multi-scrobbler/.github/dependabot.yml
FoxxMD dadaa6df35 ci: reduce dependabot npm updates to security only
Version updates are too big and unhelpful
2026-04-09 14:35:51 +00:00

37 lines
No EOL
1.1 KiB
YAML

# To get started with Dependabot version updates, you'll need to specify which
# package ecosystems to update and where the package manifests are located.
# Please see the documentation for all configuration options:
# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file
version: 2
updates:
- package-ecosystem: "npm" # See documentation for possible values
groups:
sec-updates:
applies-to: "security-updates"
patterns:
- "*"
directories:
- "/"
- "/docsite"
schedule:
interval: "weekly"
- package-ecosystem: "docker"
# Look for a `Dockerfile` in the `root` directory
directory: "/"
# Check for updates once a week
schedule:
interval: "weekly"
- package-ecosystem: "github-actions"
directory: "/"
groups:
sec-updates:
applies-to: "security-updates"
patterns:
- "*"
version-updates:
applies-to: "version-updates"
patterns:
- "*"
schedule:
interval: "weekly"