Skip to content

Conversation

cluse-heartflow
Copy link
Contributor

Clarify behavior of 'increase-if-necessary' option in Dependabot.

Why:

Originally I misread this. I thought this setting would make Dependabot ignore minor versions. I didn't understand that with this setting enabled, Dependabot will still make a PR, but it will only update the lockfile, not the package.json.

Closes:

What's being changed (if available, include any code snippets, screenshots, or gifs):

Just changing the description of the increase-if-necessary option for Dependabot so that it is more obvious that this does not cause Dependabot to ignore minor versions.

Check off the following:

  • A subject matter expert (SME) has reviewed the technical accuracy of the content in this PR. In most cases, the author can be the SME. Open source contributions may require an SME review from GitHub staff.
  • The changes in this PR meet the docs fundamentals that are required for all content.
  • All CI checks are passing and the changes look good in the review environment.

Clarify behavior of 'increase-if-necessary' option in Dependabot.
@Copilot Copilot AI review requested due to automatic review settings September 23, 2025 23:50
Copy link

welcome bot commented Sep 23, 2025

Thanks for opening this pull request! A GitHub docs team member should be by to give feedback soon. In the meantime, please check out the contributing guidelines.

Copy link
Contributor

@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR clarifies the description of the increase-if-necessary option in the Dependabot versioning strategy documentation to better explain its behavior with manifest and lockfile updates.

Key Changes:

  • Expands the description of the increase-if-necessary versioning strategy option to clearly explain when Dependabot updates manifest files vs. lockfiles only

@github-actions github-actions bot added the triage Do not begin working on this issue until triaged by the team label Sep 23, 2025
Copy link
Contributor

github-actions bot commented Sep 23, 2025

How to review these changes 👓

Thank you for your contribution. To review these changes, choose one of the following options:

A Hubber will need to deploy your changes internally to review.

Table of review links

Note: Please update the URL for your staging server or codespace.

The table shows the files in the content directory that were changed in this pull request. This helps you review your changes on a staging server. Changes to the data directory are not included in this table.

Source Review Production What Changed
code-security/dependabot/working-with-dependabot/dependabot-options-reference.md fpt
ghec
ghes@ 3.17 3.16 3.15 3.14
fpt
ghec
ghes@ 3.17 3.16 3.15 3.14

Key: fpt: Free, Pro, Team; ghec: GitHub Enterprise Cloud; ghes: GitHub Enterprise Server

🤖 This comment is automatically generated.

@Sharra-writes
Copy link
Contributor

Sharra-writes commented Sep 25, 2025

@cluse-heartflow Thanks for opening a PR! This wording definitely looks opaque as-is. I checked with the Dependabot team, and they proposed this wording to be more concise:

Leave the version requirement unchanged if it already allows the new release (Dependabot still updates the resolved version). Otherwise widen the requirement.

Do you think this is clearer, or is there a change you would like to make for better clarity? We're trying to keep it short since it appears in a table and we don't want a big block of text. That's unfortunately also a barrier to understanding. We could probably make it a little longer than this, though.

@cluse-heartflow
Copy link
Contributor Author

Sure, sounds good to me.

@Sharra-writes Sharra-writes added content This issue or pull request belongs to the Docs Content team dependabot Content related to Dependabot and removed triage Do not begin working on this issue until triaged by the team labels Sep 25, 2025
@Sharra-writes Sharra-writes added the needs SME This proposal needs review from a subject matter expert label Sep 25, 2025
@Sharra-writes Sharra-writes added this pull request to the merge queue Sep 25, 2025
Copy link
Contributor

Thanks for opening a pull request! We've triaged this issue for technical review by a subject matter expert 👀

Merged via the queue into github:main with commit 5d6faf0 Sep 25, 2025
50 checks passed
Copy link
Contributor

Thanks very much for contributing! Your pull request has been merged 🎉 You should see your changes appear on the site in approximately 24 hours. If you're looking for your next contribution, check out our help wanted issues

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
content This issue or pull request belongs to the Docs Content team dependabot Content related to Dependabot needs SME This proposal needs review from a subject matter expert
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants