File tree Expand file tree Collapse file tree 2 files changed +116
-0
lines changed
Expand file tree Collapse file tree 2 files changed +116
-0
lines changed Original file line number Diff line number Diff line change 1+ version : 2
2+ updates :
3+ # Maintain dependencies for npm
4+ - package-ecosystem : " npm"
5+ directory : " /"
6+ schedule :
7+ interval : " weekly"
8+ day : " monday"
9+ time : " 09:00"
10+ timezone : " UTC"
11+ open-pull-requests-limit : 10
12+ reviewers :
13+ - " Countly/engineering"
14+ labels :
15+ - " dependencies"
16+ - " automated"
17+ commit-message :
18+ prefix : " deps"
19+ prefix-development : " deps-dev"
20+ include : " scope"
21+ versioning-strategy : increase
22+ ignore :
23+ # Ignore major version updates for stability
24+ - dependency-name : " *"
25+ update-types : ["version-update:semver-major"]
26+ groups :
27+ # Group MCP SDK updates together
28+ mcp-sdk :
29+ patterns :
30+ - " @modelcontextprotocol/*"
31+ # Group dev dependencies together
32+ development-dependencies :
33+ dependency-type : " development"
34+ update-types :
35+ - " minor"
36+ - " patch"
37+
38+ # Maintain dependencies for GitHub Actions
39+ - package-ecosystem : " github-actions"
40+ directory : " /"
41+ schedule :
42+ interval : " weekly"
43+ day : " monday"
44+ time : " 09:00"
45+ timezone : " UTC"
46+ open-pull-requests-limit : 5
47+ reviewers :
48+ - " Countly/engineering"
49+ labels :
50+ - " github-actions"
51+ - " dependencies"
52+ - " automated"
53+ commit-message :
54+ prefix : " ci"
55+ include : " scope"
56+
57+ # Maintain dependencies for Docker
58+ - package-ecosystem : " docker"
59+ directory : " /"
60+ schedule :
61+ interval : " weekly"
62+ day : " monday"
63+ time : " 09:00"
64+ timezone : " UTC"
65+ open-pull-requests-limit : 5
66+ reviewers :
67+ - " Countly/engineering"
68+ labels :
69+ - " docker"
70+ - " dependencies"
71+ - " automated"
72+ commit-message :
73+ prefix : " docker"
74+ include : " scope"
Original file line number Diff line number Diff line change 1+ name : " CodeQL"
2+
3+ on :
4+ push :
5+ branches : [ "main", "develop" ]
6+ pull_request :
7+ branches : [ "main", "develop" ]
8+ schedule :
9+ - cron : ' 0 0 * * 1' # Run every Monday at midnight UTC
10+ workflow_dispatch :
11+
12+ jobs :
13+ analyze :
14+ name : Analyze
15+ runs-on : ubuntu-latest
16+ permissions :
17+ actions : read
18+ contents : read
19+ security-events : write
20+
21+ strategy :
22+ fail-fast : false
23+ matrix :
24+ language : [ 'javascript-typescript' ]
25+
26+ steps :
27+ - name : Checkout repository
28+ uses : actions/checkout@v4
29+
30+ - name : Initialize CodeQL
31+ uses : github/codeql-action/init@v3
32+ with :
33+ languages : ${{ matrix.language }}
34+ queries : security-extended,security-and-quality
35+
36+ - name : Autobuild
37+ uses : github/codeql-action/autobuild@v3
38+
39+ - name : Perform CodeQL Analysis
40+ uses : github/codeql-action/analyze@v3
41+ with :
42+ category : " /language:${{matrix.language}}"
You can’t perform that action at this time.
0 commit comments