Skip to content

Commit e766691

Browse files
committed
Enable Dependabot for dependency security scanning
Enables automated PRs for dependency updates and security vulnerabilities. Will catch issues like Mako CVE-2026-44307. References: #1812 Change-Id: I852513232af7251cd2056843f1d9c7b5635efaab
1 parent 4d1e38c commit e766691

1 file changed

Lines changed: 36 additions & 0 deletions

File tree

.github/dependabot.yml

Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
# Dependabot configuration for Alembic
2+
# Automatically creates PRs for dependency updates and security vulnerabilities
3+
4+
version: 2
5+
updates:
6+
# Python dependencies
7+
- package-ecosystem: "pip"
8+
directory: "/"
9+
schedule:
10+
interval: "daily"
11+
# Create PRs for both security updates and version updates
12+
open-pull-requests-limit: 10
13+
labels:
14+
- "dependencies"
15+
- "python"
16+
# Group all patch updates together to reduce noise
17+
groups:
18+
patch-updates:
19+
patterns:
20+
- "*"
21+
update-types:
22+
- "patch"
23+
# Allow both minor and major version updates
24+
allow:
25+
- dependency-type: "direct"
26+
- dependency-type: "indirect"
27+
28+
# GitHub Actions dependencies
29+
- package-ecosystem: "github-actions"
30+
directory: "/"
31+
schedule:
32+
interval: "weekly"
33+
day: "monday"
34+
labels:
35+
- "dependencies"
36+
- "github-actions"

0 commit comments

Comments
 (0)