From 4452f5f3e8946ee5cb587c9805eeec46d8d3d7fd Mon Sep 17 00:00:00 2001 From: "claude[bot]" <41898282+claude[bot]@users.noreply.github.com> Date: Sat, 18 Apr 2026 18:47:15 +0000 Subject: [PATCH] fix: set npm open-pull-requests-limit to 0 for security-only policy Per dependabot policy, application ecosystems (npm) should suppress routine version-update PRs by setting open-pull-requests-limit to 0. Dependabot security updates bypass this limit, so security PRs still get created. The github-actions ecosystem correctly retains limit 10. Closes #173 Co-authored-by: don-petry --- .github/dependabot.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 5f3e228d..fca64956 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -4,7 +4,7 @@ updates: directory: '/' schedule: interval: 'weekly' - open-pull-requests-limit: 10 + open-pull-requests-limit: 0 labels: - 'security' - 'dependencies'