Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 1 | # supabase/supabase's .github/dependabot.yml, as published. |
| 2 | version: 2 | |
| 3 | updates: | |
| 4 | - package-ecosystem: 'github-actions' | |
| 5 | directory: '/' | |
| 6 | schedule: | |
| 7 | interval: 'weekly' | |
| 8 | cooldown: | |
| 9 | default-days: 7 | |
| 10 | # `pnpm-workspace.yaml`'s `minimumReleaseAge: 4320` (3 days) rejects any | |
| 11 | # dependency version younger than 3 days old during `pnpm install`. Without | |
| 12 | # a cooldown, Dependabot proposes the newest release the moment it's | |
| 13 | # published, so its PRs are structurally guaranteed to fail CI/Vercel until | |
| 14 | # the proposed version happens to age past the pnpm gate on its own. This | |
| 15 | # cooldown holds Dependabot's proposals back until they've already cleared | |
| 16 | # (with a one-day margin for scheduling/CI latency) pnpm's minimum release | |
| 17 | # age, so the version pnpm sees is always old enough to be accepted. | |
| 18 | - package-ecosystem: 'npm' | |
| 19 | directories: | |
| 20 | - '/' | |
| 21 | - '/apps/*' | |
| 22 | - '/packages/*' | |
| 23 | - '/blocks/*' | |
| 24 | - '/e2e/*' | |
| 25 | schedule: | |
| 26 | interval: 'weekly' | |
| 27 | cooldown: | |
| 28 | default-days: 4 |