version: 2 updates: # Runtime dependencies. Grouped so a quiet week produces one PR, not five. - package-ecosystem: pip directory: "/" schedule: interval: weekly day: monday open-pull-requests-limit: 5 groups: python-deps: patterns: ["*"] ignore: # mcp 2.x removed mcp.server.fastmcp (FastMCP -> MCPServer). Verified against # mcp 2.2.0: the import raises ModuleNotFoundError. 2.x stays out until the # server is ported; 1.x updates still come through. # An explicit version range, not update-types: the semver-major rule did not # stop Dependabot from widening "<2" to "<3" (PRs #15, #16, #17). The docs do # not say whether update-types applies to requirement widening; a range does. - dependency-name: mcp versions: [">=2"] commit-message: prefix: deps # Action versions. These are pinned by tag and go stale silently. - package-ecosystem: github-actions directory: "/" schedule: interval: weekly day: monday open-pull-requests-limit: 3 groups: actions: patterns: ["*"] commit-message: prefix: ci