Skip to content

Dependabot/gh-actions: move to bi-weekly schedule#2668

Merged
GaryJones merged 1 commit intodevelopfrom
feature/dependabot-every-two-weeks
Dec 15, 2025
Merged

Dependabot/gh-actions: move to bi-weekly schedule#2668
GaryJones merged 1 commit intodevelopfrom
feature/dependabot-every-two-weeks

Conversation

@jrfnl
Copy link
Copy Markdown
Member

@jrfnl jrfnl commented Dec 8, 2025

Description

👉 Important: this is for version updates only, not for security updates, which are handled separately and don't depend on this configuration.


PR #2621 updated the GitHub Actions workflows used in this repo to use "pinned" versions for external action runners to improve workflow security.

The net result of this, is that Dependabot now sends PRs to all repos I (co-)maintain on a weekly basis for most repos. As the default day for the "weekly" interval is Monday and most repos don't change this, it means that Dependabot has a huge queue on Mondays and that PRs come in bit by bit throughout the day and even spill over into Tuesday.

This constant stream of low level/easy PRs to merge is disruptive and time consuming, especially as I can't just go through them all in one go.

As these updates are rarely time-sensitive, it should be fine to receive them less frequently.

This commit tries to make it so by changing the Dependabot schedule for GitHub Actions to once every two weeks and late in the day when the queue should be mostly empty (as long as it's not a Monday), which should mean that if I apply this same change to all repos I am involved with, all these Dependabot PRs should come in around the same time.

Suggested changelog entry

N/A

Additional Context

As per the description, this is mostly a quality of life improvement for me as currently I can't seem to get any work done anymore on any given Monday.

👉 Important: this is for **version** updates only, not for security updates, which are handled separately and don't depend on this configuration.

---

PR 2621 updated the GitHub Actions workflows used in this repo to use "pinned" versions for external action runners to improve workflow security.

The net result of this, is that Dependabot now sends PRs to all repos I (co-)maintain on a weekly basis for most repos.
As the default day for the "weekly" interval is _Monday_ and most repos don't change this, it means that Dependabot has a huge queue on Mondays and that PRs come in bit by bit throughout the day and even spill over into Tuesday.

This constant stream of low level/easy PRs to merge is disruptive and time consuming, especially as I can't just go through them all in one go.

As these updates are rarely time-sensitive, it should be fine to receive them less frequently.

This commit tries to make it so by changing the Dependabot schedule for GitHub Actions to once every two weeks and late in the day when the queue should be mostly empty (as long as it's not a Monday), which should mean that if I apply this same change to all repos I am involved with, all these Dependabot PRs should come in around the same time.
@rodrigoprimo rodrigoprimo self-requested a review December 8, 2025 17:16
@jrfnl jrfnl requested a review from GaryJones December 15, 2025 12:49
@GaryJones GaryJones merged commit a94350c into develop Dec 15, 2025
42 checks passed
@GaryJones GaryJones deleted the feature/dependabot-every-two-weeks branch December 15, 2025 12:58
@jrfnl jrfnl modified the milestones: 3.3.x, 3.4.0 Feb 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants