From 8a1b3a13ce938ed6ef275194fc45c7d4910780a5 Mon Sep 17 00:00:00 2001 From: Devasy Patel <110348311+Devasy23@users.noreply.github.com> Date: Sun, 29 Jun 2025 18:37:10 +0530 Subject: [PATCH 1/3] Create dependabot.yml --- .github/dependabot.yml | 11 +++++++++++ 1 file changed, 11 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 00000000..516c81dd --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,11 @@ +# To get started with Dependabot version updates, you'll need to specify which +# package ecosystems to update and where the package manifests are located. +# Please see the documentation for all configuration options: +# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file + +version: 2 +updates: + - package-ecosystem: "pypi" # See documentation for possible values + directory: "/" # Location of package manifests + schedule: + interval: "weekly" From d7fa6de84d8654a6ddffa3dd9bc32a4dbe61518e Mon Sep 17 00:00:00 2001 From: Devasy Patel <110348311+Devasy23@users.noreply.github.com> Date: Sun, 29 Jun 2025 18:45:52 +0530 Subject: [PATCH 2/3] feat: Enhance Dependabot configuration for multiple package ecosystems and schedules --- .github/dependabot.yml | 104 ++++++++++++++++++++++++++++++++++++++--- 1 file changed, 98 insertions(+), 6 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 516c81dd..be134117 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,11 +1,103 @@ -# To get started with Dependabot version updates, you'll need to specify which -# package ecosystems to update and where the package manifests are located. -# Please see the documentation for all configuration options: -# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file +# Enhanced Dependabot configuration for SplitWiser +# Monitors multiple package ecosystems for security and version updates +# Documentation: https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file version: 2 updates: - - package-ecosystem: "pypi" # See documentation for possible values - directory: "/" # Location of package manifests + # Python dependencies (Backend - Root level) + - package-ecosystem: "pip" + directory: "/" schedule: interval: "weekly" + day: "monday" + time: "09:00" + assignees: + - "devasy23" + reviewers: + - "devasy23" + commit-message: + prefix: "deps" + prefix-development: "deps-dev" + include: "scope" + open-pull-requests-limit: 5 + labels: + - "dependencies" + - "python" + - "backend" + + # Python dependencies (Backend directory) + - package-ecosystem: "pip" + directory: "/backend" + schedule: + interval: "weekly" + day: "monday" + time: "09:00" + assignees: + - "devasy23" + reviewers: + - "devasy23" + commit-message: + prefix: "deps" + prefix-development: "deps-dev" + include: "scope" + open-pull-requests-limit: 5 + labels: + - "dependencies" + - "python" + - "backend" + + # Node.js dependencies (Frontend) + - package-ecosystem: "npm" + directory: "/frontend" + schedule: + interval: "weekly" + day: "tuesday" + time: "09:00" + assignees: + - "vrajpatelll" + reviewers: + - "vrajpatelll" + commit-message: + prefix: "deps" + prefix-development: "deps-dev" + include: "scope" + open-pull-requests-limit: 5 + labels: + - "dependencies" + - "javascript" + - "frontend" + # Group React Native and Expo related updates + groups: + react-native: + patterns: + - "react-native*" + - "react" + - "react-dom" + - "@react-*" + expo: + patterns: + - "expo*" + - "@expo/*" + navigation: + patterns: + - "@react-navigation/*" + + # GitHub Actions + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" + day: "wednesday" + time: "09:00" + assignees: + - "devasy23" + reviewers: + - "devasy23" + commit-message: + prefix: "ci" + include: "scope" + open-pull-requests-limit: 3 + labels: + - "dependencies" + - "github-actions" + - "ci/cd" From a1d7d155ba543634a12f2331c9fd9856d8ea93f6 Mon Sep 17 00:00:00 2001 From: Devasy Patel <110348311+Devasy23@users.noreply.github.com> Date: Sun, 29 Jun 2025 18:50:09 +0530 Subject: [PATCH 3/3] fix(dependabot): remove 'include: scope' from commit message configuration --- .github/dependabot.yml | 2 -- 1 file changed, 2 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index be134117..2f799787 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -18,7 +18,6 @@ updates: commit-message: prefix: "deps" prefix-development: "deps-dev" - include: "scope" open-pull-requests-limit: 5 labels: - "dependencies" @@ -39,7 +38,6 @@ updates: commit-message: prefix: "deps" prefix-development: "deps-dev" - include: "scope" open-pull-requests-limit: 5 labels: - "dependencies"