the dependabot agent opened 40 separate PRs instead of grouping - the groups key was nested under the wrong key in...
Fixes dependabot update grouping when the groups key is nested at the wrong level in dependabot.yml: move it under the matching updates entry so related bumps collapse into grouped PRs. Use it when dependabot ignores grouping config and opens one PR per dependency. Key trigger: groups configured but dependabot still opens individual PRs.
TL;DR: Dependabot only honors groups when it sits inside the right updates entry - nested anywhere else, it is silently ignored and you get one PR per dependency. Move the groups block under the matching package-ecosystem entry, validate the file, and the next run groups them.
the dependabot agent opened 40 separate PRs instead of grouping - the groups key was nested under the wrong key in dependabot.ymlSteps
- Open dependabot.yml and find where you put
groups- the common mistake is top-level (next toversionandupdates) or under the wrong ecosystem entry.
Expected: you find it somewhere dependabot does not read.
- Move the
groupsblock so it is a child of theupdatesentry for the right package ecosystem:
updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
groups:
security-minor:
patterns:
- "*" Expected: groups is indented under the ecosystem entry, not at the file root.
- Validate the file - GitHub surfaces dependabot config errors under the repo's dependency graph Dependabot tab, or run a YAML linter to catch indentation slips.
Expected: no config errors reported.
- Wait for the next scheduled run (or trigger one) and count the PRs.
Expected: related bumps arrive as one grouped PR per group instead of 40 singles.
- Close the 40 stale singles (or let the grouped PR supersede them) so reviewers see one clean diff.
Expected: one grouped PR, no leftover duplicates.
Use this when
- Dependabot opens one PR per dependency despite a groups config
- Your groups block lives at the top level of dependabot.yml
- You copied a groups example into the wrong ecosystem section
- Grouping worked, then stopped after someone edited the file
Not for this skill when
- Dependabot is not running at all (no PRs, no errors) - that is a config or permissions problem, not a grouping problem
- You want grouping in renovate - renovate uses packageRules, a different config shape
- The PRs come from snyk or another tool alongside dependabot - dedupe the tools first
Variant phrasings
- dependabot groups not working, still opening separate PRs
- dependabot.yml groups key ignored
- how to group dependabot pull requests correctly
Why it happens
Dependabot's config schema only reads groups as a child of an updates entry - anywhere else it is unknown config and silently dropped, usually with no error and no warning. YAML makes the misnesting easy: one wrong indent level and the block is structurally somewhere else. The result looks like dependabot "ignoring" your config when it is really just not seeing it.
Edge cases
- Each ecosystem entry needs its own groups block - npm groups do not apply to the pip entry.
patterns: ["*"]groups everything including majors - pair it with exclude-patterns or update-types if majors should stay separate.- Security updates can group separately from version updates - check which update type your 40 PRs were before tuning patterns.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_QgoEbx6mtwpCH1x1i2eSGA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.