Skip to content

Dependabot: one PR for each provider SDK - #1568

Merged
arul28 merged 1 commit into
mainfrom
ade/dependabot-pr-per-sdk
Oct 10, 2026
Merged

arul28 merged 1 commit into
mainfrom
ade/dependabot-pr-per-sdk

Conversation

@arul28

@arul28 arul28 commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Change

  • Replace the provider-sdks group with a group-by: dependency-name group. Each SDK gets its own PR. That PR bumps the SDK in both apps/desktop and apps/ade-cli, so the two folders stay on the same version.
  • Raise open-pull-requests-limit from 2 to 6, one for each watched SDK.

The owner asked for one PR for each bump, so the Dependabot automation runs once for each SDK.

Check

After the merge, Dependabot should open one PR each for Claude Agent SDK, Codex, Cursor, OpenCode CLI and OpenCode client.

🤖 Generated with Claude Code


Note

Low Risk
CI/automation config only; no application runtime or security logic changes.

Overview
Dependabot now opens one PR per provider SDK instead of batching all six into a shared group.

The old provider-sdks pattern group is replaced with each-provider-sdk using group-by: dependency-name, so a single PR still bumps the same package in both apps/desktop and apps/ade-cli. open-pull-requests-limit goes from 2 to 6 so each watched SDK can have its own open bump PR at once.

Reviewed by Cursor Bugbot for commit 11163c9. Configure here.

Summary by CodeRabbit

  • Chores
    • Automated update pull requests are now grouped separately for each SDK. Updates for the same SDK across both configured locations are grouped together, and up to six update pull requests can remain open at a time. This replaces the previous setup, which combined the listed SDKs into one group and allowed up to two open pull requests.

Replace the provider-sdks group with group-by: dependency-name, so each
SDK gets its own PR that bumps both apps/desktop and apps/ade-cli. Raise
the open PR limit from 2 to 6, one for each watched SDK.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
ade Ignored Ignored Preview Oct 9, 2026 8:34pm UTC

@cursor

cursor Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: 56bd2fa1-43b1-48f4-9184-3b45a4df408f)

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: arul28/ADE/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 2a2c3349-627c-4ed3-a3ec-37e330f8a8ec

📥 Commits

Reviewing files that changed from the base of the PR and between 515dcc0 and 11163c9.


📒 Files selected for processing (1)
  • .github/dependabot.yml

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.



📝 Walkthrough

Walkthrough

Dependabot now creates separate update groups for each SDK by dependency name. Each group can include updates from both configured directories. The open-PR limit increases from two to six.

Changes

Dependabot SDK Updates

Layer / File(s) Summary
SDK update grouping
.github/dependabot.yml
Dependabot groups updates by dependency name across both configured directories. The open-PR limit increases from two to six.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Other

Suggested labels: ci


Merge Risk: ⚪ Minimal · up to 11163

The configuration supports the intended per-SDK updates across both app directories. No actionable mergeability risk was identified.

Pre-merge checks | Passed 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly describes the main change: Dependabot will create a separate PR for each provider SDK.
Docstring Coverage Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.


✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@arul28
arul28 merged commit c3e3686 into main Oct 10, 2026
42 checks passed
@arul28
arul28 deleted the ade/dependabot-pr-per-sdk branch October 10, 2026 20:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant