Skip to content

chore: take the fleet's Dependabot configuration - #22

Merged
zmaril merged 1 commit into
mainfrom
fleet-dependabot
Aug 30, 2026
Merged

zmaril merged 1 commit into
mainfrom
fleet-dependabot

Conversation

@zmaril

@zmaril zmaril commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

The fleet's dependabot.yml (PowderworksCode/conf#6), which this repository has not picked up yet.

The bun entry's directories glob was /*, which reaches exactly one level down: it missed members whose bun project is the repository root, and anything nested deeper — treebank's language oracles sit two levels below crates/. It is /** now, the whole tree, which is what the file always meant by letting globs discover each member's topology rather than listing it centrally.

npm joins bun, for directories carrying a package-lock.json rather than a bun.lock. Dependabot decides per directory from the lockfile it finds there.

One file, straight from conf; a local edit here would be drift the next sync reports.

The globs reach the whole tree now rather than one level down, so a bun
project at the repository root or nested deeper is covered, and npm
joins bun for the directories carrying a package-lock.json.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0144PU3MssnfbM5tZiqXW7d3
@zmaril
zmaril merged commit c445831 into main Aug 30, 2026
10 checks passed
@zmaril
zmaril deleted the fleet-dependabot branch August 30, 2026 09:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant