* Drop the @remark42/api package It cannot authenticate anyone: clients/auth.ts exposes only anonymous, email and telegram, with no OAuth method, and the fetcher never sets credentials so its cookie auth cannot work cross-origin. Nothing in the repo consumes it, no third-party consumer exists, and npm has served an alpha from July 2022 that CI never publishes. * Drop the removed workflow from the pnpm pinning checklist frontend/CLAUDE.md still counted ci-frontend-api.yml among the places the pnpm version is pinned, and stated a fixed total that no longer holds.
76 lines
2.3 KiB
YAML
76 lines
2.3 KiB
YAML
# To get started with Dependabot version updates, you'll need to specify which
|
|
# package ecosystems to update and where the package manifests are located.
|
|
# Please see the documentation for all configuration options:
|
|
# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file
|
|
|
|
version: 2
|
|
|
|
# npm updates are switched off entirely. open-pull-requests-limit bounds version
|
|
# updates only, so the ignore entries below are what also stops security updates;
|
|
# removing the npm entries would not work, as security updates come from alerts
|
|
# rather than from this file.
|
|
updates:
|
|
- package-ecosystem: "github-actions"
|
|
directory: "/"
|
|
schedule:
|
|
interval: "monthly"
|
|
groups:
|
|
"GitHub Actions updates":
|
|
patterns:
|
|
- "*"
|
|
- package-ecosystem: "gomod"
|
|
directory: "/backend"
|
|
schedule:
|
|
interval: "monthly"
|
|
groups:
|
|
"Go modules updates":
|
|
dependency-type: "production"
|
|
- package-ecosystem: "npm"
|
|
directory: "/frontend"
|
|
open-pull-requests-limit: 0
|
|
ignore:
|
|
- dependency-name: "*"
|
|
schedule:
|
|
interval: "monthly"
|
|
groups:
|
|
"NPM modules updates":
|
|
dependency-type: "production"
|
|
"NPM modules updates for tests":
|
|
dependency-type: "development"
|
|
- package-ecosystem: "npm"
|
|
directory: "/frontend/e2e"
|
|
open-pull-requests-limit: 0
|
|
ignore:
|
|
- dependency-name: "*"
|
|
schedule:
|
|
interval: "monthly"
|
|
groups:
|
|
"NPM modules updates":
|
|
dependency-type: "production"
|
|
"NPM modules updates for tests":
|
|
dependency-type: "development"
|
|
- package-ecosystem: "npm"
|
|
directory: "/frontend/apps/remark42"
|
|
open-pull-requests-limit: 0
|
|
ignore:
|
|
- dependency-name: "*"
|
|
schedule:
|
|
interval: "monthly"
|
|
groups:
|
|
"NPM modules updates":
|
|
dependency-type: "production"
|
|
"NPM modules updates for tests":
|
|
dependency-type: "development"
|
|
- package-ecosystem: "npm"
|
|
directory: "/site"
|
|
open-pull-requests-limit: 0
|
|
ignore:
|
|
- dependency-name: "*"
|
|
schedule:
|
|
interval: "monthly"
|
|
groups:
|
|
"NPM modules updates":
|
|
dependency-type: "production"
|
|
"NPM modules updates for tests":
|
|
dependency-type: "development"
|