Skip to content
compiler.dev

Dependabot Setup That Doesn't Drown Your Team

Dependabot opens pull requests when your dependencies have new versions or security fixes. Left on defaults in a busy repository it produces a stream of small PRs that people learn to ignore, which defeats the purpose. This guide sets it up so updates arrive in a few batched PRs, security fixes stay fast, and low-risk updates merge themselves.

Two kinds of updates

  • Security updates are opened when a dependency has a known vulnerability (from the GitHub Advisory Database). You turn them on in repository settings under Advisories and Dependabot alerts. They are not controlled by the schedule in your config file.
  • Version updates are opened for new releases whether or not they have a vulnerability, according to dependabot.yml.

Treat them differently. Security updates should be reviewed and merged quickly. Version updates can be batched and slowed down.

A good starting config

Create .github/dependabot.yml:

version: 2
updates:
  - package-ecosystem: "npm"
    directory: "/"
    schedule:
      interval: "weekly"
      day: "monday"
      time: "06:00"
      timezone: "Europe/London"
    open-pull-requests-limit: 5
    groups:
      dev-dependencies:
        dependency-type: "development"
        update-types: ["minor", "patch"]
      production-minor-patch:
        dependency-type: "production"
        update-types: ["minor", "patch"]
    ignore:
      - dependency-name: "*"
        update-types: ["version-update:semver-major"]
    labels: ["dependencies"]
    commit-message:
      prefix: "chore(deps)"

  - package-ecosystem: "github-actions"
    directory: "/"
    schedule:
      interval: "monthly"
    groups:
      actions:
        patterns: ["*"]

Generate one for your stacks with the Dependabot config generator.

The five settings that cut noise

1. Schedule. weekly is a good default; monthly for slow-moving repos. Daily is rarely worth it. A fixed day and time means the PRs show up when people expect them.

2. Groups. Without grouping, 15 dev-dependency bumps are 15 PRs, 15 CI runs and 15 merges. With groups, they are one. Group by dependency type, by update type, or by name pattern (patterns: ["eslint", "@typescript-eslint/"]). Dependabot only groups updates of the same ecosystem and directory, and a group's PR is opened for the version updates that are due.

3. Ignore major versions by default. Majors usually need code changes. Ignore them in the config, then upgrade them deliberately as planned work. You can also ignore a specific dependency until you are ready:

ignore:
  - dependency-name: "react"
    versions: [">=19"]

4. Cooldown. The cooldown option delays a new release before Dependabot proposes it. Many malicious or broken releases are found and pulled within days, so a delay avoids most of them:

cooldown:
  default-days: 5
  semver-major-days: 30
  semver-minor-days: 7
  semver-patch-days: 3

Check the current Dependabot options reference for which ecosystems support cooldown, and note that security updates are not delayed by it.

5. Open PR limit. open-pull-requests-limit defaults to 5 for version updates. Lower it if your CI queue gets crowded. Setting it to 0 disables version updates for that entry (security updates are unaffected).

Keep CI cost down

Each Dependabot PR runs your full CI. Mitigate:

  • Group updates (above), so one run covers many bumps.
  • Use concurrency with cancel-in-progress so rebased PRs do not stack runs.
  • Run lighter checks on dependency PRs, for example only unit tests, and the heavy suite in the merge queue. See GitHub merge queue.
  • Schedule updates at a time when CI is idle.

Use the CI minutes forecaster to see what 20 extra PRs a week cost.

Auto-merge the safe ones

Auto-merge patch and minor updates of dev dependencies when CI passes. A workflow using dependabot/fetch-metadata reads the update type:

name: dependabot-auto-merge
on: pull_request
permissions:
  contents: write
  pull-requests: write
jobs:
  auto:
    if: github.actor == 'dependabot[bot]'
    runs-on: ubuntu-latest
    steps:
      - id: meta
        uses: dependabot/fetch-metadata@v2
        with:
          github-token: ${{ secrets.GITHUB_TOKEN }}
      - if: steps.meta.outputs.update-type != 'version-update:semver-major'
        run: gh pr merge --auto --squash "$PR_URL"
        env:
          PR_URL: ${{ github.event.pull_request.html_url }}
          GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}

This only merges after required checks pass, so branch protection and good tests are what make it safe. Turn on "Allow auto-merge" in repository settings. Pin dependabot/fetch-metadata to a SHA, as described in securing GitHub Actions. Never auto-merge anything that touches production dependencies without test coverage you trust.

Keep GitHub Actions pinned and updated

Add the github-actions ecosystem as shown above. Dependabot updates both tag-style and SHA-pinned references; with SHA pins it keeps the trailing # v3.5.2 comment accurate. This is how you can pin by SHA without the maintenance burden.

Routing and ownership

PRs need an owner or nobody looks at them. Instead of the deprecated reviewers and assignees options in dependabot.yml, use CODEOWNERS so a team is requested for review, and use labels to filter. Rotate the "dependency owner" role weekly and keep a short rule: merge green patch updates the same day; schedule majors.

Monorepos and multiple directories

Dependabot needs one updates entry per ecosystem and directory. For many directories, use directories (a list or glob) to avoid repeating the block:

- package-ecosystem: "npm"
  directories: ["/", "/apps/*", "/packages/*"]
  schedule:
    interval: "weekly"

Groups then collect updates across those directories where the same dependency is bumped. Check your version of the Dependabot docs for how multi-directory groups are formed.

FAQ

How many Dependabot PRs is too many?

If PRs sit open for more than a week, you have too many. Tighten the schedule, group more and cut ignored ecosystems.

Does Dependabot cost money?

Dependabot itself is free. Its PRs run your CI, so they use Actions minutes.

Should I use Renovate instead?

Renovate has more configuration options and works across platforms. Dependabot is built into GitHub and needs no hosting. Both support grouping and scheduling; choose by the features you need.

Can I silence an update for a while?

Yes, comment @dependabot ignore this minor version or use ignore entries. Or use cooldown to slow everything down.

Faster CI makes dependency PRs cheaper to process: compiler.dev's comparison mode shows what your test workflow costs on faster runners, which is useful when you receive many automated PRs.

Made by compiler.dev. Free tools · Pricing