Skip to content

Commit cd51c1b

Browse files
authored
chore: configure dependabot to only open PRs for security issues (#1034)
1 parent 2fce36c commit cd51c1b

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

.github/dependabot.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,10 +7,15 @@ updates:
77
directory: "/"
88
schedule:
99
interval: "daily"
10+
# Disable version updates for npm dependencies
11+
# https://docs.github.com/en/code-security/supply-chain-security/keeping-your-dependencies-updated-automatically/configuration-options-for-dependency-updates#open-pull-requests-limit
12+
open-pull-requests-limit: 0
1013

1114
# Maintain dependencies for npm
1215
- package-ecosystem: "npm"
1316
target-branch: "develop"
1417
directory: "/"
1518
schedule:
1619
interval: "daily"
20+
# Disable version updates for npm dependencies
21+
open-pull-requests-limit: 0

0 commit comments

Comments
 (0)