Skip to content

Commit 3601ff9

Browse files
authored
Add Dependabot configuration for package updates
1 parent 2e513f1 commit 3601ff9

File tree

1 file changed

+26
-0
lines changed

1 file changed

+26
-0
lines changed

.github/workflows/dependabot.yml

Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
version: 2
2+
3+
updates:
4+
- package-ecosystem: "pip"
5+
directory: "/"
6+
schedule:
7+
interval: "weekly"
8+
day: "monday"
9+
open-pull-requests-limit: 10
10+
labels:
11+
- "security"
12+
- "dependencies"
13+
ignore:
14+
- dependency-name: "*"
15+
update-types: ["version-update:semver-major"]
16+
vulnerabilities:
17+
accepted-severity: low
18+
19+
- package-ecosystem: "github-actions"
20+
directory: "/"
21+
schedule:
22+
interval: "weekly"
23+
day: "monday"
24+
labels:
25+
- "security"
26+
- "ci-cd"

0 commit comments

Comments
 (0)