Skip to content

g1t/services/security/fixtures/dependabot/apache_airflow.yml

463 lines13,206 bytesCodeBlame
1# apache/airflow's .github/dependabot.yml, as published.
2# Licensed to the Apache Software Foundation (ASF) under one
3# or more contributor license agreements. See the NOTICE file
4# distributed with this work for additional information
5# regarding copyright ownership. The ASF licenses this file
6# to you under the Apache License, Version 2.0 (the
7# "License"); you may not use this file except in compliance
8# with the License. You may obtain a copy of the License at
9#
10# http://www.apache.org/licenses/LICENSE-2.0
11#
12# Unless required by applicable law or agreed to in writing,
13# software distributed under the License is distributed on an
14# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
15# KIND, either express or implied. See the License for the
16# specific language governing permissions and limitations
17# under the License
18---
19# NOTE: a group applies to version updates unless it declares `applies-to: security-updates`.
20# Every entry below that targets the default branch therefore carries a matching
21# `*-security-updates` group, so alert-driven bumps arrive batched instead of one PR per
22# dependency. Entries using `target-branch` deliberately have no such group - Dependabot raises
23# security updates against the default branch only, so it would never match anything there.
24version: 2
25updates:
26 - package-ecosystem: "github-actions"
27 directory: "/"
28 cooldown:
29 default-days: 4
30 schedule:
31 # Check for updates to GitHub Actions every week
32 interval: "weekly"
33 groups:
34 github-actions-updates:
35 patterns:
36 - "*"
37 github-actions-security-updates:
38 applies-to: security-updates
39 patterns:
40 - "*"
41
42 - package-ecosystem: "github-actions"
43 directory: "/"
44 cooldown:
45 default-days: 4
46 schedule:
47 # Check for updates to GitHub Actions every week
48 interval: "weekly"
49 target-branch: v3-4-test
50 # Paused while v3-4-test is fast-forwarded to main for the 3.4.0 betas - remove when the
51 # 3.4.0 RCs start (see "Beta releases" in dev/README_RELEASE_AIRFLOW.md).
52 open-pull-requests-limit: 0
53 groups:
54 github-actions-updates:
55 patterns:
56 - "*"
57
58 - package-ecosystem: pip
59 cooldown:
60 default-days: 4
61 directories:
62 - /airflow-core
63 - /airflow-ctl
64 - /clients/python
65 - /dev/breeze
66 - /docker-tests
67 - /kubernetes-tests
68 - /chart
69 - /task-sdk
70 - /
71 schedule:
72 interval: daily
73 groups:
74 pip-dependency-updates:
75 patterns:
76 - "*"
77 pip-security-updates:
78 applies-to: security-updates
79 patterns:
80 - "*"
81
82 - package-ecosystem: gradle
83 directories:
84 - /java-sdk
85 - /java-sdk/example
86 - /java-sdk/scala_spark_example
87 cooldown:
88 default-days: 14
89 schedule:
90 interval: weekly
91 groups:
92 java-sdk-dependency-updates:
93 patterns:
94 - "*"
95 update-types:
96 - minor
97 - patch
98 java-sdk-security-updates:
99 applies-to: security-updates
100 patterns:
101 - "*"
102 ignore:
103 - dependency-name: "*"
104 update-types:
105 - version-update:semver-major
106 # Pinned to the last release that supports Java 11. Ignore minor/patch
107 # bumps too, not just majors, until the SDK's Java 11 support requirement
108 # is dropped. See also: java-sdk/sdk/build.gradle.kts
109 - dependency-name: "com.gradleup.shadow:shadow-gradle-plugin"
110 update-types:
111 - version-update:semver-minor
112 - version-update:semver-patch
113 - dependency-name: "org.jsonschema2pojo"
114 update-types:
115 - version-update:semver-minor
116 - version-update:semver-patch
117
118 - package-ecosystem: npm
119 cooldown:
120 default-days: 4
121 directories:
122 - /airflow-core/src/airflow/ui
123 schedule:
124 interval: "weekly"
125 groups:
126 react:
127 patterns:
128 - "react"
129 - "react-dom"
130 - "@types/react"
131 - "@types/react-dom"
132 chakra-ui:
133 patterns:
134 - "@chakra-ui/*"
135 - "@emotion/*"
136 - "framer-motion"
137 eslint:
138 patterns:
139 - "eslint*"
140 - "@eslint/*"
141 typescript:
142 patterns:
143 - "typescript*"
144 - "@typescript-eslint/*"
145 - "@types/typescript"
146 core-ui-package-updates:
147 patterns:
148 - "*"
149 update-types:
150 - "minor"
151 - "patch"
152 core-ui-security-updates:
153 patterns:
154 - "*"
155 applies-to: security-updates
156
157 - package-ecosystem: npm
158 cooldown:
159 default-days: 4
160 directories:
161 - /airflow-core/src/airflow/api_fastapi/auth/managers/simple/ui
162 schedule:
163 interval: "weekly"
164 groups:
165 auth-ui-package-updates:
166 patterns:
167 - "*"
168 update-types:
169 - "minor"
170 - "patch"
171 auth-ui-security-updates:
172 patterns:
173 - "*"
174 applies-to: security-updates
175
176 - package-ecosystem: npm
177 cooldown:
178 default-days: 4
179 directories:
180 - /dev/react-plugin-tools/react_plugin_template
181 schedule:
182 interval: "weekly"
183 groups:
184 ui-plugin-template-package-updates:
185 patterns:
186 - "*"
187 update-types:
188 - "minor"
189 - "patch"
190 ui-plugin-template-security-updates:
191 patterns:
192 - "*"
193 applies-to: security-updates
194 ignore:
195 - dependency-name: "*"
196 update-types: ["version-update:semver-major"]
197
198 - package-ecosystem: npm
199 cooldown:
200 default-days: 4
201 directories:
202 - /providers/edge3/src/airflow/providers/edge3/plugins/www
203 schedule:
204 interval: "weekly"
205 groups:
206 edge-ui-package-updates:
207 patterns:
208 - "*"
209 update-types:
210 - "minor"
211 - "patch"
212 edge-ui-security-updates:
213 patterns:
214 - "*"
215 applies-to: security-updates
216 ignore:
217 - dependency-name: "*"
218 update-types: ["version-update:semver-major"]
219
220 - package-ecosystem: npm
221 cooldown:
222 default-days: 4
223 directories:
224 - /providers/fab/src/airflow/providers/fab/www
225 schedule:
226 interval: daily
227 groups:
228 fab-ui-package-updates:
229 patterns:
230 - "*"
231 fab-ui-security-updates:
232 patterns:
233 - "*"
234 applies-to: security-updates
235
236 - package-ecosystem: npm
237 cooldown:
238 default-days: 4
239 directories:
240 - /registry
241 schedule:
242 interval: "weekly"
243 groups:
244 registry-package-updates:
245 patterns:
246 - "*"
247 update-types:
248 - "minor"
249 - "patch"
250 registry-security-updates:
251 patterns:
252 - "*"
253 applies-to: security-updates
254
255 # Repeat dependency updates on v3-4-test branch as well
256 - package-ecosystem: pip
257 cooldown:
258 default-days: 4
259 directories:
260 - /airflow-core
261 - /airflow-ctl
262 - /clients/python
263 - /dev/breeze
264 - /docker-tests
265 - /kubernetes-tests
266 - /chart
267 - /task-sdk
268 - /
269 schedule:
270 interval: daily
271 target-branch: v3-4-test
272 # Paused while v3-4-test is fast-forwarded to main for the 3.4.0 betas - remove when the
273 # 3.4.0 RCs start (see "Beta releases" in dev/README_RELEASE_AIRFLOW.md).
274 open-pull-requests-limit: 0
275 groups:
276 pip-dependency-updates:
277 patterns:
278 - "*"
279
280 - package-ecosystem: npm
281 cooldown:
282 default-days: 4
283 directories:
284 - /airflow-core/src/airflow/ui
285 schedule:
286 interval: "weekly"
287 target-branch: v3-4-test
288 # Paused while v3-4-test is fast-forwarded to main for the 3.4.0 betas - remove when the
289 # 3.4.0 RCs start (see "Beta releases" in dev/README_RELEASE_AIRFLOW.md).
290 open-pull-requests-limit: 0
291 groups:
292 3-4-core-ui-package-updates:
293 patterns:
294 - "*"
295 update-types:
296 - "minor"
297 - "patch"
298 ignore:
299 - dependency-name: "*"
300 update-types: ["version-update:semver-major"]
301
302 - package-ecosystem: npm
303 cooldown:
304 default-days: 4
305 directories:
306 - /airflow-core/src/airflow/api_fastapi/auth/managers/simple/ui
307 schedule:
308 interval: "weekly"
309 target-branch: v3-4-test
310 # Paused while v3-4-test is fast-forwarded to main for the 3.4.0 betas - remove when the
311 # 3.4.0 RCs start (see "Beta releases" in dev/README_RELEASE_AIRFLOW.md).
312 open-pull-requests-limit: 0
313 groups:
314 3-4-auth-ui-package-updates:
315 patterns:
316 - "*"
317 update-types:
318 - "minor"
319 - "patch"
320 ignore:
321 - dependency-name: "*"
322 update-types: ["version-update:semver-major"]
323
324 # The remaining non-provider directories are mirrored onto v3-4-test as well. Dependabot raises
325 # security updates against the default branch only, so a fixed version reaches the maintenance
326 # branch through its own version updates - Dependabot resolves and regenerates the lock file on
327 # that branch, which a cherry-picked lock file diff from main cannot do. Majors stay ignored, so
328 # a fix that needs a major bump still has to be backported by hand.
329 #
330 # Provider directories (providers/*) are deliberately NOT mirrored onto v3-4-test: providers are
331 # released from main, so their dependencies on a maintenance branch never ship to users and the
332 # PRs are pure review noise.
333 - package-ecosystem: npm
334 cooldown:
335 default-days: 4
336 directories:
337 - /registry
338 schedule:
339 interval: "weekly"
340 target-branch: v3-4-test
341 # Paused while v3-4-test is fast-forwarded to main for the 3.4.0 betas - remove when the
342 # 3.4.0 RCs start (see "Beta releases" in dev/README_RELEASE_AIRFLOW.md).
343 open-pull-requests-limit: 0
344 groups:
345 3-4-registry-package-updates:
346 patterns:
347 - "*"
348 update-types:
349 - "minor"
350 - "patch"
351 ignore:
352 - dependency-name: "*"
353 update-types: ["version-update:semver-major"]
354
355 - package-ecosystem: npm
356 cooldown:
357 default-days: 4
358 directories:
359 - /dev/react-plugin-tools/react_plugin_template
360 schedule:
361 interval: "weekly"
362 target-branch: v3-4-test
363 # Paused while v3-4-test is fast-forwarded to main for the 3.4.0 betas - remove when the
364 # 3.4.0 RCs start (see "Beta releases" in dev/README_RELEASE_AIRFLOW.md).
365 open-pull-requests-limit: 0
366 groups:
367 3-4-ui-plugin-template-package-updates:
368 patterns:
369 - "*"
370 update-types:
371 - "minor"
372 - "patch"
373 ignore:
374 - dependency-name: "*"
375 update-types: ["version-update:semver-major"]
376
377 - package-ecosystem: "uv"
378 cooldown:
379 default-days: 4
380 directory: "/dev/breeze"
381 schedule:
382 interval: "weekly"
383 target-branch: v3-4-test
384 # Paused while v3-4-test is fast-forwarded to main for the 3.4.0 betas - remove when the
385 # 3.4.0 RCs start (see "Beta releases" in dev/README_RELEASE_AIRFLOW.md).
386 open-pull-requests-limit: 0
387 groups:
388 3-4-uv-dependency-updates:
389 patterns:
390 - "*"
391 update-types:
392 - "minor"
393 - "patch"
394 ignore:
395 - dependency-name: "*"
396 update-types: ["version-update:semver-major"]
397
398 - package-ecosystem: npm
399 cooldown:
400 default-days: 7
401 directory: /ts-sdk
402 schedule:
403 interval: "weekly"
404 groups:
405 ts-sdk-package-updates:
406 patterns:
407 - "*"
408 update-types:
409 - "minor"
410 - "patch"
411 ts-sdk-security-updates:
412 applies-to: security-updates
413 patterns:
414 - "*"
415
416 - package-ecosystem: "uv"
417 cooldown:
418 default-days: 4
419 directory: "/dev/breeze"
420 schedule:
421 interval: "weekly"
422 groups:
423 uv-dependency-updates:
424 patterns:
425 - "*"
426 uv-security-updates:
427 patterns:
428 - "*"
429 applies-to: security-updates
430
431 # Go modules resolve straight to upstream repositories: there is no central registry
432 # (unlike PyPI/npm) that pre-scans a release, and whoever controls a module's namespace
433 # can publish a version at any time. To keep an unreviewed upstream Go release from being
434 # auto-merged into our dev/CI chain, we do NOT raise automatic version-update PRs here
435 # (`open-pull-requests-limit: 0`); routine Go bumps are done manually. We still accept
436 # advisory-driven security updates, which require a published GHSA advisory and so cannot
437 # be triggered by an upstream release self-declaring itself a "security" fix.
438 - package-ecosystem: "gomod"
439 cooldown:
440 default-days: 14
441 directory: "/go-sdk"
442 schedule:
443 interval: "weekly"
444 open-pull-requests-limit: 0
445 groups:
446 go-sdk-security-updates:
447 patterns:
448 - "*"
449 applies-to: security-updates
450
451 - package-ecosystem: "gomod"
452 cooldown:
453 default-days: 14
454 directory: "/go-sdk"
455 schedule:
456 interval: "weekly"
457 target-branch: v3-4-test
458 open-pull-requests-limit: 0
459 groups:
460 3-4-go-sdk-security-updates:
461 patterns:
462 - "*"
463 applies-to: security-updates