Skip to content

Commit 6406934

Browse files
add initial dependabot configuration
1 parent 4deaa0d commit 6406934

1 file changed

Lines changed: 74 additions & 0 deletions

File tree

.github/dependabot.yml

Lines changed: 74 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,74 @@
1+
# See the documentation for all configuration options:
2+
# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file
3+
4+
version: 2
5+
updates:
6+
#
7+
# Check for minor/patch versions only on a weekly basis - we are likely to be able to
8+
# merge these routinely. Major versions we'll check for and update manually.
9+
#
10+
- package-ecosystem: 'npm'
11+
directory: '/'
12+
versioning-strategy: increase
13+
schedule:
14+
# interval: 'weekly'
15+
# day: 'friday'
16+
# time: '03:00'
17+
interval: 'daily'
18+
time: '12:05'
19+
timezone: Europe/London
20+
commit-message:
21+
prefix: 'chore (deps): '
22+
ignore:
23+
# we'll do any major version updates manually
24+
- dependency-name: '*'
25+
update-types: ['version-update:semver-major']
26+
# packages we can't currently update
27+
# see issue #2214 for rationale for each of these
28+
- dependency-name: '@xmldom/xmldom'
29+
versions: [ '>=0.9.0' ]
30+
- dependnecy-name: 'bcryptjs'
31+
versions: [ '>=3.0.0' ]
32+
- dependency-name: 'bootstrap'
33+
versions: [ '>=5.0.0' ]
34+
- dependency-name: 'bson'
35+
versions: [ '>=5.0.0' ]
36+
- dependency-name: 'cbor'
37+
versions: [ '>=10.0.0' ]
38+
- dependency-name: 'cspell'
39+
versions: [ '>=9.0.0' ]
40+
- dependency-name: 'eslint'
41+
versions: [ '>=10.0.0' ]
42+
- dependency-name: 'eslint-plugin-jsdoc'
43+
versions: [ '>=51.0.0' ]
44+
- dependency-name: 'fernet'
45+
versions: [ '>=0.4.0' ]
46+
- dependency-name: 'geodesy'
47+
versions: [ '>=2.0.0' ]
48+
- dependency-name: 'otpauth'
49+
versions: [ '>=9.4.0' ]
50+
- dependency-name: 'webpack-dev-server'
51+
versions: [ '>=5.1.0' ]
52+
groups:
53+
#
54+
# Grouping so we don't get a seperate PR for every patch version.
55+
#
56+
patch-updates:
57+
applies-to: version-updates
58+
patterns:
59+
- '*'
60+
update-types:
61+
- 'patch'
62+
63+
- package-ecosystem: "github-actions"
64+
# Workflow files stored in the default location of `.github/workflows`; no need to
65+
# specify `/.github/workflows` for `directory`
66+
directory: '/'
67+
versioning-strategy: increase
68+
schedule:
69+
interval: 'weekly'
70+
day: 'friday'
71+
time: '03:00'
72+
timezone: Europe/London
73+
commit-message:
74+
prefix: 'chore (deps): '

0 commit comments

Comments
 (0)