g1t/services/security/fixtures/dependabot/every-option.yml
Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 1 | # Every option of the format, written once, for the parser's tests. |
| 2 | version: 2 | |
| 3 | enable-beta-ecosystems: false | |
| 4 | ||
| 5 | registries: | |
| 6 | npm-acme: | |
| 7 | type: npm-registry | |
| 8 | url: https://npm.acme.dev | |
| 9 | token: ${{secrets.ACME_NPM_TOKEN}} | |
| 10 | replaces-base: true | |
| 11 | scope: "@acme" | |
| 12 | crates-acme: | |
| 13 | type: cargo-registry | |
| 14 | url: https://cargo.acme.dev/index | |
| 15 | token: ${{ secrets.ACME_CARGO_TOKEN }} | |
| 16 | pypi-acme: | |
| 17 | type: python-index | |
| 18 | url: https://pypi.acme.dev/simple | |
| 19 | username: ci | |
| 20 | password: ${{secrets.ACME_PYPI_PASSWORD}} | |
| 21 | goproxy-acme: | |
| 22 | type: goproxy-server | |
| 23 | url: https://go.acme.dev | |
| 24 | username: ci | |
| 25 | password: ${{secrets.ACME_GO_PASSWORD}} | |
| 26 | ecr: | |
| 27 | type: docker-registry | |
| 28 | url: https://123456789012.dkr.ecr.us-east-1.amazonaws.com | |
| 29 | username: ${{secrets.ECR_ACCESS_KEY_ID}} | |
| 30 | password: ${{secrets.ECR_SECRET_ACCESS_KEY}} | |
| 31 | artifactory: | |
| 32 | type: maven-repository | |
| 33 | url: https://acme.jfrog.io/artifactory/maven | |
| 34 | jfrog-oidc-provider-name: acme | |
| 35 | identity-mapping-name: dependabot | |
| 36 | audience: jfrog | |
| 37 | hex: | |
| 38 | type: hex-organization | |
| 39 | organization: acme | |
| 40 | key: ${{secrets.HEX_KEY}} | |
| 41 | ||
| 42 | multi-ecosystem-groups: | |
| 43 | infrastructure: | |
| 44 | schedule: | |
| 45 | interval: weekly | |
| 46 | day: wednesday | |
| 47 | time: "06:00" | |
| 48 | timezone: UTC | |
| 49 | labels: [infrastructure] | |
| 50 | assignees: [platform-lead] | |
| 51 | milestone: 2 | |
| 52 | commit-message: | |
| 53 | prefix: infra | |
| 54 | pull-request-branch-name: | |
| 55 | separator: "-" | |
| 56 | open-pull-requests-limit: 3 | |
| 57 | ||
| 58 | updates: | |
| 59 | - package-ecosystem: npm | |
| 60 | directories: | |
| 61 | - "/" | |
| 62 | - "/apps/*" | |
| 63 | - "/packages/**" | |
| 64 | schedule: | |
| 65 | interval: weekly | |
| 66 | day: tuesday | |
| 67 | time: "09:30" | |
| 68 | timezone: America/New_York | |
| 69 | allow: | |
| 70 | - dependency-type: production | |
| 71 | - dependency-name: "@acme/*" | |
| 72 | update-types: ["version-update:semver-minor", "version-update:semver-patch"] | |
| 73 | ignore: | |
| 74 | - dependency-name: react | |
| 75 | versions: [">=19.0.0"] | |
| 76 | - dependency-name: "*" | |
| 77 | update-types: ["version-update:semver-major"] | |
| 78 | - dependency-name: left-pad | |
| 79 | groups: | |
| 80 | lint: | |
| 81 | patterns: ["eslint*", "@typescript-eslint/*", "prettier"] | |
| 82 | exclude-patterns: ["eslint-plugin-legacy"] | |
| 83 | update-types: [minor, patch] | |
| 84 | dependency-type: development | |
| 85 | security-fixes: | |
| 86 | applies-to: security-updates | |
| 87 | patterns: ["*"] | |
| 88 | shared: | |
| 89 | patterns: ["@acme/*"] | |
| 90 | group-by: dependency-name | |
| 91 | cooldown: | |
| 92 | default-days: 5 | |
| 93 | semver-major-days: 30 | |
| 94 | semver-minor-days: 7 | |
| 95 | semver-patch-days: 0 | |
| 96 | include: ["*"] | |
| 97 | exclude: ["@acme/*"] | |
| 98 | assignees: [ana] | |
| 99 | reviewers: [ben, acme/frontend] | |
| 100 | labels: [dependencies, javascript] | |
| 101 | milestone: 4 | |
| 102 | commit-message: | |
| 103 | prefix: build | |
| 104 | prefix-development: chore | |
| 105 | include: scope | |
| 106 | open-pull-requests-limit: 10 | |
| 107 | pull-request-branch-name: | |
| 108 | separator: "/" | |
| 109 | prefix: deps | |
| 110 | max-length: 120 | |
| 111 | word-separator: "-" | |
| 112 | branch-name-case: lowercase | |
| 113 | template: "{prefix}/{package_manager}/{directory}/{name}" | |
| 114 | rebase-strategy: auto | |
| 115 | target-branch: main | |
| 116 | versioning-strategy: increase-if-necessary | |
| 117 | insecure-external-code-execution: deny | |
| 118 | exclude-paths: ["vendor/**", "src/test/assets", "**/*.snap"] | |
| 119 | registries: [npm-acme] | |
| 120 | name: Web dependencies | |
| 121 | ||
| 122 | - package-ecosystem: cargo | |
| 123 | directory: "/" | |
| 124 | schedule: | |
| 125 | interval: monthly | |
| 126 | versioning-strategy: lockfile-only | |
| 127 | registries: [crates-acme] | |
| 128 | open-pull-requests-limit: 0 | |
| 129 | ||
| 130 | - package-ecosystem: gomod | |
| 131 | directory: /tools | |
| 132 | schedule: | |
| 133 | interval: cron | |
| 134 | cronjob: "every weekday at 6am" | |
| 135 | timezone: Europe/London | |
| 136 | vendor: true | |
| 137 | allow: | |
| 138 | - dependency-type: all | |
| 139 | registries: [goproxy-acme] | |
| 140 | ||
| 141 | - package-ecosystem: pip | |
| 142 | directory: / | |
| 143 | schedule: | |
| 144 | interval: quarterly | |
| 145 | insecure-external-code-execution: allow | |
| 146 | registries: "*" | |
| 147 | rebase-strategy: disabled | |
| 148 | ||
| 149 | - package-ecosystem: docker | |
| 150 | directory: / | |
| 151 | patterns: ["nginx", "redis"] | |
| 152 | multi-ecosystem-group: infrastructure | |
| 153 | registries: [ecr] | |
| 154 | ||
| 155 | - package-ecosystem: terraform | |
| 156 | directory: /infra | |
| 157 | patterns: ["*"] | |
| 158 | multi-ecosystem-group: infrastructure | |
| 159 | ||
| 160 | - package-ecosystem: github-actions | |
| 161 | directory: / | |
| 162 | schedule: | |
| 163 | interval: semiannually | |
| 164 | groups: | |
| 165 | actions: | |
| 166 | patterns: ["*"] | |
| 167 | ||
| 168 | - package-ecosystem: maven | |
| 169 | directory: /java | |
| 170 | schedule: | |
| 171 | interval: yearly | |
| 172 | registries: [artifactory] | |
| 173 | ||
| 174 | - package-ecosystem: mix | |
| 175 | directory: /elixir | |
| 176 | schedule: | |
| 177 | interval: daily | |
| 178 | registries: [hex] |