Skip to content

chore: add Dependabot config (weekly Node (npm + github-actions) updates)#6

Open
LEEI1337 wants to merge 1 commit into
mainfrom
chore/dependabot-config
Open

chore: add Dependabot config (weekly Node (npm + github-actions) updates)#6
LEEI1337 wants to merge 1 commit into
mainfrom
chore/dependabot-config

Conversation

@LEEI1337
Copy link
Copy Markdown
Member

Summary

  • Adds .github/dependabot.yml for weekly automated dependency PRs (W83-D)
  • Stack scope: Node (npm + github-actions)
  • Open-PRs cap: 5 per ecosystem (prevents review storms)
  • Schedule: Mo 06:00 deps / Di 06:00 actions (Europe/Vienna)

Why

  • W83-D Tier-2: Repository hardening sweep across 13 active AIE repos
  • Closes supply-chain-risk gap (ISC2 Block-3 vulnerability mgmt)
  • Cross-Ref: ~/kb/raw/2026-05-27-w83-d-branch-protection-dependabot.md

Test plan

  • Dependabot UI shows config detected (Insights → Dependency graph → Dependabot)
  • First weekly run produces clean PR (no parse errors)

Co-Authored-By: auto-remediation-controller (W83-D)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant