g1t/services/security/fixtures/dependabot/github_docs.yml
Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 1 | # github/docs's .github/dependabot.yml, as published. |
| 2 | version: 2 | |
| 3 | ||
| 4 | registries: | |
| 5 | ghcr: | |
| 6 | type: docker-registry | |
| 7 | url: ghcr.io | |
| 8 | username: PAT | |
| 9 | password: ${{secrets.BASE_CONTAINER_IMAGE_READER_DEPENDABOT}} | |
| 10 | ||
| 11 | updates: | |
| 12 | - package-ecosystem: npm | |
| 13 | directory: '/' | |
| 14 | schedule: | |
| 15 | interval: weekly | |
| 16 | day: tuesday | |
| 17 | cooldown: | |
| 18 | default-days: 7 | |
| 19 | ignore: | |
| 20 | # Keep the Elasticsearch client pinned to the server-compatible version. | |
| 21 | - dependency-name: '@elastic/elasticsearch' | |
| 22 | - dependency-name: '*' | |
| 23 | update-types: | |
| 24 | ['version-update:semver-patch', 'version-update:semver-minor'] | |
| 25 | ||
| 26 | - package-ecosystem: 'github-actions' | |
| 27 | directory: '/' | |
| 28 | schedule: | |
| 29 | interval: weekly | |
| 30 | day: tuesday | |
| 31 | cooldown: | |
| 32 | default-days: 7 | |
| 33 | groups: | |
| 34 | actions: | |
| 35 | patterns: | |
| 36 | - '*' | |
| 37 | ignore: | |
| 38 | - dependency-name: '*' | |
| 39 | update-types: | |
| 40 | ['version-update:semver-patch', 'version-update:semver-minor'] | |
| 41 | - dependency-name: 'github/internal-actions' | |
| 42 | ||
| 43 | - package-ecosystem: 'docker' | |
| 44 | registries: | |
| 45 | - ghcr | |
| 46 | directories: | |
| 47 | - '/' | |
| 48 | - '/.devcontainer' | |
| 49 | schedule: | |
| 50 | interval: daily | |
| 51 | cooldown: | |
| 52 | default-days: 7 | |
| 53 | groups: | |
| 54 | baseImages: | |
| 55 | patterns: | |
| 56 | - '*' | |
| 57 | ignore: | |
| 58 | - dependency-name: 'node' # Ignore Dockerfile.openapi_decorator's Node image. |