Repository navigation
Expand file tree
/
Copy pathdependabot.yml
More file actions
153 lines (146 loc) · 6.5 KB
/
Copy pathdependabot.yml
File metadata and controls
153 lines (146 loc) · 6.5 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
version: 2
updates:
# Each of these is an independent package.json/package-lock.json — kept as
# separate entries (rather than one root entry) so an update PR for, say,
# frontend never bundles unrelated app or e2e dependency bumps.
- package-ecosystem: npm
directory: /frontend
schedule:
interval: weekly
# A brand-new release sits for a week before Dependabot will propose it —
# protects against a typosquatted or freshly-compromised package version
# landing in a PR within hours of publish (Semgrep:
# package_managers.dependabot.dependabot-missing-cooldown, which checks
# for exactly this 7-day default). Applies to every update type here
# (default-days), not just majors: a malicious patch/minor release is
# exactly as dangerous as a malicious major one.
cooldown:
default-days: 7
open-pull-requests-limit: 10
groups:
# Security patches land immediately rather than waiting in a batched
# group PR that might sit unreviewed.
production-dependencies:
applies-to: version-updates
dependency-type: production
development-dependencies:
applies-to: version-updates
dependency-type: development
- package-ecosystem: npm
directory: /app
schedule:
interval: weekly
# A brand-new release sits for a week before Dependabot will propose it —
# protects against a typosquatted or freshly-compromised package version
# landing in a PR within hours of publish (Semgrep:
# package_managers.dependabot.dependabot-missing-cooldown, which checks
# for exactly this 7-day default). Applies to every update type here
# (default-days), not just majors: a malicious patch/minor release is
# exactly as dangerous as a malicious major one.
cooldown:
default-days: 7
open-pull-requests-limit: 10
groups:
production-dependencies:
applies-to: version-updates
dependency-type: production
development-dependencies:
applies-to: version-updates
dependency-type: development
- package-ecosystem: npm
directory: /admin-console
schedule:
interval: weekly
# A brand-new release sits for a week before Dependabot will propose it —
# protects against a typosquatted or freshly-compromised package version
# landing in a PR within hours of publish (Semgrep:
# package_managers.dependabot.dependabot-missing-cooldown, which checks
# for exactly this 7-day default). Applies to every update type here
# (default-days), not just majors: a malicious patch/minor release is
# exactly as dangerous as a malicious major one.
cooldown:
default-days: 7
open-pull-requests-limit: 10
groups:
production-dependencies:
applies-to: version-updates
dependency-type: production
development-dependencies:
applies-to: version-updates
dependency-type: development
- package-ecosystem: npm
directory: /e2e
schedule:
interval: weekly
# A brand-new release sits for a week before Dependabot will propose it —
# protects against a typosquatted or freshly-compromised package version
# landing in a PR within hours of publish (Semgrep:
# package_managers.dependabot.dependabot-missing-cooldown, which checks
# for exactly this 7-day default). Applies to every update type here
# (default-days), not just majors: a malicious patch/minor release is
# exactly as dangerous as a malicious major one.
cooldown:
default-days: 7
open-pull-requests-limit: 5
- package-ecosystem: npm
directory: /mastervault-mcp-server
schedule:
interval: weekly
# A brand-new release sits for a week before Dependabot will propose it —
# protects against a typosquatted or freshly-compromised package version
# landing in a PR within hours of publish (Semgrep:
# package_managers.dependabot.dependabot-missing-cooldown, which checks
# for exactly this 7-day default). Applies to every update type here
# (default-days), not just majors: a malicious patch/minor release is
# exactly as dangerous as a malicious major one.
cooldown:
default-days: 7
open-pull-requests-limit: 5
# lib/ is the napi-rs (Rust) download engine bound into the Electron app.
- package-ecosystem: cargo
directory: /lib
schedule:
interval: weekly
# A brand-new release sits for a week before Dependabot will propose it —
# protects against a typosquatted or freshly-compromised package version
# landing in a PR within hours of publish (Semgrep:
# package_managers.dependabot.dependabot-missing-cooldown, which checks
# for exactly this 7-day default). Applies to every update type here
# (default-days), not just majors: a malicious patch/minor release is
# exactly as dangerous as a malicious major one.
cooldown:
default-days: 7
open-pull-requests-limit: 5
# ml/hardware-recommender is a standalone Python project (see ci.yml's
# python-recommender job) — its own dependency surface, tracked separately
# from the shipped app since only its exported ONNX artifact ships.
- package-ecosystem: pip
directory: /ml/hardware-recommender
schedule:
interval: weekly
# A brand-new release sits for a week before Dependabot will propose it —
# protects against a typosquatted or freshly-compromised package version
# landing in a PR within hours of publish (Semgrep:
# package_managers.dependabot.dependabot-missing-cooldown, which checks
# for exactly this 7-day default). Applies to every update type here
# (default-days), not just majors: a malicious patch/minor release is
# exactly as dangerous as a malicious major one.
cooldown:
default-days: 7
open-pull-requests-limit: 5
# The CI/release workflows' own actions (actions/checkout, setup-node, …)
# — easy to forget since they're not in any package.json.
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
# A brand-new release sits for a week before Dependabot will propose it —
# protects against a typosquatted or freshly-compromised package version
# landing in a PR within hours of publish (Semgrep:
# package_managers.dependabot.dependabot-missing-cooldown, which checks
# for exactly this 7-day default). Applies to every update type here
# (default-days), not just majors: a malicious patch/minor release is
# exactly as dangerous as a malicious major one.
cooldown:
default-days: 7
open-pull-requests-limit: 5