g1t/services/security/fixtures/dependabot/argoproj_argo-cd.yml
Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 1 | # argoproj/argo-cd's .github/dependabot.yml, as published. |
| 2 | version: 2 | |
| 3 | updates: | |
| 4 | - package-ecosystem: "gomod" | |
| 5 | directory: "/" | |
| 6 | schedule: | |
| 7 | interval: "daily" | |
| 8 | open-pull-requests-limit: 20 | |
| 9 | ignore: | |
| 10 | - dependency-name: k8s.io/* | |
| 11 | groups: | |
| 12 | aws-sdk-v2: | |
| 13 | patterns: | |
| 14 | - "github.com/aws/aws-sdk-go-v2*" | |
| 15 | otel: | |
| 16 | patterns: | |
| 17 | - "go.opentelemetry.io/*" | |
| 18 | golang-x: | |
| 19 | patterns: | |
| 20 | - "golang.org/x/*" | |
| 21 | ||
| 22 | - package-ecosystem: "github-actions" | |
| 23 | directory: "/" | |
| 24 | schedule: | |
| 25 | interval: "weekly" | |
| 26 | day: "monday" | |
| 27 | ignore: | |
| 28 | # Renovate manages its own action, together with it's pinned docker image version. | |
| 29 | # So whenever they are updated they both going to land in the same PR. | |
| 30 | # See renovate-presets/devtool.json5. | |
| 31 | - dependency-name: "renovatebot/github-action" | |
| 32 | groups: | |
| 33 | github-actions: | |
| 34 | patterns: | |
| 35 | - "*" | |
| 36 | ||
| 37 | - package-ecosystem: "npm" | |
| 38 | directory: "/ui/" | |
| 39 | schedule: | |
| 40 | interval: "daily" | |
| 41 | groups: | |
| 42 | # react-dom throws at runtime unless react is the exact same version. | |
| 43 | react: | |
| 44 | patterns: | |
| 45 | - "react" | |
| 46 | - "react-dom" | |
| 47 | - "@types/react" | |
| 48 | - "@types/react-dom" |