them leaves lottie-ios, CodeScanner and swift-secp256k1 updating automatically, which is the subset where an automated bump is worth reviewing. The ignore rules use globs rather than exact names because the Swift ecosystem is inconsistent about whether a dependency is identified by its bare name or its full repository URL, and an exact match that misses fails silently.

No app code is touched, so there is no changelog fragment.

Linked Issues/Tasks

Screenshot / Video

N/A — repository configuration only.

QA Notes

Manual Tests

Dependabot reads dependabot.yml from the default branch only, so none of these can run until this merges. Each row in the Dependabot tab has a Check for updates button that forces a run without waiting for the monthly schedule.

  • 1. Insights → Dependency graph → Dependabot: three rows listed (npm, GitHub Actions, Swift), each with a Last checked timestamp and no config error banner.
  • 2a. Dependabot tab → Swift row → Check for updates → open the job log: lottie-ios, CodeScanner and swift-secp256k1 are resolved from the Xcode-managed manifest.
    • 2b. Same log: bitkit-core, ldk-node, vss-rust-client-ffi and paykit-rs are skipped as ignored rather than proposed.
    • 2c. If the log reports no manifest found, replace directory: / on the swift entry with directories: ["/Bitkit.xcodeproj/project.xcworkspace/xcshareddata/swiftpm"] and re-run.
  • 3. Dependabot tab → npm row → Check for updates: resolves test-push-server/package-lock.json and does not look at the repo root.
  • 4a. Dependabot tab → GitHub Actions row → Check for updates: proposes one grouped pull request rather than one per action.
    • 4b. That pull request is the github-actions-major group, since every action here is pinned to a floating major tag; github-actions-minor produces nothing.
  • 5. Repo admin → run the two gh api --method PUT commands above (or tick Settings → Advanced Security) → gh api repos/synonymdev/bitkit-ios/automated-security-fixes: returns enabled: true, paused: false. Until this is done, advisories will not open pull requests.
  • 6. First grouped pull request Dependabot opens → unit-tests and integration-tests: both green. Dependabot pull requests run with a read-only token and no repository secrets, so if the e2e suite fails for want of CHATWOOT_API that needs a Dependabot secret or an author guard, in a follow-up.

Automated Checks

  • No Swift or app code changed, so no test coverage was added, modified or removed.
  • npx -y js-yaml .github/dependabot.yml parses cleanly and yields all three updates entries with the intended ecosystems, directories, groups and ignore rules.
  • Schema validity is enforced by GitHub rather than locally: an invalid dependabot.yml is annotated directly on the pull request, so the absence of a Dependabot annotation here is the check.
  • Ecosystem resolution and grouping behaviour can only be observed once the config is on the default branch (after merge); that is what the manual steps above cover.
  • CI: standard checks run by the PR bot.

@greptile-apps

Copy link
Copy Markdown

Greptile Summary

The PR adds monthly Dependabot version-update configuration for the repository’s npm, GitHub Actions, and Xcode-managed Swift dependencies.

  • Groups routine dependency updates by ecosystem to limit CI usage.
  • Excludes four native Swift dependencies that require coordinated manual upgrades.
  • Configures ecosystem-specific commit prefixes and pull-request limits.

Confidence Score: 4/5

The GitHub Actions grouping configuration should be fixed before merging because it bundles major action upgrades that the PR intends to isolate for review.

The catch-all GitHub Actions group lacks the minor/patch filter present on the npm and Swift groups, so major action upgrades enter the grouped monthly pull request.

Files Needing Attention: .github/dependabot.yml

Important Files Changed

FilenameOverview
.github/dependabot.ymlAdds the three intended Dependabot ecosystems, but the GitHub Actions group unintentionally includes major updates despite the stated standalone-review policy.

Reviews (1): Last reviewed commit: "chore: add dependabot config" | Re-trigger Greptile

Comment thread.github/dependabot.yml
@jvsena42jvsena42 self-assigned this Aug 5, 2026

@ovitrifovitrif left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Dependabot config matches the repo: npm under test-push-server, Actions at root with major/minor groups for floating tags, and Swift ignores for the Synonym FFI packages that need coordinated bumps.

@jvsena42
jvsena42 merged commit 6791e8d into masterAug 5, 2026
11 checks passed
@jvsena42
jvsena42 deleted the chore/dependabot-automated-prs branch August 5, 2026 18:59
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jvsena42@ovitrif
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore: add dependabot config for automated PRs - #655

Merged
jvsena42 merged 2 commits into
masterfrom
chore/dependabot-automated-prs
Aug 5, 2026
Merged

chore: add dependabot config for automated PRs#655
jvsena42 merged 2 commits into
masterfrom
chore/dependabot-automated-prs

Conversation

@jvsena42

@jvsena42jvsena42 commented Aug 5, 2026

Copy link
Copy Markdown
Member

Description

This PR:

  1. Adds a dependabot.yml covering the three package ecosystems this repo actually has — the test-push-server npm tree, the workflow actions, and the Xcode-managed Package.resolved
  2. Groups each ecosystem into a single monthly PR to keep the CI cost of automated updates bounded
  3. Excludes the Synonym-owned FFI packages, which cannot be bumped unattended

The repo has had Dependabot alerts enabled for a long time but has never had a Dependabot pull request — there is no config file, so nothing was ever proposed. All 30 historical alerts are closed as fixed because they were cleaned up by hand, most recently in #651. This is the piece that stops that from being manual work.

One thing this does not do on its own, and it is the important caveat: a config file only turns on version updates. Turning an advisory into a pull request is a separate repo setting, and it needs admin on the repo. Merging this alone will not make alerts arrive as pull requests. The two halves are complementary: version updates keep dependencies current so advisories land less often, security updates handle the ones that land anyway.

Admin steps to finish enabling this

Either tick Settings → Advanced Security → Dependabot security updates, or run the equivalent from the CLI. Both endpoints require admin on the repository and return 204 No Content on success:

# Dependabot alerts — already on here, but idempotent and safe to re-run
gh api --method PUT repos/synonymdev/bitkit-ios/vulnerability-alerts
# Dependabot security updates — this is the one that turns an alert into a pull request
gh api --method PUT repos/synonymdev/bitkit-ios/automated-security-fixes

Verify afterwards:

# expect {"enabled": true, "paused": false}
gh api repos/synonymdev/bitkit-ios/automated-security-fixes
# expect HTTP/2.0 204 — a 404 means either disabled or the caller is not an admin
gh api repos/synonymdev/bitkit-ios/vulnerability-alerts --include | head -1

The dependency graph needs no action: it is on by default for public repositories and cannot be turned off.

Swift is included because it only recently became possible. Dependabot required a top-level Package.swift until 31 March 2026, when it gained the ability to discover Package.resolved nested inside .xcodeproj and .xcworkspace bundles and to read version rules out of project.pbxproj. That is exactly this repo's layout, so the ecosystem is supported here for the first time. It is also the least proven part of the change, which is why the QA notes below include a fallback to an explicit directories: path if the resolver does not find the manifest.

Grouping is the cost control rather than a tidiness preference. Unit tests and integration tests run on every pull request with no path filter, both on macos-15 with hour-long timeouts, and the e2e suite fires on anything touching Bitkit.xcodeproj/** or its own workflow file — which a Swift bump and an actions bump respectively do. Ungrouped, a month with six updates is six full CI runs. Grouping holds it to a handful.

Majors are kept out of the routine batches, but how that is expressed differs by ecosystem. For npm and swift the groups take minor and patch only, so a major bump falls through to its own pull request. Actions are a different case: every one of them is pinned to a floating major tag (actions/checkout@v6, upload-artifact@v7, and so on), so every update Dependabot can propose for them is a major one. Restricting that group the same way would mean it never fires and each action arrives as its own pull request with its own full CI run. Instead the actions entry has two groups, minor/patch and major, both matching everything — a dependency lands in the first group it matches, so major action bumps get a dedicated pull request separate from routine updates without fanning out into eight of them.

The four ignored packages are bitkit-core, ldk-node, vss-rust-client-ffi and paykit-rs. Two are on release candidates, one is pinned to a branch revision, and all four are bumped in lockstep with native code, so an unattended bump produces a red pull request rather than a useful one — #632 spent a cycle on exactly that failure mode. Ignoring them leaves lottie-ios, CodeScanner and swift-secp256k1 updating automatically, which is the subset where an automated bump is worth reviewing. The ignore rules use globs rather than exact names because the Swift ecosystem is inconsistent about whether a dependency is identified by its bare name or its full repository URL, and an exact match that misses fails silently.

No app code is touched, so there is no changelog fragment.

Linked Issues/Tasks

Screenshot / Video

N/A — repository configuration only.

QA Notes

Manual Tests

Dependabot reads dependabot.yml from the default branch only, so none of these can run until this merges. Each row in the Dependabot tab has a Check for updates button that forces a run without waiting for the monthly schedule.

  • 1. Insights → Dependency graph → Dependabot: three rows listed (npm, GitHub Actions, Swift), each with a Last checked timestamp and no config error banner.
  • 2a. Dependabot tab → Swift row → Check for updates → open the job log: lottie-ios, CodeScanner and swift-secp256k1 are resolved from the Xcode-managed manifest.
    • 2b. Same log: bitkit-core, ldk-node, vss-rust-client-ffi and paykit-rs are skipped as ignored rather than proposed.
    • 2c. If the log reports no manifest found, replace directory: / on the swift entry with directories: ["/Bitkit.xcodeproj/project.xcworkspace/xcshareddata/swiftpm"] and re-run.
  • 3. Dependabot tab → npm row → Check for updates: resolves test-push-server/package-lock.json and does not look at the repo root.
  • 4a. Dependabot tab → GitHub Actions row → Check for updates: proposes one grouped pull request rather than one per action.
    • 4b. That pull request is the github-actions-major group, since every action here is pinned to a floating major tag; github-actions-minor produces nothing.
  • 5. Repo admin → run the two gh api --method PUT commands above (or tick Settings → Advanced Security) → gh api repos/synonymdev/bitkit-ios/automated-security-fixes: returns enabled: true, paused: false. Until this is done, advisories will not open pull requests.
  • 6. First grouped pull request Dependabot opens → unit-tests and integration-tests: both green. Dependabot pull requests run with a read-only token and no repository secrets, so if the e2e suite fails for want of CHATWOOT_API that needs a Dependabot secret or an author guard, in a follow-up.

Automated Checks

  • No Swift or app code changed, so no test coverage was added, modified or removed.
  • npx -y js-yaml .github/dependabot.yml parses cleanly and yields all three updates entries with the intended ecosystems, directories, groups and ignore rules.
  • Schema validity is enforced by GitHub rather than locally: an invalid dependabot.yml is annotated directly on the pull request, so the absence of a Dependabot annotation here is the check.
  • Ecosystem resolution and grouping behaviour can only be observed once the config is on the default branch (after merge); that is what the manual steps above cover.
  • CI: standard checks run by the PR bot.

@greptile-apps

Copy link
Copy Markdown

Greptile Summary

The PR adds monthly Dependabot version-update configuration for the repository’s npm, GitHub Actions, and Xcode-managed Swift dependencies.

  • Groups routine dependency updates by ecosystem to limit CI usage.
  • Excludes four native Swift dependencies that require coordinated manual upgrades.
  • Configures ecosystem-specific commit prefixes and pull-request limits.

Confidence Score: 4/5

The GitHub Actions grouping configuration should be fixed before merging because it bundles major action upgrades that the PR intends to isolate for review.

The catch-all GitHub Actions group lacks the minor/patch filter present on the npm and Swift groups, so major action upgrades enter the grouped monthly pull request.

Files Needing Attention: .github/dependabot.yml

Important Files Changed

FilenameOverview
.github/dependabot.ymlAdds the three intended Dependabot ecosystems, but the GitHub Actions group unintentionally includes major updates despite the stated standalone-review policy.

Reviews (1): Last reviewed commit: "chore: add dependabot config" | Re-trigger Greptile

Comment thread.github/dependabot.yml
@jvsena42jvsena42 self-assigned this Aug 5, 2026

@ovitrifovitrif left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Dependabot config matches the repo: npm under test-push-server, Actions at root with major/minor groups for floating tags, and Swift ignores for the Synonym FFI packages that need coordinated bumps.

@jvsena42
jvsena42 merged commit 6791e8d into masterAug 5, 2026
11 checks passed
@jvsena42
jvsena42 deleted the chore/dependabot-automated-prs branch August 5, 2026 18:59
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jvsena42@ovitrif
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: add dependabot config for automated PRs - #655

Merged
jvsena42 merged 2 commits into
masterfrom
chore/dependabot-automated-prs
Aug 5, 2026
Merged

chore: add dependabot config for automated PRs#655
jvsena42 merged 2 commits into
masterfrom
chore/dependabot-automated-prs

Conversation

@jvsena42

@jvsena42jvsena42 commented Aug 5, 2026

Copy link
Copy Markdown
Member

Description

This PR:

  1. Adds a dependabot.yml covering the three package ecosystems this repo actually has — the test-push-server npm tree, the workflow actions, and the Xcode-managed Package.resolved
  2. Groups each ecosystem into a single monthly PR to keep the CI cost of automated updates bounded
  3. Excludes the Synonym-owned FFI packages, which cannot be bumped unattended

The repo has had Dependabot alerts enabled for a long time but has never had a Dependabot pull request — there is no config file, so nothing was ever proposed. All 30 historical alerts are closed as fixed because they were cleaned up by hand, most recently in #651. This is the piece that stops that from being manual work.

One thing this does not do on its own, and it is the important caveat: a config file only turns on version updates. Turning an advisory into a pull request is a separate repo setting, and it needs admin on the repo. Merging this alone will not make alerts arrive as pull requests. The two halves are complementary: version updates keep dependencies current so advisories land less often, security updates handle the ones that land anyway.

Admin steps to finish enabling this

Either tick Settings → Advanced Security → Dependabot security updates, or run the equivalent from the CLI. Both endpoints require admin on the repository and return 204 No Content on success:

# Dependabot alerts — already on here, but idempotent and safe to re-run
gh api --method PUT repos/synonymdev/bitkit-ios/vulnerability-alerts
# Dependabot security updates — this is the one that turns an alert into a pull request
gh api --method PUT repos/synonymdev/bitkit-ios/automated-security-fixes

Verify afterwards:

# expect {"enabled": true, "paused": false}
gh api repos/synonymdev/bitkit-ios/automated-security-fixes
# expect HTTP/2.0 204 — a 404 means either disabled or the caller is not an admin
gh api repos/synonymdev/bitkit-ios/vulnerability-alerts --include | head -1

The dependency graph needs no action: it is on by default for public repositories and cannot be turned off.

Swift is included because it only recently became possible. Dependabot required a top-level Package.swift until 31 March 2026, when it gained the ability to discover Package.resolved nested inside .xcodeproj and .xcworkspace bundles and to read version rules out of project.pbxproj. That is exactly this repo's layout, so the ecosystem is supported here for the first time. It is also the least proven part of the change, which is why the QA notes below include a fallback to an explicit directories: path if the resolver does not find the manifest.

Grouping is the cost control rather than a tidiness preference. Unit tests and integration tests run on every pull request with no path filter, both on macos-15 with hour-long timeouts, and the e2e suite fires on anything touching Bitkit.xcodeproj/** or its own workflow file — which a Swift bump and an actions bump respectively do. Ungrouped, a month with six updates is six full CI runs. Grouping holds it to a handful.

Majors are kept out of the routine batches, but how that is expressed differs by ecosystem. For npm and swift the groups take minor and patch only, so a major bump falls through to its own pull request. Actions are a different case: every one of them is pinned to a floating major tag (actions/checkout@v6, upload-artifact@v7, and so on), so every update Dependabot can propose for them is a major one. Restricting that group the same way would mean it never fires and each action arrives as its own pull request with its own full CI run. Instead the actions entry has two groups, minor/patch and major, both matching everything — a dependency lands in the first group it matches, so major action bumps get a dedicated pull request separate from routine updates without fanning out into eight of them.

The four ignored packages are bitkit-core, ldk-node, vss-rust-client-ffi and paykit-rs. Two are on release candidates, one is pinned to a branch revision, and all four are bumped in lockstep with native code, so an unattended bump produces a red pull request rather than a useful one — #632 spent a cycle on exactly that failure mode. Ignoring them leaves lottie-ios, CodeScanner and swift-secp256k1 updating automatically, which is the subset where an automated bump is worth reviewing. The ignore rules use globs rather than exact names because the Swift ecosystem is inconsistent about whether a dependency is identified by its bare name or its full repository URL, and an exact match that misses fails silently.

No app code is touched, so there is no changelog fragment.

Linked Issues/Tasks

Screenshot / Video

N/A — repository configuration only.

QA Notes

Manual Tests

Dependabot reads dependabot.yml from the default branch only, so none of these can run until this merges. Each row in the Dependabot tab has a Check for updates button that forces a run without waiting for the monthly schedule.

  • 1. Insights → Dependency graph → Dependabot: three rows listed (npm, GitHub Actions, Swift), each with a Last checked timestamp and no config error banner.
  • 2a. Dependabot tab → Swift row → Check for updates → open the job log: lottie-ios, CodeScanner and swift-secp256k1 are resolved from the Xcode-managed manifest.
    • 2b. Same log: bitkit-core, ldk-node, vss-rust-client-ffi and paykit-rs are skipped as ignored rather than proposed.
    • 2c. If the log reports no manifest found, replace directory: / on the swift entry with directories: ["/Bitkit.xcodeproj/project.xcworkspace/xcshareddata/swiftpm"] and re-run.
  • 3. Dependabot tab → npm row → Check for updates: resolves test-push-server/package-lock.json and does not look at the repo root.
  • 4a. Dependabot tab → GitHub Actions row → Check for updates: proposes one grouped pull request rather than one per action.
    • 4b. That pull request is the github-actions-major group, since every action here is pinned to a floating major tag; github-actions-minor produces nothing.
  • 5. Repo admin → run the two gh api --method PUT commands above (or tick Settings → Advanced Security) → gh api repos/synonymdev/bitkit-ios/automated-security-fixes: returns enabled: true, paused: false. Until this is done, advisories will not open pull requests.
  • 6. First grouped pull request Dependabot opens → unit-tests and integration-tests: both green. Dependabot pull requests run with a read-only token and no repository secrets, so if the e2e suite fails for want of CHATWOOT_API that needs a Dependabot secret or an author guard, in a follow-up.

Automated Checks

  • No Swift or app code changed, so no test coverage was added, modified or removed.
  • npx -y js-yaml .github/dependabot.yml parses cleanly and yields all three updates entries with the intended ecosystems, directories, groups and ignore rules.
  • Schema validity is enforced by GitHub rather than locally: an invalid dependabot.yml is annotated directly on the pull request, so the absence of a Dependabot annotation here is the check.
  • Ecosystem resolution and grouping behaviour can only be observed once the config is on the default branch (after merge); that is what the manual steps above cover.
  • CI: standard checks run by the PR bot.

@greptile-apps

Copy link
Copy Markdown

Greptile Summary

The PR adds monthly Dependabot version-update configuration for the repository’s npm, GitHub Actions, and Xcode-managed Swift dependencies.

  • Groups routine dependency updates by ecosystem to limit CI usage.
  • Excludes four native Swift dependencies that require coordinated manual upgrades.
  • Configures ecosystem-specific commit prefixes and pull-request limits.

Confidence Score: 4/5

The GitHub Actions grouping configuration should be fixed before merging because it bundles major action upgrades that the PR intends to isolate for review.

The catch-all GitHub Actions group lacks the minor/patch filter present on the npm and Swift groups, so major action upgrades enter the grouped monthly pull request.

Files Needing Attention: .github/dependabot.yml

Important Files Changed

FilenameOverview
.github/dependabot.ymlAdds the three intended Dependabot ecosystems, but the GitHub Actions group unintentionally includes major updates despite the stated standalone-review policy.

Reviews (1): Last reviewed commit: "chore: add dependabot config" | Re-trigger Greptile

Comment thread.github/dependabot.yml
@jvsena42jvsena42 self-assigned this Aug 5, 2026

@ovitrifovitrif left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Dependabot config matches the repo: npm under test-push-server, Actions at root with major/minor groups for floating tags, and Swift ignores for the Synonym FFI packages that need coordinated bumps.

@jvsena42
jvsena42 merged commit 6791e8d into masterAug 5, 2026
11 checks passed
@jvsena42
jvsena42 deleted the chore/dependabot-automated-prs branch August 5, 2026 18:59
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jvsena42@ovitrif
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: add dependabot config for automated PRs - #655

Merged
jvsena42 merged 2 commits into
masterfrom
chore/dependabot-automated-prs
Aug 5, 2026
Merged

chore: add dependabot config for automated PRs#655
jvsena42 merged 2 commits into
masterfrom
chore/dependabot-automated-prs

Conversation

@jvsena42

@jvsena42jvsena42 commented Aug 5, 2026

Copy link
Copy Markdown
Member

Description

This PR:

  1. Adds a dependabot.yml covering the three package ecosystems this repo actually has — the test-push-server npm tree, the workflow actions, and the Xcode-managed Package.resolved
  2. Groups each ecosystem into a single monthly PR to keep the CI cost of automated updates bounded
  3. Excludes the Synonym-owned FFI packages, which cannot be bumped unattended

The repo has had Dependabot alerts enabled for a long time but has never had a Dependabot pull request — there is no config file, so nothing was ever proposed. All 30 historical alerts are closed as fixed because they were cleaned up by hand, most recently in #651. This is the piece that stops that from being manual work.

One thing this does not do on its own, and it is the important caveat: a config file only turns on version updates. Turning an advisory into a pull request is a separate repo setting, and it needs admin on the repo. Merging this alone will not make alerts arrive as pull requests. The two halves are complementary: version updates keep dependencies current so advisories land less often, security updates handle the ones that land anyway.

Admin steps to finish enabling this

Either tick Settings → Advanced Security → Dependabot security updates, or run the equivalent from the CLI. Both endpoints require admin on the repository and return 204 No Content on success:

# Dependabot alerts — already on here, but idempotent and safe to re-run
gh api --method PUT repos/synonymdev/bitkit-ios/vulnerability-alerts
# Dependabot security updates — this is the one that turns an alert into a pull request
gh api --method PUT repos/synonymdev/bitkit-ios/automated-security-fixes

Verify afterwards:

# expect {"enabled": true, "paused": false}
gh api repos/synonymdev/bitkit-ios/automated-security-fixes
# expect HTTP/2.0 204 — a 404 means either disabled or the caller is not an admin
gh api repos/synonymdev/bitkit-ios/vulnerability-alerts --include | head -1

The dependency graph needs no action: it is on by default for public repositories and cannot be turned off.

Swift is included because it only recently became possible. Dependabot required a top-level Package.swift until 31 March 2026, when it gained the ability to discover Package.resolved nested inside .xcodeproj and .xcworkspace bundles and to read version rules out of project.pbxproj. That is exactly this repo's layout, so the ecosystem is supported here for the first time. It is also the least proven part of the change, which is why the QA notes below include a fallback to an explicit directories: path if the resolver does not find the manifest.

Grouping is the cost control rather than a tidiness preference. Unit tests and integration tests run on every pull request with no path filter, both on macos-15 with hour-long timeouts, and the e2e suite fires on anything touching Bitkit.xcodeproj/** or its own workflow file — which a Swift bump and an actions bump respectively do. Ungrouped, a month with six updates is six full CI runs. Grouping holds it to a handful.

Majors are kept out of the routine batches, but how that is expressed differs by ecosystem. For npm and swift the groups take minor and patch only, so a major bump falls through to its own pull request. Actions are a different case: every one of them is pinned to a floating major tag (actions/checkout@v6, upload-artifact@v7, and so on), so every update Dependabot can propose for them is a major one. Restricting that group the same way would mean it never fires and each action arrives as its own pull request with its own full CI run. Instead the actions entry has two groups, minor/patch and major, both matching everything — a dependency lands in the first group it matches, so major action bumps get a dedicated pull request separate from routine updates without fanning out into eight of them.

The four ignored packages are bitkit-core, ldk-node, vss-rust-client-ffi and paykit-rs. Two are on release candidates, one is pinned to a branch revision, and all four are bumped in lockstep with native code, so an unattended bump produces a red pull request rather than a useful one — #632 spent a cycle on exactly that failure mode. Ignoring them leaves lottie-ios, CodeScanner and swift-secp256k1 updating automatically, which is the subset where an automated bump is worth reviewing. The ignore rules use globs rather than exact names because the Swift ecosystem is inconsistent about whether a dependency is identified by its bare name or its full repository URL, and an exact match that misses fails silently.

No app code is touched, so there is no changelog fragment.

Linked Issues/Tasks

Screenshot / Video

N/A — repository configuration only.

QA Notes

Manual Tests

Dependabot reads dependabot.yml from the default branch only, so none of these can run until this merges. Each row in the Dependabot tab has a Check for updates button that forces a run without waiting for the monthly schedule.

  • 1. Insights → Dependency graph → Dependabot: three rows listed (npm, GitHub Actions, Swift), each with a Last checked timestamp and no config error banner.
  • 2a. Dependabot tab → Swift row → Check for updates → open the job log: lottie-ios, CodeScanner and swift-secp256k1 are resolved from the Xcode-managed manifest.
    • 2b. Same log: bitkit-core, ldk-node, vss-rust-client-ffi and paykit-rs are skipped as ignored rather than proposed.
    • 2c. If the log reports no manifest found, replace directory: / on the swift entry with directories: ["/Bitkit.xcodeproj/project.xcworkspace/xcshareddata/swiftpm"] and re-run.
  • 3. Dependabot tab → npm row → Check for updates: resolves test-push-server/package-lock.json and does not look at the repo root.
  • 4a. Dependabot tab → GitHub Actions row → Check for updates: proposes one grouped pull request rather than one per action.
    • 4b. That pull request is the github-actions-major group, since every action here is pinned to a floating major tag; github-actions-minor produces nothing.
  • 5. Repo admin → run the two gh api --method PUT commands above (or tick Settings → Advanced Security) → gh api repos/synonymdev/bitkit-ios/automated-security-fixes: returns enabled: true, paused: false. Until this is done, advisories will not open pull requests.
  • 6. First grouped pull request Dependabot opens → unit-tests and integration-tests: both green. Dependabot pull requests run with a read-only token and no repository secrets, so if the e2e suite fails for want of CHATWOOT_API that needs a Dependabot secret or an author guard, in a follow-up.

Automated Checks

  • No Swift or app code changed, so no test coverage was added, modified or removed.
  • npx -y js-yaml .github/dependabot.yml parses cleanly and yields all three updates entries with the intended ecosystems, directories, groups and ignore rules.
  • Schema validity is enforced by GitHub rather than locally: an invalid dependabot.yml is annotated directly on the pull request, so the absence of a Dependabot annotation here is the check.
  • Ecosystem resolution and grouping behaviour can only be observed once the config is on the default branch (after merge); that is what the manual steps above cover.
  • CI: standard checks run by the PR bot.

@greptile-apps

Copy link
Copy Markdown

Greptile Summary

The PR adds monthly Dependabot version-update configuration for the repository’s npm, GitHub Actions, and Xcode-managed Swift dependencies.

  • Groups routine dependency updates by ecosystem to limit CI usage.
  • Excludes four native Swift dependencies that require coordinated manual upgrades.
  • Configures ecosystem-specific commit prefixes and pull-request limits.

Confidence Score: 4/5

The GitHub Actions grouping configuration should be fixed before merging because it bundles major action upgrades that the PR intends to isolate for review.

The catch-all GitHub Actions group lacks the minor/patch filter present on the npm and Swift groups, so major action upgrades enter the grouped monthly pull request.

Files Needing Attention: .github/dependabot.yml

Important Files Changed

FilenameOverview
.github/dependabot.ymlAdds the three intended Dependabot ecosystems, but the GitHub Actions group unintentionally includes major updates despite the stated standalone-review policy.

Reviews (1): Last reviewed commit: "chore: add dependabot config" | Re-trigger Greptile

Comment thread.github/dependabot.yml
@jvsena42jvsena42 self-assigned this Aug 5, 2026

@ovitrifovitrif left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Dependabot config matches the repo: npm under test-push-server, Actions at root with major/minor groups for floating tags, and Swift ignores for the Synonym FFI packages that need coordinated bumps.

@jvsena42
jvsena42 merged commit 6791e8d into masterAug 5, 2026
11 checks passed
@jvsena42
jvsena42 deleted the chore/dependabot-automated-prs branch August 5, 2026 18:59
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jvsena42@ovitrif
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore: add dependabot config for automated PRs - #655

Merged
jvsena42 merged 2 commits into
masterfrom
chore/dependabot-automated-prs
Aug 5, 2026
Merged

chore: add dependabot config for automated PRs#655
jvsena42 merged 2 commits into
masterfrom
chore/dependabot-automated-prs

Conversation

@jvsena42

@jvsena42jvsena42 commented Aug 5, 2026

Copy link
Copy Markdown
Member

Description

This PR:

  1. Adds a dependabot.yml covering the three package ecosystems this repo actually has — the test-push-server npm tree, the workflow actions, and the Xcode-managed Package.resolved
  2. Groups each ecosystem into a single monthly PR to keep the CI cost of automated updates bounded
  3. Excludes the Synonym-owned FFI packages, which cannot be bumped unattended

The repo has had Dependabot alerts enabled for a long time but has never had a Dependabot pull request — there is no config file, so nothing was ever proposed. All 30 historical alerts are closed as fixed because they were cleaned up by hand, most recently in #651. This is the piece that stops that from being manual work.

One thing this does not do on its own, and it is the important caveat: a config file only turns on version updates. Turning an advisory into a pull request is a separate repo setting, and it needs admin on the repo. Merging this alone will not make alerts arrive as pull requests. The two halves are complementary: version updates keep dependencies current so advisories land less often, security updates handle the ones that land anyway.

Admin steps to finish enabling this

Either tick Settings → Advanced Security → Dependabot security updates, or run the equivalent from the CLI. Both endpoints require admin on the repository and return 204 No Content on success:

# Dependabot alerts — already on here, but idempotent and safe to re-run
gh api --method PUT repos/synonymdev/bitkit-ios/vulnerability-alerts
# Dependabot security updates — this is the one that turns an alert into a pull request
gh api --method PUT repos/synonymdev/bitkit-ios/automated-security-fixes

Verify afterwards:

# expect {"enabled": true, "paused": false}
gh api repos/synonymdev/bitkit-ios/automated-security-fixes
# expect HTTP/2.0 204 — a 404 means either disabled or the caller is not an admin
gh api repos/synonymdev/bitkit-ios/vulnerability-alerts --include | head -1

The dependency graph needs no action: it is on by default for public repositories and cannot be turned off.

Swift is included because it only recently became possible. Dependabot required a top-level Package.swift until 31 March 2026, when it gained the ability to discover Package.resolved nested inside .xcodeproj and .xcworkspace bundles and to read version rules out of project.pbxproj. That is exactly this repo's layout, so the ecosystem is supported here for the first time. It is also the least proven part of the change, which is why the QA notes below include a fallback to an explicit directories: path if the resolver does not find the manifest.

Grouping is the cost control rather than a tidiness preference. Unit tests and integration tests run on every pull request with no path filter, both on macos-15 with hour-long timeouts, and the e2e suite fires on anything touching Bitkit.xcodeproj/** or its own workflow file — which a Swift bump and an actions bump respectively do. Ungrouped, a month with six updates is six full CI runs. Grouping holds it to a handful.

Majors are kept out of the routine batches, but how that is expressed differs by ecosystem. For npm and swift the groups take minor and patch only, so a major bump falls through to its own pull request. Actions are a different case: every one of them is pinned to a floating major tag (actions/checkout@v6, upload-artifact@v7, and so on), so every update Dependabot can propose for them is a major one. Restricting that group the same way would mean it never fires and each action arrives as its own pull request with its own full CI run. Instead the actions entry has two groups, minor/patch and major, both matching everything — a dependency lands in the first group it matches, so major action bumps get a dedicated pull request separate from routine updates without fanning out into eight of them.

The four ignored packages are bitkit-core, ldk-node, vss-rust-client-ffi and paykit-rs. Two are on release candidates, one is pinned to a branch revision, and all four are bumped in lockstep with native code, so an unattended bump produces a red pull request rather than a useful one — #632 spent a cycle on exactly that failure mode. Ignoring them leaves lottie-ios, CodeScanner and swift-secp256k1 updating automatically, which is the subset where an automated bump is worth reviewing. The ignore rules use globs rather than exact names because the Swift ecosystem is inconsistent about whether a dependency is identified by its bare name or its full repository URL, and an exact match that misses fails silently.

No app code is touched, so there is no changelog fragment.

Linked Issues/Tasks

Screenshot / Video

N/A — repository configuration only.

QA Notes

Manual Tests

Dependabot reads dependabot.yml from the default branch only, so none of these can run until this merges. Each row in the Dependabot tab has a Check for updates button that forces a run without waiting for the monthly schedule.

  • 1. Insights → Dependency graph → Dependabot: three rows listed (npm, GitHub Actions, Swift), each with a Last checked timestamp and no config error banner.
  • 2a. Dependabot tab → Swift row → Check for updates → open the job log: lottie-ios, CodeScanner and swift-secp256k1 are resolved from the Xcode-managed manifest.
    • 2b. Same log: bitkit-core, ldk-node, vss-rust-client-ffi and paykit-rs are skipped as ignored rather than proposed.
    • 2c. If the log reports no manifest found, replace directory: / on the swift entry with directories: ["/Bitkit.xcodeproj/project.xcworkspace/xcshareddata/swiftpm"] and re-run.
  • 3. Dependabot tab → npm row → Check for updates: resolves test-push-server/package-lock.json and does not look at the repo root.
  • 4a. Dependabot tab → GitHub Actions row → Check for updates: proposes one grouped pull request rather than one per action.
    • 4b. That pull request is the github-actions-major group, since every action here is pinned to a floating major tag; github-actions-minor produces nothing.
  • 5. Repo admin → run the two gh api --method PUT commands above (or tick Settings → Advanced Security) → gh api repos/synonymdev/bitkit-ios/automated-security-fixes: returns enabled: true, paused: false. Until this is done, advisories will not open pull requests.
  • 6. First grouped pull request Dependabot opens → unit-tests and integration-tests: both green. Dependabot pull requests run with a read-only token and no repository secrets, so if the e2e suite fails for want of CHATWOOT_API that needs a Dependabot secret or an author guard, in a follow-up.

Automated Checks

  • No Swift or app code changed, so no test coverage was added, modified or removed.
  • npx -y js-yaml .github/dependabot.yml parses cleanly and yields all three updates entries with the intended ecosystems, directories, groups and ignore rules.
  • Schema validity is enforced by GitHub rather than locally: an invalid dependabot.yml is annotated directly on the pull request, so the absence of a Dependabot annotation here is the check.
  • Ecosystem resolution and grouping behaviour can only be observed once the config is on the default branch (after merge); that is what the manual steps above cover.
  • CI: standard checks run by the PR bot.

@greptile-apps

Copy link
Copy Markdown

Greptile Summary

The PR adds monthly Dependabot version-update configuration for the repository’s npm, GitHub Actions, and Xcode-managed Swift dependencies.

  • Groups routine dependency updates by ecosystem to limit CI usage.
  • Excludes four native Swift dependencies that require coordinated manual upgrades.
  • Configures ecosystem-specific commit prefixes and pull-request limits.

Confidence Score: 4/5

The GitHub Actions grouping configuration should be fixed before merging because it bundles major action upgrades that the PR intends to isolate for review.

The catch-all GitHub Actions group lacks the minor/patch filter present on the npm and Swift groups, so major action upgrades enter the grouped monthly pull request.

Files Needing Attention: .github/dependabot.yml

Important Files Changed

FilenameOverview
.github/dependabot.ymlAdds the three intended Dependabot ecosystems, but the GitHub Actions group unintentionally includes major updates despite the stated standalone-review policy.

Reviews (1): Last reviewed commit: "chore: add dependabot config" | Re-trigger Greptile

Comment thread.github/dependabot.yml
@jvsena42jvsena42 self-assigned this Aug 5, 2026

@ovitrifovitrif left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Dependabot config matches the repo: npm under test-push-server, Actions at root with major/minor groups for floating tags, and Swift ignores for the Synonym FFI packages that need coordinated bumps.

@jvsena42
jvsena42 merged commit 6791e8d into masterAug 5, 2026
11 checks passed
@jvsena42
jvsena42 deleted the chore/dependabot-automated-prs branch August 5, 2026 18:59
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jvsena42@ovitrif