Skip to content

g1t/services/security/fixtures/dependabot/python_cpython.yml

144 lines3,420 bytesCodeBlameRaw
1# python/cpython's .github/dependabot.yml, as published.
2version: 2
3updates:
4 - package-ecosystem: "github-actions"
5 directory: "/"
6 schedule:
7 interval: "quarterly"
8 labels:
9 - "skip issue"
10 - "skip news"
11 groups:
12 actions:
13 patterns:
14 - "*"
15 cooldown:
16 # https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns
17 # Cooldowns protect against supply chain attacks by avoiding the
18 # highest-risk window immediately after new releases.
19 default-days: 14
20
21 - package-ecosystem: "pip"
22 directory: "/Tools/"
23 schedule:
24 interval: "quarterly"
25 labels: ["skip issue", "skip news"]
26 groups:
27 pip:
28 patterns: ["*"]
29 cooldown:
30 default-days: 14
31
32 # Release branches: Dependabot only reads this file from the default
33 # branch, so each branch that should get its own actions bumps needs an
34 # entry here with `target-branch`. Add one when a new release branch is
35 # created, and remove when the branch reaches end-of-life.
36 - package-ecosystem: "github-actions"
37 target-branch: "3.15"
38 directory: "/"
39 schedule:
40 interval: "quarterly"
41 labels: ["skip issue", "skip news"]
42 groups:
43 actions:
44 patterns: ["*"]
45 cooldown:
46 default-days: 14
47
48 - package-ecosystem: "github-actions"
49 target-branch: "3.14"
50 directory: "/"
51 schedule:
52 interval: "quarterly"
53 labels: ["skip issue", "skip news"]
54 groups:
55 actions:
56 patterns: ["*"]
57 cooldown:
58 default-days: 14
59
60 - package-ecosystem: "github-actions"
61 target-branch: "3.13"
62 directory: "/"
63 schedule:
64 interval: "quarterly"
65 labels: ["skip issue", "skip news"]
66 groups:
67 actions:
68 patterns: ["*"]
69 cooldown:
70 default-days: 14
71
72 - package-ecosystem: "github-actions"
73 target-branch: "3.12"
74 directory: "/"
75 schedule:
76 interval: "quarterly"
77 labels: ["skip issue", "skip news"]
78 groups:
79 actions:
80 patterns: ["*"]
81 cooldown:
82 default-days: 14
83
84 - package-ecosystem: "github-actions"
85 target-branch: "3.11"
86 directory: "/"
87 schedule:
88 interval: "quarterly"
89 labels: ["skip issue", "skip news"]
90 groups:
91 actions:
92 patterns: ["*"]
93 cooldown:
94 default-days: 14
95
96 - package-ecosystem: "github-actions"
97 target-branch: "3.10"
98 directory: "/"
99 schedule:
100 interval: "quarterly"
101 labels: ["skip issue", "skip news"]
102 groups:
103 actions:
104 patterns: ["*"]
105 cooldown:
106 default-days: 14
107
108 # Only bump bugfix branches for pip. Remove
109 # the entry when branch goes security-only.
110 - package-ecosystem: "pip"
111 target-branch: "3.15"
112 directory: "/Tools/"
113 schedule:
114 interval: "quarterly"
115 labels: ["skip issue", "skip news"]
116 groups:
117 pip:
118 patterns: ["*"]
119 cooldown:
120 default-days: 14
121
122 - package-ecosystem: "pip"
123 target-branch: "3.14"
124 directory: "/Tools/"
125 schedule:
126 interval: "quarterly"
127 labels: ["skip issue", "skip news"]
128 groups:
129 pip:
130 patterns: ["*"]
131 cooldown:
132 default-days: 14
133
134 - package-ecosystem: "pip"
135 target-branch: "3.13"
136 directory: "/Tools/"
137 schedule:
138 interval: "quarterly"
139 labels: ["skip issue", "skip news"]
140 groups:
141 pip:
142 patterns: ["*"]
143 cooldown:
144 default-days: 14