-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdependabot.yml
More file actions
30 lines (29 loc) · 1.11 KB
/
Copy pathdependabot.yml
File metadata and controls
30 lines (29 loc) · 1.11 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
# Dependabot configuration for automatic dependency updates
# See: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file
version: 2
updates:
# Update GitHub Actions versions
# This keeps your workflow actions secure and up-to-date
- package-ecosystem: "github-actions"
directory: "/"
schedule:
# Check for updates monthly (less noisy than weekly)
interval: "monthly"
labels:
- "dependencies"
- "github-actions"
# Group all GitHub Actions updates into a single PR
# This reduces PR noise and makes reviewing easier
groups:
github-actions:
patterns:
- "*"
# Automatically add reviewers (optional - uncomment and customize)
# reviewers:
# - "your-username"
# Limit how many Dependabot PRs can be open at once (optional)
# Default is 5, increase if you want more concurrent PRs
# open-pull-requests-limit: 10
#
# Note: Auto-merge is configured in GitHub repo settings, not here.
# Go to: Settings → General → Pull Requests → Allow auto-merge