From 64a2dd31e68c4134022556c908588a167ee9cdf2 Mon Sep 17 00:00:00 2001 From: Claude Date: Tue, 29 Sep 2026 14:21:54 +0000 Subject: [PATCH] Let dependabot open the plugin bumps, so a breaking one shows up here first While @cap2ui5/cds-plugin is 0.x a minor may change how apps are written, and the samples are released in step with it. A monthly dependabot pull request for the plugin devDependency runs the whole suite against the new plugin, so a plugin release that breaks a sample turns a pull request red instead of a project that installs both. The peer range stays manual: it moves with the release that regenerates the samples. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_011hTSksXxA58KdKrPbnQjNo --- .github/dependabot.yml | 27 +++++++++++++++++++++++++++ 1 file changed, 27 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..bdaaee9 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,27 @@ +# Monthly, grouped. The dependency that matters is the devDependency on +# @cap2ui5/cds-plugin: while the plugin is 0.x a minor may change how apps are +# written, and the samples are released in step with it. A bump of it opened +# here runs the whole suite against the new plugin, so a plugin release that +# breaks a sample shows up as a red pull request instead of in a project that +# installs both. The peer range in package.json is moved by hand, with the +# release that regenerates the samples. +version: 2 +updates: + - package-ecosystem: npm + directory: / + schedule: + interval: monthly + open-pull-requests-limit: 5 + groups: + cap2ui5: + patterns: ["@cap2ui5/*"] + dependencies: + patterns: ["*"] + exclude-patterns: ["@cap2ui5/*"] + - package-ecosystem: github-actions + directory: / + schedule: + interval: monthly + groups: + actions: + patterns: ["*"]