g1t/services/security/fixtures/dependabot/microsoft_vscode.yml
Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 1 | # microsoft/vscode's .github/dependabot.yml, as published. |
| 2 | version: 2 | |
| 3 | updates: | |
| 4 | - package-ecosystem: "github-actions" | |
| 5 | directory: "/" | |
| 6 | schedule: | |
| 7 | interval: "weekly" | |
| 8 | cooldown: | |
| 9 | default-days: 7 | |
| 10 | - package-ecosystem: "devcontainers" # https://containers.dev/guide/dependabot | |
| 11 | directory: "/" | |
| 12 | schedule: | |
| 13 | interval: "weekly" | |
| 14 | - package-ecosystem: "npm" | |
| 15 | directory: "/extensions/markdown-language-features" | |
| 16 | schedule: | |
| 17 | interval: "daily" | |
| 18 | time: "16:00" | |
| 19 | timezone: "America/Los_Angeles" | |
| 20 | allow: | |
| 21 | - dependency-name: "@vscode/markdown-editor" |