docbrown/.github/dependabot.yml
2021-04-26 13:26:12 -04:00

36 lines
1.2 KiB
YAML

# Update dependencies with Dependabot
version: 2
updates:
# Set update schedule for Ruby Bundler
- package-ecosystem: "bundler"
# Raise pull requests to update vendored dependencies that are checked in to the repository
vendor: true
directory: "/"
schedule:
interval: "daily"
ignore:
# Ignoring binding_of_caller 1.0 temporarily until we find a solution for it breaking Docker
# see <https://github.com/forem/forem/issues/12068>
- dependency-name: "binding_of_caller"
versions: [">= 1.0"]
labels: []
# Set update schedule for Yarn/NPM
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
labels: []
ignore:
- dependency_name: "husky"
# Leaving this at the last v4 because the way Husky works has changed dramatically
# We can revisit this at a later time if we really need what future upgrades offer.
version_requirement: "4.x"
# Set update schedule for GitHub Actions
# https://docs.github.com/en/free-pro-team@latest/github/administering-a-repository/keeping-your-actions-up-to-date-with-dependabot
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "daily"