Version updates in Dependabot have until now arrived one pull request at a time. That model adds review overhead, and it makes it easy for linked dependencies — Storybook, Angular and the AWS SDK are the common examples — to drift apart because they cannot be bumped in lockstep. The general availability release of grouped version updates changes that: related dependencies can now move together in a single pull request, which cuts workflow overhead, lowers the chance of breaking changes and removes much of the reason teams reached for third-party tooling or manual workarounds in the first place.

I’ve been testing the grouped Dependabot updates and just wanted to say it is awesome! Grouping functionality and configuration are exactly what we want.
- Nick Gibson, Causeway Capital Management

Declaring groups in dependabot.yml

Grouping is configured through the groups key in dependabot.yml. Each group starts with a name, which Dependabot uses in pull request titles and branch names. From there, you decide what belongs in the group and what must never be swept into it.

To pull dependencies in, the available options are:

  • dependency-type — include dependencies of a given type, either development or production.
  • patterns — strings that match one or more dependency names to include.
  • update-type — group by semantic versioning level (in 1.2.3 terms, major.minor.patch) so every update of the same level lands in one group.

To keep a dependency out, use exclude-patterns, which matches dependency names by string. Excluded dependencies keep the old behaviour: Dependabot raises individual pull requests to move them to their latest version.

One constraint applies — groups can only be created for version updates.

Grouping by dependency-type

Here “production” and “development” dependencies share a group, with anything matching rubocop* held back:

# `dependabot.yml` file using the `dependency-type` option to group updates
# in conjunction with `patterns` and `exclude-patterns`.

groups:
  production-dependencies:
    dependency-type: "production"
  development-dependencies:
    dependency-type: "development"
    exclude-patterns:
    - "rubocop*"
  rubocop:
    patterns:
    - "rubocop*"

Grouping by patterns

A group named dev-dependencies updates bundler ecosystem dependencies on a weekly schedule:

# `dependabot.yml` file with customized bundler configuration
# In this example, the name of the group is `dev-dependencies`, and
# only the `patterns` and `exclude-patterns` options are used.
version: 2
updates:
  # Keep bundler dependencies up to date
  - package-ecosystem: "bundler"
    directory: "/"
    schedule:
      interval: "weekly"
    # Create a group of dependencies to be updated together in one pull request
    groups:
       # Specify a name for the group, which will be used in pull request titles
       # and branch names
       dev-dependencies:
          # Define patterns to include dependencies in the group (based on
          # dependency name)
          patterns:
            - "rubocop" # A single dependency name
            - "rspec*"  # A wildcard string that matches multiple dependency names
            - "*"       # A wildcard that matches all dependencies in the package
                        # ecosystem. Note: using "*" may open a large pull request
          # Define patterns to exclude dependencies from the group (based on
          # dependency name)
          exclude-patterns:
            - "gc_ruboconfig"
            - "gocardless-*"

Grouping by update-type

groups:
  angular:
    patterns: 
    - "@angular*"
    update-types:
    - "minor"
    - "patch"
ignore:
  - dependency-name: "@angular*"
    update-types: ["version-update:semver-major"]

Access and further reading

Anyone with repository permissions can set up Dependabot groups for that repository.