Skip to content

Commit 986aa45

Browse files
committed
fix: restrict Dependabot pip updates to security-only
The Dependabot config added in #517 included weekly version-bump PRs for all three pip packages. This would generate noisy PRs for routine dep updates we don't need. Set open-pull-requests-limit: 0 on the pip ecosystems so only CVE-triggered security updates open PRs. GitHub Actions weekly bumps are kept as-is to keep SHA pins current.
1 parent 54d51bd commit 986aa45

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

.github/dependabot.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,17 +10,20 @@ updates:
1010
directory: /packages/data-designer-config
1111
schedule:
1212
interval: weekly
13+
open-pull-requests-limit: 0
1314
commit-message:
1415
prefix: "chore"
1516
- package-ecosystem: pip
1617
directory: /packages/data-designer-engine
1718
schedule:
1819
interval: weekly
20+
open-pull-requests-limit: 0
1921
commit-message:
2022
prefix: "chore"
2123
- package-ecosystem: pip
2224
directory: /packages/data-designer
2325
schedule:
2426
interval: weekly
27+
open-pull-requests-limit: 0
2528
commit-message:
2629
prefix: "chore"

0 commit comments

Comments
 (0)