diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..09ffe12 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,58 @@ +version: 2 +updates: + - package-ecosystem: "nuget" + directory: "/" + schedule: + interval: "daily" + open-pull-requests-limit: 5 + reviewers: + - "auth0/dx-sdks-approver" + assignees: + - "auth0/dx-sdks-approver" + commit-message: + prefix: "chore(deps)" + include: "scope" + labels: + - "dependencies" + - "nuget" + + - package-ecosystem: "npm" + directory: "/" + schedule: + interval: "daily" + open-pull-requests-limit: 3 + reviewers: + - "auth0/dx-sdks-approver" + assignees: + - "auth0/dx-sdks-approver" + commit-message: + prefix: "chore(deps)" + include: "scope" + labels: + - "dependencies" + - "npm" + # Only security updates for npm since they're dev dependencies + # for build scripts and not critical for library functionality + allow: + - dependency-type: "direct" + update-type: "version-update:semver-patch" + - dependency-type: "direct" + update-type: "version-update:semver-minor" + - dependency-type: "indirect" + update-type: "security-update" + + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "daily" + open-pull-requests-limit: 3 + reviewers: + - "auth0/dx-sdks-approver" + assignees: + - "auth0/dx-sdks-approver" + commit-message: + prefix: "chore(deps)" + include: "scope" + labels: + - "dependencies" + - "github-actions"