TL;DR: Dependabot only honors `groups` when it sits inside the right `updates` entry - nested anywhere else, it is silently ignored and you get one PR per dependency. Move the groups block under the matching package-ecosystem entry, validate the file, and the next run groups them.

```text
the dependabot agent opened 40 separate PRs instead of grouping - the groups key was nested under the wrong key in dependabot.yml
```

## Steps

1. Open dependabot.yml and find where you put `groups` - the common mistake is top-level (next to `version` and `updates`) or under the wrong ecosystem entry.
   Expected: you find it somewhere dependabot does not read.
2. Move the `groups` block so it is a child of the `updates` entry for the right package ecosystem:
```yaml
updates:
  - package-ecosystem: "npm"
    directory: "/"
    schedule:
      interval: "weekly"
    groups:
      security-minor:
        patterns:
          - "*"
```
   Expected: `groups` is indented under the ecosystem entry, not at the file root.
3. Validate the file - GitHub surfaces dependabot config errors under the repo's dependency graph Dependabot tab, or run a YAML linter to catch indentation slips.
   Expected: no config errors reported.
4. Wait for the next scheduled run (or trigger one) and count the PRs.
   Expected: related bumps arrive as one grouped PR per group instead of 40 singles.
5. Close the 40 stale singles (or let the grouped PR supersede them) so reviewers see one clean diff.
   Expected: one grouped PR, no leftover duplicates.

## Use this when

- Dependabot opens one PR per dependency despite a groups config
- Your groups block lives at the top level of dependabot.yml
- You copied a groups example into the wrong ecosystem section
- Grouping worked, then stopped after someone edited the file

## Not for this skill when

- Dependabot is not running at all (no PRs, no errors) - that is a config or permissions problem, not a grouping problem
- You want grouping in renovate - renovate uses packageRules, a different config shape
- The PRs come from snyk or another tool alongside dependabot - dedupe the tools first

## Variant phrasings

- dependabot groups not working, still opening separate PRs
- dependabot.yml groups key ignored
- how to group dependabot pull requests correctly

## Why it happens

Dependabot's config schema only reads `groups` as a child of an `updates` entry - anywhere else it is unknown config and silently dropped, usually with no error and no warning. YAML makes the misnesting easy: one wrong indent level and the block is structurally somewhere else. The result looks like dependabot "ignoring" your config when it is really just not seeing it.

## Edge cases

- Each ecosystem entry needs its own groups block - npm groups do not apply to the pip entry.
- `patterns: ["*"]` groups everything including majors - pair it with exclude-patterns or update-types if majors should stay separate.
- Security updates can group separately from version updates - check which update type your 40 PRs were before tuning patterns.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_QgoEbx6mtwpCH1x1i2eSGA
