# Dependabot and compat entries for tests (and docs)

**URL:** <https://discourse.julialang.org/t/dependabot-and-compat-entries-for-tests-and-docs/138548>\
**Category:** Tooling\
**Tags:** question, pkg, compatibility\
**Created:** [July 31, 2026, 8:05am UTC](https://discourse.julialang.org/t/dependabot-and-compat-entries-for-tests-and-docs/138548 "2026-07-31T08:05:46Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [July 31, 2026, 8:05am UTC](https://discourse.julialang.org/t/dependabot-and-compat-entries-for-tests-and-docs/138548/1 "2026-07-31T08:05:46Z")

</div>

I have started using Dependabot in place of Compathelper for my packages.

It tries adding compat bounds for tests (and docs if applicable). I am wondering if this is good practice — yes, I can see the value in it, but at the same time it increases maintenance burden.

Also, can this feature of dependabot be disabled? I could not figure out how.

---

<div class="post-metadata">

**Author:** ![JoshuaLampert](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/joshualampert/32/205964_2.png) [@JoshuaLampert](https://discourse.julialang.org/u/JoshuaLampert)\
**Post date:** [July 31, 2026, 8:39am UTC](https://discourse.julialang.org/t/dependabot-and-compat-entries-for-tests-and-docs/138548/2 "2026-07-31T08:39:55Z")

</div>

You have told dependabot that you have julia projects in the root directory, in docs/ and in test/ using the `directories` keyword (see [here](https://github.com/tpapp/LogDensityProblemsAD.jl/blob/876cd8047f12f652ab680ddae313bd984b422579/.github/dependabot.yml#L11-L13)). If you don’t want compat updates for docs/ and test/ (and don’t use workspaces) you should be able to just remove those from `directories`. Most of this is explained in [PSA: GitHub Dependabot now supports Julia](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997).

---

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [July 31, 2026, 11:11am UTC](https://discourse.julialang.org/t/dependabot-and-compat-entries-for-tests-and-docs/138548/3 "2026-07-31T11:11:06Z")

</div>

Thanks, but I get the impression that _if_ I have `[workspace]`, then merely `/` in `directories:` makes dependabot submit PRs for subprojects.

What I (may) want is keep using workspaces, but not have dependabot submit PRs for subprojects.

(I see now that this is an [open question](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/15), haven’t seen this when I read this PSA last.)

---

<div class="post-metadata">

**Author:** ![JoshuaLampert](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/joshualampert/32/205964_2.png) [@JoshuaLampert](https://discourse.julialang.org/u/JoshuaLampert)\
**Post date:** [July 31, 2026, 11:15am UTC](https://discourse.julialang.org/t/dependabot-and-compat-entries-for-tests-and-docs/138548/4 "2026-07-31T11:15:52Z")

</div>

Yes, if you use workspaces it is probably not so easy, but I would say having correct compat bounds in test/ and docs/ is good practice anyway.

---

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [July 31, 2026, 1:57pm UTC](https://discourse.julialang.org/t/dependabot-and-compat-entries-for-tests-and-docs/138548/5 "2026-07-31T13:57:06Z")

</div>

> [@JoshuaLampert](#):
>
> if you use workspaces it is probably not so easy

I am now wondering if it is _possible_, easy or not.

---

<div class="post-metadata">

**Author:** ![nhz2](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/nhz2/32/44428_2.png) [@nhz2](https://discourse.julialang.org/u/nhz2)\
**Post date:** [July 31, 2026, 2:31pm UTC](https://discourse.julialang.org/t/dependabot-and-compat-entries-for-tests-and-docs/138548/6 "2026-07-31T14:31:54Z")

</div>

Check out [PSA: GitHub Dependabot now supports Julia - #16 by Eben60](https://discourse.julialang.org/t/psa-github-dependabot-now-supports-julia/134997/16) and the discussion in [Does it make sense to define compat bounds in the test/Project.toml?](https://discourse.julialang.org/t/does-it-make-sense-to-define-compat-bounds-in-the-test-project-toml/138466)
