Skip to content

g1t/services/security/fixtures/dependabot/github_docs.yml

58 lines1,374 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar1# github/docs's .github/dependabot.yml, as published.
2version: 2
3
4registries:
5 ghcr:
6 type: docker-registry
7 url: ghcr.io
8 username: PAT
9 password: ${{secrets.BASE_CONTAINER_IMAGE_READER_DEPENDABOT}}
10
11updates:
12 - package-ecosystem: npm
13 directory: '/'
14 schedule:
15 interval: weekly
16 day: tuesday
17 cooldown:
18 default-days: 7
19 ignore:
20 # Keep the Elasticsearch client pinned to the server-compatible version.
21 - dependency-name: '@elastic/elasticsearch'
22 - dependency-name: '*'
23 update-types:
24 ['version-update:semver-patch', 'version-update:semver-minor']
25
26 - package-ecosystem: 'github-actions'
27 directory: '/'
28 schedule:
29 interval: weekly
30 day: tuesday
31 cooldown:
32 default-days: 7
33 groups:
34 actions:
35 patterns:
36 - '*'
37 ignore:
38 - dependency-name: '*'
39 update-types:
40 ['version-update:semver-patch', 'version-update:semver-minor']
41 - dependency-name: 'github/internal-actions'
42
43 - package-ecosystem: 'docker'
44 registries:
45 - ghcr
46 directories:
47 - '/'
48 - '/.devcontainer'
49 schedule:
50 interval: daily
51 cooldown:
52 default-days: 7
53 groups:
54 baseImages:
55 patterns:
56 - '*'
57 ignore:
58 - dependency-name: 'node' # Ignore Dockerfile.openapi_decorator's Node image.