Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
69 changes: 26 additions & 43 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -1,63 +1,46 @@
# To get started with Dependabot version updates, you'll need to specify which
# package ecosystems to update and where the package manifests are located.
# Please see the documentation for all configuration options:
# https://docs.github.com/github/administering-a-repository/configuration-options-for-dependency-updates
# Combine all routine version updates, including major releases, into one PR.
# Add new ecosystems to this group so they share the same schedule.
# https://docs.github.com/en/code-security/how-tos/secure-your-supply-chain/secure-your-dependencies/configuring-multi-ecosystem-updates

version: 2
multi-ecosystem-groups:
dependencies:
schedule:
interval: "weekly"
day: "monday"
time: "09:00"
timezone: "America/Chicago"

updates:
- package-ecosystem: "cargo"
directory: "/rust"
cooldown:
default-days: 7
groups:
rust-dependencies:
update-types:
- "minor"
- "patch"
schedule:
interval: "weekly"
multi-ecosystem-group: "dependencies"
patterns:
- "*"
- package-ecosystem: "github-actions"
# The JavaScript workflows' composite actions live under .github/actions.
directories:
- "/"
- "/.github/actions/*"
schedule:
interval: "weekly"
multi-ecosystem-group: "dependencies"
patterns:
- "*"
- package-ecosystem: "gomod"
directories:
- "**/*"
groups:
go-dependencies:
update-types:
- "minor"
- "patch"
schedule:
interval: "weekly"
# Routine minor and patch updates to the JavaScript workspace arrive as one
# grouped pull request per dependency type; major updates stay separate so
# each can be reviewed on its own. Exact pins in package.json (Prisma, the
# TypeScript-next preview, pnpm overrides) stay exact because `increase`
# rewrites the pinned version rather than widening it.
multi-ecosystem-group: "dependencies"
patterns:
- "*"
# Exact pins in package.json (Prisma, the TypeScript-next preview, pnpm
# overrides) stay exact because `increase` rewrites the pinned version
# rather than widening it.
- package-ecosystem: "npm"
directory: "/js"
cooldown:
default-days: 7
groups:
development-dependencies:
dependency-type: "development"
patterns:
- "*"
update-types:
- "minor"
- "patch"
production-dependencies:
dependency-type: "production"
patterns:
- "*"
update-types:
- "minor"
- "patch"
open-pull-requests-limit: 10
schedule:
interval: "monthly"
multi-ecosystem-group: "dependencies"
patterns:
- "*"
versioning-strategy: increase
Loading