From dbad7e510327b64de93d92f52c56756eac47cdd7 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 23 Sep 2026 05:46:19 +0000 Subject: [PATCH 1/3] Initial plan From bf2462b92f2f33f5633b6565053b3c7c3679a21f Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 23 Sep 2026 05:47:54 +0000 Subject: [PATCH 2/3] Add NuGet and workshop npm Dependabot updates Co-authored-by: justinyoo <1538528+justinyoo@users.noreply.github.com> --- .github/dependabot.yml | 37 +++++++++++++++++++++++++++++++++++++ 1 file changed, 37 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 2c48305..de019be 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -9,3 +9,40 @@ updates: interval: "weekly" cooldown: default-days: 7 + + # NuGet packages are centrally managed in Directory.Packages.props and use + # floating versions (for example "13.*" and "1.*-*"), so minor, patch and + # prerelease updates are already resolved at restore time and are ignored + # here. Dependabot only proposes major version bumps, which require the + # floating range itself to change. Dependabot rewrites a floating range to a + # resolved version when it opens a pull request, so review those pull + # requests and restore the floating notation (for example "14.*" or "2.*-*"). + - package-ecosystem: "nuget" + directories: + - "/" + - "/src/**" + - "/tests/**" + groups: + nuget: + patterns: ["*"] + ignore: + - dependency-name: "*" + update-types: + - "version-update:semver-minor" + - "version-update:semver-patch" + schedule: + interval: "weekly" + cooldown: + default-days: 7 + + # Workshop site dependencies and devDependencies in workshop/package.json. + # Dependabot keeps workshop/package-lock.json in sync with the manifest. + - package-ecosystem: "npm" + directory: "/workshop" + groups: + npm: + patterns: ["*"] + schedule: + interval: "weekly" + cooldown: + default-days: 7 From a0294d1ed63661e7ff47ba5c54f4b4b7fc4cb113 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 23 Sep 2026 05:48:18 +0000 Subject: [PATCH 3/3] Explain explicit NuGet project directories Co-authored-by: justinyoo <1538528+justinyoo@users.noreply.github.com> --- .github/dependabot.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index de019be..321c607 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -17,6 +17,8 @@ updates: # floating range itself to change. Dependabot rewrites a floating range to a # resolved version when it opens a pull request, so review those pull # requests and restore the floating notation (for example "14.*" or "2.*-*"). + # The project directories are listed explicitly because Dependabot does not + # discover projects through the .slnx solution file. - package-ecosystem: "nuget" directories: - "/"