Skip Dependabot cooldown for internal wp-cli packages - #293
Conversation
The 7-day cooldown is meant to guard against bad releases of third-party packages. Packages published by the wp-cli org are our own, so they should be picked up immediately. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FHYHkFiEDRs9E7BstQpdLD
|
Understand this PR’s impact Explore downstream dependencies and potential security impact with Blast Radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe Dependabot Composer configuration now excludes ChangesDependabot policy
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Other Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
Updated Dependabot configuration to exclude internal wp-cli packages from the default 7-day cooldown period, allowing them to be updated immediately upon release.
Changes
wp-cli/*pattern are now exempt from the cooldown delayRationale
Since packages from the wp-cli organization are maintained internally and considered trusted, there's no need to apply the same cautious update delay that applies to external dependencies. This enables faster iteration on internal tooling and dependencies.
https://claude.ai/code/session_01FHYHkFiEDRs9E7BstQpdLD
Summary by CodeRabbit
wp-cli/*pattern.