# To get started with Dependabot version updates, you'll need to specify which # package ecosystems to update and where the package manifests are located. # Please see the documentation for all configuration options: # https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file version: 2 # npm updates are switched off entirely. open-pull-requests-limit bounds version # updates only, so the ignore entries below are what also stops security updates; # removing the npm entries would not work, as security updates come from alerts # rather than from this file. updates: - package-ecosystem: "github-actions" directory: "/" schedule: interval: "monthly" groups: "GitHub Actions updates": patterns: - "*" - package-ecosystem: "gomod" directory: "/backend" schedule: interval: "monthly" groups: "Go modules updates": dependency-type: "production" - package-ecosystem: "gomod" directory: "/e2e" schedule: interval: "monthly" groups: "Go modules updates": dependency-type: "production" - package-ecosystem: "npm" directory: "/frontend" open-pull-requests-limit: 0 ignore: - dependency-name: "*" schedule: interval: "monthly" groups: "NPM modules updates": dependency-type: "production" "NPM modules updates for tests": dependency-type: "development" - package-ecosystem: "npm" directory: "/frontend/apps/remark42" open-pull-requests-limit: 0 ignore: - dependency-name: "*" schedule: interval: "monthly" groups: "NPM modules updates": dependency-type: "production" "NPM modules updates for tests": dependency-type: "development" - package-ecosystem: "docker" directory: "/site" schedule: interval: "monthly" groups: "Site image updates": patterns: - "*"