Skip to content

Commit 1fb53fa

Browse files
author
MPCoreDeveloper
committed
chore(deps): reduce dependabot noise - weekly schedule, ignore reviewed gRPC 2.8.x alerts
1 parent c19630b commit 1fb53fa

1 file changed

Lines changed: 15 additions & 2 deletions

File tree

.github/dependabot.yml

Lines changed: 15 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,11 @@ updates:
33
- package-ecosystem: "nuget"
44
directory: "/"
55
schedule:
6-
interval: "daily"
6+
interval: "weekly"
7+
day: "monday"
78
time: "06:00"
89
timezone: "Europe/Amsterdam"
9-
open-pull-requests-limit: 20
10+
open-pull-requests-limit: 10
1011
labels:
1112
- "dependencies"
1213
- "nuget"
@@ -24,6 +25,18 @@ updates:
2425
serilog:
2526
patterns:
2627
- "Serilog*"
28+
ignore:
29+
# gRPC 2.8.x — reviewed, not affected by reported CVEs
30+
- dependency-name: "Grpc.Tools"
31+
versions: ["2.8.*"]
32+
- dependency-name: "Grpc.Core"
33+
versions: ["2.8.*"]
34+
- dependency-name: "Grpc.Net.Client"
35+
versions: ["2.8.*"]
36+
- dependency-name: "Grpc.AspNetCore"
37+
versions: ["2.8.*"]
38+
- dependency-name: "Grpc.Net.ClientFactory"
39+
versions: ["2.8.*"]
2740

2841
- package-ecosystem: "github-actions"
2942
directory: "/"

0 commit comments

Comments
 (0)