g1t/services/security/fixtures/dependabot/cloudflare_workers-sdk.yml
Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 1 | # cloudflare/workers-sdk's .github/dependabot.yml, as published. |
| 2 | version: 2 | |
| 3 | updates: | |
| 4 | # Automatically check for updates in framework CLIs for C3 | |
| 5 | - package-ecosystem: "npm" | |
| 6 | open-pull-requests-limit: 10 | |
| 7 | directory: "/packages/create-cloudflare/src/frameworks" | |
| 8 | schedule: | |
| 9 | interval: "weekly" | |
| 10 | # Don't run these at midday on Mondays, when we are busy trying to land PRs | |
| 11 | day: "sunday" | |
| 12 | time: "06:00" | |
| 13 | versioning-strategy: increase | |
| 14 | # Match the 24h minimumReleaseAge enforced by pnpm in pnpm-workspace.yaml | |
| 15 | # so Dependabot doesn't open PRs that CI will then reject. | |
| 16 | cooldown: | |
| 17 | default-days: 1 | |
| 18 | # the following is used to add the [C3] prefix to the PR title, | |
| 19 | # we override the commit message but setting a prefix like this | |
| 20 | # makes it so that also the PR title gets such prefix | |
| 21 | commit-message: | |
| 22 | prefix: "[C3] " | |
| 23 | labels: | |
| 24 | - "package:c3" | |
| 25 | - "dependencies" | |
| 26 | - "ci:skip-pr-description-validation" | |
| 27 | ||
| 28 | # Check for workerd & workers-types updates for Miniflare | |
| 29 | - package-ecosystem: "npm" | |
| 30 | # If you restrict the update to a directory that is not the root | |
| 31 | # then it will not update the pnpm-lock.yaml. | |
| 32 | directory: "/" | |
| 33 | groups: | |
| 34 | # We want to keep workerd and workers-types updates in lock-step | |
| 35 | workerd-and-workers-types: | |
| 36 | patterns: | |
| 37 | - "workerd" | |
| 38 | - "@cloudflare/workers-types" | |
| 39 | schedule: | |
| 40 | interval: "daily" | |
| 41 | time: "06:00" | |
| 42 | # These packages are published by Cloudflare and can be updated immediately. | |
| 43 | cooldown: | |
| 44 | exclude: | |
| 45 | - "workerd" | |
| 46 | - "@cloudflare/workers-types" | |
| 47 | versioning-strategy: increase | |
| 48 | labels: | |
| 49 | - "package:miniflare" | |
| 50 | - "dependencies" | |
| 51 | - "ci:skip-pr-description-validation" | |
| 52 | allow: | |
| 53 | - dependency-name: "workerd" | |
| 54 | - dependency-name: "@cloudflare/workers-types" |