Skip to content

ci: add Dependabot configuration#203

Merged
MarioCadenas merged 1 commit intomainfrom
dependabot-config
Mar 24, 2026
Merged

ci: add Dependabot configuration#203
MarioCadenas merged 1 commit intomainfrom
dependabot-config

Conversation

@pietern
Copy link
Copy Markdown
Collaborator

@pietern pietern commented Mar 24, 2026

Add the npm package ecosystem with security-only updates by setting
open-pull-requests-limit to 0.

Add the github-actions package ecosystem with a monthly update interval.
Monthly keeps churn low while ensuring deprecation notices and security
fixes flow in through PRs. The 7-day cooldown avoids bumping actions
that were just released, letting them bake first.

Co-authored-by: Isaac

Add the npm package ecosystem with security-only updates by setting
open-pull-requests-limit to 0.

Add the github-actions package ecosystem with a monthly update interval.
Monthly keeps churn low while ensuring deprecation notices and security
fixes flow in through PRs. The 7-day cooldown avoids bumping actions
that were just released, letting them bake first.

Co-authored-by: Isaac
@pietern pietern changed the title Add Dependabot configuration ci: add Dependabot configuration Mar 24, 2026
@pietern pietern requested review from MarioCadenas and pkosiec March 24, 2026 11:00
@MarioCadenas MarioCadenas merged commit c9fbb5e into main Mar 24, 2026
1 of 3 checks passed
@MarioCadenas MarioCadenas deleted the dependabot-config branch March 24, 2026 13:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants