aspnetcore/.github/dependabot.yml

86 строки
2.0 KiB
YAML

version: 2
registries:
dev.azure.com:
token: ${{secrets.DEPENDABOT_NPM_TOKEN}}
type: npm-registry
url: https://pkgs.dev.azure.com/
updates:
- package-ecosystem: npm
directory: "/"
# Perform only security updates of our npm dependencies.
open-pull-requests-limit: 0
registries:
- dev.azure.com
# Schedule should be ignored for security updates.
schedule:
interval: monthly
- package-ecosystem: "github-actions"
directory: "/"
schedule:
day: friday
interval: "weekly"
time: "05:00"
timezone: "America/Los_Angeles"
commit-message:
prefix: "[main] "
include: scope
labels:
- area-infrastructure
# Keep submodules up to date in 'main'.
- package-ecosystem: "gitsubmodule"
directory: "/"
schedule:
day: friday
interval: "weekly"
time: "05:00"
timezone: "America/Los_Angeles"
allow:
- dependency-type: "all"
commit-message:
prefix: "[main] "
include: scope
labels:
- area-infrastructure
# Keep submodules up to date in 'release/*' branches. (Unfortunately Dependabot security PRs can't target these.)
# Monthly interval opens PRs on the first of each month.
- package-ecosystem: "gitsubmodule"
directory: "/"
schedule:
interval: "monthly"
allow:
- dependency-type: "all"
commit-message:
prefix: "[release/2.1] "
include: scope
labels:
- area-infrastructure
target-branch: "release/2.1"
- package-ecosystem: "gitsubmodule"
directory: "/"
schedule:
interval: "monthly"
allow:
- dependency-type: "all"
commit-message:
prefix: "[release/6.0] "
include: scope
labels:
- area-infrastructure
target-branch: "release/6.0"
- package-ecosystem: "gitsubmodule"
directory: "/"
schedule:
interval: "monthly"
allow:
- dependency-type: "all"
commit-message:
prefix: "[release/7.0] "
include: scope
labels:
- area-infrastructure
target-branch: "release/7.0"