Problem
Dependabot currently omits target-branch: dev for both configured ecosystems, so grouped updates #730 and #731 target stale main contrary to repository workflow. Their CI then fails because versioned workflow/dependency pins move without the repository contract-test assertions, and the Python group does not update uv.lock.
SemVer
Patch-level dependency/tooling maintenance within the unreleased v2.5 line. No public API break is authorized.
Acceptance
Problem
Dependabot currently omits
target-branch: devfor both configured ecosystems, so grouped updates #730 and #731 target stalemaincontrary to repository workflow. Their CI then fails because versioned workflow/dependency pins move without the repository contract-test assertions, and the Python group does not updateuv.lock.SemVer
Patch-level dependency/tooling maintenance within the unreleased v2.5 line. No public API break is authorized.
Acceptance
dev;dev;uv.lock;origin/dev;