Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 28 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file
version: 2
updates:
# npm / pnpm dependencies (auto-detected via pnpm-lock.yaml)
- package-ecosystem: npm
directory: /
schedule:
interval: weekly
open-pull-requests-limit: 10
commit-message:
prefix: chore
include: scope
groups:
# Bundle non-major updates so we don't get a flood of PRs
minor-and-patch:
update-types:
- minor
- patch

# GitHub Actions used in .github/workflows/
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
open-pull-requests-limit: 5
commit-message:
prefix: chore
include: scope
Comment on lines +21 to +28

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

To maintain consistency with the npm configuration and reduce pull request noise, consider grouping minor and patch updates for GitHub Actions as well. This ensures that non-breaking updates are bundled together, making them easier to manage and reducing the risk of hitting the open-pull-requests-limit.

  - package-ecosystem: github-actions
    directory: /
    schedule:
      interval: weekly
    open-pull-requests-limit: 5
    commit-message:
      prefix: chore
      include: scope
    groups:
      # Bundle non-major updates so we don't get a flood of PRs
      minor-and-patch:
        update-types:
          - minor
          - patch