| 1 | # supabase/supabase's .github/dependabot.yml, as published. |
| 2 | version: 2 |
| 3 | updates: |
| 4 | - package-ecosystem: 'github-actions' |
| 5 | directory: '/' |
| 6 | schedule: |
| 7 | interval: 'weekly' |
| 8 | cooldown: |
| 9 | default-days: 7 |
| 10 | # `pnpm-workspace.yaml`'s `minimumReleaseAge: 4320` (3 days) rejects any |
| 11 | # dependency version younger than 3 days old during `pnpm install`. Without |
| 12 | # a cooldown, Dependabot proposes the newest release the moment it's |
| 13 | # published, so its PRs are structurally guaranteed to fail CI/Vercel until |
| 14 | # the proposed version happens to age past the pnpm gate on its own. This |
| 15 | # cooldown holds Dependabot's proposals back until they've already cleared |
| 16 | # (with a one-day margin for scheduling/CI latency) pnpm's minimum release |
| 17 | # age, so the version pnpm sees is always old enough to be accepted. |
| 18 | - package-ecosystem: 'npm' |
| 19 | directories: |
| 20 | - '/' |
| 21 | - '/apps/*' |
| 22 | - '/packages/*' |
| 23 | - '/blocks/*' |
| 24 | - '/e2e/*' |
| 25 | schedule: |
| 26 | interval: 'weekly' |
| 27 | cooldown: |
| 28 | default-days: 4 |