Skip to content

ci(dependabot): update openCoreEMR packages without the release cooldown - #38

Merged
kojiromike merged 1 commit into
mainfrom
ci/dependabot-cooldown-internal
Sep 29, 2026
Merged

kojiromike merged 1 commit into
mainfrom
ci/dependabot-cooldown-internal

Conversation

@kojiromike

Copy link
Copy Markdown
Contributor

Dependabot now holds every version update for 3 days after release, unless dependabot.yml configures cooldown. That delay guards against a compromised third-party release. For our own packages it only adds a wait: openCoreEMR/github-workflows-internal v5.2.0 went unproposed for that reason.

This adds cooldown.exclude for openCoreEMR/* and opencoreemr/* to every updates: entry. Both casings are listed because GitHub Actions and Composer spell the owner differently. Third-party updates keep the 3-day default. Reference: exclude takes wildcards and always wins over the default.

The change is the same across the org's repos. It is checked so that the parsed config changes only by the new cooldown keys.

Dependabot now holds every version update for 3 days after release unless
dependabot.yml configures a cooldown. The delay guards against a compromised
third-party release, but it only slows down our own: an internal release sat
unproposed until the window passed. Exclude openCoreEMR packages (both name
casings, since GitHub Actions and Composer spell the owner differently) and
keep the 3-day default for everything else.

Assisted-by: Claude Code
@kojiromike
kojiromike force-pushed the ci/dependabot-cooldown-internal branch from 5a3fd69 to 2d4139b Compare September 29, 2026 16:12
@kojiromike
kojiromike merged commit b7e721d into main Sep 29, 2026
1 check passed
@kojiromike
kojiromike deleted the ci/dependabot-cooldown-internal branch September 29, 2026 16:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant