Skip to content

Commit c904b67

Browse files
committed
Set Dependabot cooldown period to 4 days
This addresses the zizmor findings by setting a cooldown period of 4 days for all package ecosystems in dependabot.yml. Related to: ENG-3236
1 parent 5f9dd45 commit c904b67

File tree

1 file changed

+22
-20
lines changed

1 file changed

+22
-20
lines changed

.github/dependabot.yml

Lines changed: 22 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -1,22 +1,24 @@
11
version: 2
22
updates:
3-
- package-ecosystem: npm
4-
directory: "/"
5-
schedule:
6-
interval: daily
7-
time: "14:00"
8-
open-pull-requests-limit: 20
9-
groups:
10-
minor-and-patch:
11-
patterns:
12-
- "*"
13-
update-types:
14-
- "minor"
15-
- "patch"
16-
cooldown:
17-
default-days: 4
18-
- package-ecosystem: "github-actions"
19-
directory: "/"
20-
schedule:
21-
interval: daily
22-
time: "14:00"
3+
- package-ecosystem: npm
4+
directory: /
5+
schedule:
6+
interval: daily
7+
time: '14:00'
8+
open-pull-requests-limit: 20
9+
groups:
10+
minor-and-patch:
11+
patterns:
12+
- '*'
13+
update-types:
14+
- minor
15+
- patch
16+
cooldown:
17+
default-days: 4
18+
- package-ecosystem: github-actions
19+
directory: /
20+
schedule:
21+
interval: daily
22+
time: '14:00'
23+
cooldown:
24+
default-days: 4

0 commit comments

Comments
 (0)