inspector/.github/dependabot.yml at main · MCPJam/inspector · GitHub
https://github.com/MCPJam/inspector/blob/main/.github/dependabot.yml • 282 KB fetched
Open original page
inspector/.github/dependabot.yml at main · MCPJam/inspector · GitHub
Skip to content
Navigation Menu
Sign in Appearance settings
* Platform
* AI CODE CREATION
* GitHub Copilot Write better code with AI
* GitHub Copilot app Direct agents from issue to merge
* MCP Registry Integrate external tools
* DEVELOPER WORKFLOWS
* Actions Automate any workflow
* Codespaces Instant dev environments
* Issues Plan and track work
* Code Review Manage code changes
* Code Quality Enforce quality at merge
* APPLICATION SECURITY
* GitHub Advanced Security Find and fix vulnerabilities
* Code security Secure your code as you build
* Secret protection Stop leaks before they start
* EXPLORE
* Why GitHub
* Documentation
* Blog
* Changelog
* Marketplace
View all features
* Solutions
* BY COMPANY SIZE
* Enterprises
* Small and medium teams
* Startups
* Nonprofits
* BY USE CASE
* App Modernization
* DevSecOps
* DevOps
* CI/CD
* View all use cases
* BY INDUSTRY
* Healthcare
* Financial services
* Manufacturing
* Government
* View all industries
View all solutions
* Resources
* EXPLORE BY TOPIC
* AI
* Software Development
* DevOps
* Security
* View all topics
* EXPLORE BY TYPE
* Customer stories
* Events & webinars
* Ebooks & reports
* Business insights
* GitHub Skills
* SUPPORT & SERVICES
* Documentation
* Customer support
* Community forum
* Trust center
* Partners
View all resources
* Open Source
* COMMUNITY
* GitHub Sponsors Fund open source developers
* PROGRAMS
* Security Lab
* Maintainer Community
* GitHub Stars
* Archive Program
* REPOSITORIES
* Topics
* Trending
* Collections
* Enterprise
* ENTERPRISE SOLUTIONS
* Enterprise platform AI-powered developer platform
* AVAILABLE ADD-ONS
* GitHub Advanced Security Enterprise-grade security features
* Copilot for Business Enterprise-grade AI features
* Premium Support Enterprise-grade 24/7 support
* Pricing
Search /
Sign in
Sign up Appearance settings
You signed in with another tab or window. Reload to refresh your session.
You signed out in another tab or window. Reload to refresh your session.
You switched accounts on another tab or window. Reload to refresh your session.
Dismiss alert
Uh oh!
There was an error while loading. Please reload this page .
MCPJam
/
inspector
Public
*
Uh oh!
There was an error while loading. Please reload this page .
*
Notifications
You must be signed in to change notification settings
*
Fork
277
*
Star
2.2k
*
Code
*
Issues
52
*
Pull requests
241
*
Discussions
*
Actions
*
Projects
*
Security and quality
1
*
Insights
Additional navigation options
*
Code
*
Issues
*
Pull requests
*
Discussions
*
Actions
*
Projects
*
Security and quality
*
Insights
Files Expand file tree
main
Breadcrumbs
* inspector
* / .github
/ dependabot.yml
Copy path
Blame
More file actions
Blame
More file actions
Latest commit
History
History
History
131 lines (128 loc) · 5.44 KB
main
Breadcrumbs
* inspector
* / .github
/ dependabot.yml
Copy path
Top
File metadata and controls
* Code
* Blame
131 lines (128 loc) · 5.44 KB
Raw
Copy raw file
Download raw file
Open symbols panel Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
# Dependabot configuration.
#
# Why this file exists: before it landed, this repo raised alerts but never
# acted on them. Dependabot security updates were off and no config existed,
# so a critical protobufjs RCE advisory sat open for 124 days (2026-04-16 →
# 2026-08-18) and was cleared only because a human happened to look. Alerts
# without update PRs are a reporting system, not a remediation one.
#
# Grouping is load-bearing, not cosmetic. There are ~400 open alerts; turning
# security updates on WITHOUT groups opens a PR per advisory, and a flood of
# several hundred PRs gets ignored in exactly the way the alerts did.
version: 2
updates:
# --------------------------------------------------------------- workspace
- package-ecosystem: npm
directories:
- "/"
# Standalone: has its own committed manifest + lockfile and is NOT a root
# npm workspace, so the workspace entry above does not cover it.
- "/mcpjam-inspector/test-servers/mcp-check-fixture"
schedule:
interval: weekly
open-pull-requests-limit: 10
groups:
# The desktop packaging chain gets its own groups. dependabot-auto-merge
# holds any PR that TOUCHES electron/sharp/@electron*, so leaving these
# packages inside the general groups holds the entire group hostage: the
# first weekly sync's 29-update dev group (#4558) was held for one
# packaging package while 28 auto-mergeable bumps sat behind it. Carving
# them out keeps the hold blast radius to exactly the packages it is for.
desktop-packaging:
applies-to: version-updates
patterns: ["electron", "sharp", "@electron/*", "@electron-forge/*"]
update-types: [minor, patch]
desktop-packaging-security:
applies-to: security-updates
patterns: ["electron", "sharp", "@electron/*", "@electron-forge/*"]
# @xmldom/xmldom is pre-1.0, where a "minor" is allowed to break —
# and 0.8 → 0.9 does: `ErrorHandlerFunction` no longer accepts
# `warning`, and its `Document` no longer structurally matches the
# DOM one. Dependabot classifies that as `semver-minor`, so it landed
# inside the production group and took 34 unrelated bumps down with
# it (#4556 failed every check on three type errors in
# sdk/src/xaa/mint/saml.ts and sdk/src/openai-readiness/package/
# svg-xml-node.ts). Its own group keeps one breaking 0.x bump from
# gating the group that carries the security-relevant updates.
# DELETE this carve-out once the 0.9 migration lands.
xmldom:
applies-to: version-updates
patterns: ["@xmldom/xmldom"]
xmldom-security:
applies-to: security-updates
patterns: ["@xmldom/xmldom"]
production-dependencies:
applies-to: version-updates
dependency-type: production
update-types: [minor, patch]
exclude-patterns:
[
"electron",
"sharp",
"@electron/*",
"@electron-forge/*",
"@xmldom/xmldom",
]
development-dependencies:
applies-to: version-updates
dependency-type: development
update-types: [minor, patch]
exclude-patterns:
["electron", "sharp", "@electron/*", "@electron-forge/*"]
# Security updates group separately so an advisory PR is never queued
# behind a routine version bump.
security-production:
applies-to: security-updates
dependency-type: production
exclude-patterns:
[
"electron",
"sharp",
"@electron/*",
"@electron-forge/*",
"@xmldom/xmldom",
]
security-development:
applies-to: security-updates
dependency-type: development
exclude-patterns:
["electron", "sharp", "@electron/*", "@electron-forge/*"]
# Deliberately NO `ignore` rules for electron / sharp majors. `ignore`
# suppresses SECURITY updates as well as version updates, so such a rule
# would have hidden the Electron 37 → 43 bump (#4081) that cleared 31
# advisories. Those packages are held back from AUTO-MERGE instead — see
# dependabot-auto-merge.yml — so a human reads them, never so they vanish.
# ------------------------------------------------------------ example apps
# Each example ships its own lockfile, so each is a separate Dependabot
# target. Together they are ~70% of open-alert volume while shipping nothing
# to users, which is why extracting them to a public examples repo is under
# discussion. Keep this block contiguous so it deletes in one cut.
- package-ecosystem: npm
directories:
- "/examples/conformance/basic"
- "/examples/evals/asana"
- "/examples/evals/brightdata"
- "/examples/mcp-apps/express-react-template"
- "/examples/mcp-apps/flashcards-supabase"
- "/examples/mcp-apps/reservation-app"
- "/examples/mcp-apps/sip-cocktails"
schedule:
interval: weekly
open-pull-requests-limit: 5
groups:
example-dependencies:
applies-to: version-updates
patterns: ["*"]
update-types: [minor, patch]
example-security:
applies-to: security-updates
patterns: ["*"]
# --------------------------------------------------------- GitHub Actions
- package-ecosystem: github-actions
directory: "/"
schedule:
interval: weekly
open-pull-requests-limit: 5
groups:
github-actions:
patterns: ["*"]
Footer
(c) 2026 GitHub, Inc.
Footer navigation
*
Terms
*
Privacy
*
Security
*
Status
*
Community
*
Docs
*
Contact
*
Manage cookies
*
Do not share my personal information
You can’t perform that action at this time.
Links found on this page
- Skip to content [direct]
- Sign in [direct]
- GitHub Copilot Write better code with AI [direct]
- GitHub Copilot app Direct agents from issue to merge [direct]
- MCP Registry Integrate external tools [direct]
- Actions Automate any workflow [direct]
- Codespaces Instant dev environments [direct]
- Issues Plan and track work [direct]
- Code Review Manage code changes [direct]
- Code Quality Enforce quality at merge [direct]
- GitHub Advanced Security Find and fix vulnerabilities [direct]
- Code security Secure your code as you build [direct]
- Secret protection Stop leaks before they start [direct]
- Why GitHub [direct]
- Documentation [direct]
- Blog [direct]
- Changelog [direct]
- Marketplace [direct]
- View all features [direct]
- Enterprises [direct]
- Small and medium teams [direct]
- Startups [direct]
- Nonprofits [direct]
- App Modernization [direct]
- DevSecOps [direct]
- DevOps [direct]
- CI/CD [direct]
- View all use cases [direct]
- Healthcare [direct]
- Financial services [direct]
- Manufacturing [direct]
- Government [direct]
- View all industries [direct]
- View all solutions [direct]
- AI [direct]
- Software Development [direct]
- DevOps [direct]
- Security [direct]
- View all topics [direct]
- Customer stories [direct]
- Events & webinars [direct]
- Ebooks & reports [direct]
- Business insights [direct]
- GitHub Skills [direct]
- Customer support [direct]
- Community forum [direct]
- Trust center [direct]
- Partners [direct]
- View all resources [direct]
- GitHub Sponsors Fund open source developers [direct]
- Security Lab [direct]
- Maintainer Community [direct]
- GitHub Stars [direct]
- Archive Program [direct]
- Topics [direct]
- Trending [direct]
- Collections [direct]
- Copilot for Business Enterprise-grade AI features [direct]
- Premium Support Enterprise-grade 24/7 support [direct]
- Pricing [direct]
- Sign up [direct]
- MCPJam [direct]
- inspector [direct]
- Notifications [direct]
- Issues
52 [direct]
- Pull requests
241 [direct]
- Discussions [direct]
- Actions [direct]
- Projects [direct]
- Security and quality
1 [direct]
- Insights [direct]
- inspector [direct]
- .github [direct]
- History [direct]
- Raw [direct]
- Terms [direct]
- Privacy [direct]
- Security [direct]
- Status [direct]
- Community [direct]