From d13ee794a0c18185f48ed4a3f508b3e579d13163 Mon Sep 17 00:00:00 2001 From: Claude Date: Mon, 21 Sep 2026 10:40:33 +0000 Subject: [PATCH] Exclude wp-cli packages from the Composer Dependabot cooldown The 7-day cooldown is meant to guard against bad releases of third-party packages. Packages published by the wp-cli org are our own, so they should be picked up immediately. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01FHYHkFiEDRs9E7BstQpdLD --- .github/dependabot.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 991c6c3..49fbe19 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -9,6 +9,9 @@ updates: - scope:distribution cooldown: default-days: 7 + # Packages from our own org are trusted, so they are updated immediately. + exclude: + - "wp-cli/*" # Only wp-cli-tests carries a package.json, holding the pinned version of the # Gherkin linter. This is a no-op in every other repository. - package-ecosystem: npm