Skip to content

Add Dependabot config and auto-merge workflow - #37822

Open
gewarren wants to merge 1 commit into
dotnet:mainfrom
gewarren:merge-dependabot
Open

gewarren wants to merge 1 commit into
dotnet:mainfrom
gewarren:merge-dependabot

Conversation

@gewarren

@gewarren gewarren commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

Copilot AI balanced review requested due to automatic review settings October 9, 2026 00:23

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

NuGet globs omit many package-bearing sample directories that use naming forms other than an exact samples segment.

1 open finding
What changed in this PR

Adds Dependabot dependency updates and automatic approval/merging for Dependabot PRs targeting main.

Changes:

  • Configures weekly GitHub Actions and NuGet updates.
  • Adds a hardened auto-approval and squash-merge workflow.
File Description
.github/​dependabot.yml Defines grouped dependency-update schedules.
.github/​workflows/​dependabot-approve-merge.yml Automatically approves and merges Dependabot PRs.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/dependabot.yml
# NuGet updates for ASP.NET Core samples
- package-ecosystem: "nuget"
directories:
- "aspnetcore/fundamentals/**/samples/**/*"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants