diff --git a/.github/dependabot.yml b/.github/dependabot.yml index f38b4e9..8349cbe 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -18,3 +18,10 @@ updates: interval: daily time: "04:00" open-pull-requests-limit: 5 + ignore: + # Stay on Java LTS: skip non-LTS Temurin majors (26-28, 30-32). + # Patch/minor updates of 25 and the next LTS (29, then 33) still come through. + - dependency-name: "eclipse-temurin" + versions: + - ">= 26, < 29" + - ">= 30, < 33" diff --git a/AGENTS.md b/AGENTS.md index 312bcaa..46ed1da 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -118,6 +118,13 @@ the user explicitly asks. Implementation: `RateLimitFilter` + `ClientIpKeyResolver` (IPv6 `/64`). Docs: README and `docker/README.md`. +## Dependabot + +`.github/dependabot.yml` ignores non-LTS `eclipse-temurin` majors (26–28, 30–32), +so the runtime image stays on Java LTS (25 now; 29 is the next LTS). Moving to a +new LTS is a deliberate change: Docker images, `java.toolchain`, Kotlin +`jvmTarget`, and `setup-java` `java-version` all have to change together. + ## PR / verify Before considering work done: