dependabot / dependabot/dependabot-core

Per dependency bump schedule

Open
#2,165 18 comments 45 reactions 0 assignees View on GitHub
F: configuration-file F: noise Keep T: feature-request
Dominant language
Ruby
Stars
5.8k
Forks
1.5k
Avg merge
2d 18h
Merged PRs (30d)
149

Description

I'm not sure if there is already an open issue/backlog item for this, but it would be nice to be able to set bump schedules on a per-dependency basis.

For example, I typically want daily updates to my repositories so I can get the latest packages asap, except there are a few dependencies that release daily that I don't want to have to review and merge every day. For these few dependencies (usually AWS packages), I would want them to be bumped weekly or even monthly.

Right now I have this repository set to bump weekly because of those frequently updated packages, so I get a big dump of everything on Mondays. It would be nice to change it to daily for all packages except the frequently updated ones.

Thanks for all your work on dependabot!

Contributor guide

Open the contributing guide

Research direction

The issue names no files, tests, or entry points. Start by locating the current repository-wide bump-schedule configuration and dependency selection logic; done should allow named dependencies to use weekly or monthly schedules while other dependencies retain the default schedule.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, ruby
Domain
devtools
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.