← ClaudeAtlas

ref-sp-dev-github-dependabotlisted

Portable Dependabot guidance for dependabot.yml configuration, ecosystem selection, schedules, grouping, ignore or allow rules, private registries, and GitHub Actions updates. Use when: creating or reviewing .github/dependabot.yml, tuning update volume, or deciding how version and security updates should be grouped and scoped.
swiftpostlabs/agentic-tools · ★ 0 · AI & Automation · score 73
Install: claude install-skill swiftpostlabs/agentic-tools
# GitHub Dependabot ## Purpose Provide portable defaults for configuring Dependabot so repositories stay current without drowning maintainers in low-signal update pull requests. ## When to use this skill - Creating or revising `.github/dependabot.yml`. - Choosing which ecosystems and directories Dependabot should monitor. - Reducing PR noise with schedules, grouping, cooldowns, or open PR limits. - Configuring updates for GitHub Actions, private registries, or multi-directory repositories. - Automating safe Dependabot PR handling, such as metadata-driven labels, approvals, automerge, or release-intent file generation. ## Scope boundaries This skill owns **`.github/dependabot.yml`**: ecosystems, schedules, grouping, ignore and allow rules, private registries, and update volume. - `ref-sp-dev-github-actions-ci` — `.github/workflows/*.yml`. Same folder, different job: this config opens the dependency PRs; those workflows are what run on them. - `ref-sp-dev-semantic-versioning` — what a version range actually permits, and which dependency field a package belongs in. Those rules decide what Dependabot is even allowed to propose. - `ref-sp-dev-package-management` — keeping versions in step across manifests once an update lands. ## Defaults - Keep the config in `.github/dependabot.yml` and start it with `version: 2`. - Add one `updates` block per ecosystem and directory boundary unless multi-directory grouping is intentional. - Prefer `weekly` schedules by default; use