diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 38eb5c0a..dab5e766 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,14 +1,17 @@ # To get started with Dependabot version updates, you'll need to specify which # package ecosystems to update and where the package manifests are located. # Please see the documentation for all configuration options: -# https://docs.github.com/github/administering-a-repository/configuration-options-for-dependency-updates +# https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference version: 2 updates: - package-ecosystem: 'npm' # See documentation for possible values directory: '/' # Location of package manifests + versioning-strategy: increase-if-necessary schedule: - interval: 'daily' + interval: 'weekly' + cooldown: + default-days: 3 groups: prod-dependencies: dependency-type: 'production' @@ -20,3 +23,10 @@ updates: update-types: - 'minor' - 'patch' + + - package-ecosystem: 'github-actions' + directory: '/' + schedule: + interval: 'weekly' + cooldown: + default-days: 3