From 84e93fbf018757cf117c733420bea7b7b68f6f21 Mon Sep 17 00:00:00 2001 From: Benjamin Komen Date: Tue, 29 Sep 2026 10:13:10 -0700 Subject: [PATCH] Skip non-LTS Temurin majors in Dependabot. Ignore eclipse-temurin versions >=26,<29 and >=30,<33 in the docker ecosystem so the runtime image stays on Java LTS (25; next LTS 29). Patch/minor updates of 25 keep flowing. Note the policy in AGENTS.md. --- .github/dependabot.yml | 7 +++++++ AGENTS.md | 7 +++++++ 2 files changed, 14 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index f38b4e9..8349cbe 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -18,3 +18,10 @@ updates: interval: daily time: "04:00" open-pull-requests-limit: 5 + ignore: + # Stay on Java LTS: skip non-LTS Temurin majors (26-28, 30-32). + # Patch/minor updates of 25 and the next LTS (29, then 33) still come through. + - dependency-name: "eclipse-temurin" + versions: + - ">= 26, < 29" + - ">= 30, < 33" diff --git a/AGENTS.md b/AGENTS.md index 312bcaa..46ed1da 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -118,6 +118,13 @@ the user explicitly asks. Implementation: `RateLimitFilter` + `ClientIpKeyResolver` (IPv6 `/64`). Docs: README and `docker/README.md`. +## Dependabot + +`.github/dependabot.yml` ignores non-LTS `eclipse-temurin` majors (26–28, 30–32), +so the runtime image stays on Java LTS (25 now; 29 is the next LTS). Moving to a +new LTS is a deliberate change: Docker images, `java.toolchain`, Kotlin +`jvmTarget`, and `setup-java` `java-version` all have to change together. + ## PR / verify Before considering work done: