diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 00000000..37632e0a --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,28 @@ +# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file +version: 2 +updates: + # npm / pnpm dependencies (auto-detected via pnpm-lock.yaml) + - package-ecosystem: npm + directory: / + schedule: + interval: weekly + open-pull-requests-limit: 10 + commit-message: + prefix: chore + include: scope + groups: + # Bundle non-major updates so we don't get a flood of PRs + minor-and-patch: + update-types: + - minor + - patch + + # GitHub Actions used in .github/workflows/ + - package-ecosystem: github-actions + directory: / + schedule: + interval: weekly + open-pull-requests-limit: 5 + commit-message: + prefix: chore + include: scope