diff --git a/.github/dependabot.yml b/.github/dependabot.yml index e5c4502..6028dd3 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -8,6 +8,16 @@ updates: day: "monday" open-pull-requests-limit: 10 labels: ["dependencies", "security"] + # Skip major bumps for test-infra dev deps that have known breaking + # changes between major versions. Re-enable when bandwidth opens to + # update the test suite for the new APIs. Decision: 2026-05-06, + # after #38 (pytest 8→9) and #40 (pytest-asyncio 0.24→1.3) failed + # tests with no urgency to upgrade. + ignore: + - dependency-name: "pytest" + update-types: ["version-update:semver-major"] + - dependency-name: "pytest-asyncio" + update-types: ["version-update:semver-major"] # Group patch + minor updates into a single PR per package-ecosystem. # Major bumps still get their own PR for human review. Mergify # batches the resulting PR group via .mergify.yml's "dependencies"