diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..01a55b0 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,13 @@ +# Dependency updates, once a month, grouped into one PR per ecosystem so the +# org's zero-open-PR steady state survives them. Security updates arrive as +# they are published regardless of the schedule. +version: 2 +updates: + - package-ecosystem: github-actions + directory: / + schedule: + interval: monthly + groups: + actions: + patterns: ["*"] + labels: [dependencies] diff --git a/CHANGELOG.md b/CHANGELOG.md index dc4be91..95900d0 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,11 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] +## [1.8.5] - 2026-09-16 + +### Added +- `.github/dependabot.yml`: monthly dependency updates, grouped into one PR per ecosystem (org audit E17). + ## [1.8.4] - 2026-08-03 ### Added diff --git a/VERSION b/VERSION index bfa363e..ff2fd4f 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -1.8.4 +1.8.5 \ No newline at end of file