g1t/services/security/fixtures/dependabot/aws_aws-cdk.yml
Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 1 | # aws/aws-cdk's .github/dependabot.yml, as published. |
| 2 | # Reference: https://docs.github.com/en/github/administering-a-repository/configuration-options-for-dependency-updates | |
| 3 | # NOTE: dependabot only takes care of updating non-npm deps | |
| 4 | # npm dependencies are updated through the "yarn-upgrade" github workflow. | |
| 5 | ||
| 6 | version: 2 | |
| 7 | updates: | |
| 8 | - package-ecosystem: "github-actions" | |
| 9 | directory: "/" | |
| 10 | schedule: | |
| 11 | interval: "weekly" | |
| 12 | labels: | |
| 13 | - "auto-approve" | |
| 14 | open-pull-requests-limit: 5 |