mirror of
https://github.com/tendermint/tendermint.git
synced 2026-01-09 14:43:19 +00:00
At present we allow automated dependency updates on release branches via Dependabot. This seems fine for `main`, but is risky for release branches.
This PR enables _daily_ checks for security-related dependency updates on release branches, but only performs automated non-security-related updates for `main` (weekly).
---
#### PR checklist
- [x] Tests written/updated, or no tests needed
- [x] `CHANGELOG_PENDING.md` updated, or no changelog entry needed
- [x] Updated relevant documentation (`docs/`) and code comments, or no
documentation updates needed
76 lines
1.6 KiB
YAML
76 lines
1.6 KiB
YAML
version: 2
|
|
updates:
|
|
- package-ecosystem: github-actions
|
|
directory: "/"
|
|
schedule:
|
|
interval: weekly
|
|
target-branch: "main"
|
|
open-pull-requests-limit: 10
|
|
labels:
|
|
- T:dependencies
|
|
- S:automerge
|
|
|
|
- package-ecosystem: github-actions
|
|
directory: "/"
|
|
schedule:
|
|
interval: weekly
|
|
target-branch: "v0.37.x"
|
|
open-pull-requests-limit: 10
|
|
labels:
|
|
- T:dependencies
|
|
- S:automerge
|
|
|
|
- package-ecosystem: github-actions
|
|
directory: "/"
|
|
schedule:
|
|
interval: weekly
|
|
target-branch: "v0.34.x"
|
|
open-pull-requests-limit: 10
|
|
labels:
|
|
- T:dependencies
|
|
- S:automerge
|
|
|
|
- package-ecosystem: npm
|
|
directory: "/docs"
|
|
schedule:
|
|
interval: weekly
|
|
open-pull-requests-limit: 10
|
|
|
|
###################################
|
|
##
|
|
## Update All Go Dependencies
|
|
|
|
- package-ecosystem: gomod
|
|
directory: "/"
|
|
schedule:
|
|
interval: weekly
|
|
target-branch: "main"
|
|
open-pull-requests-limit: 10
|
|
labels:
|
|
- T:dependencies
|
|
- S:automerge
|
|
|
|
- package-ecosystem: gomod
|
|
directory: "/"
|
|
schedule:
|
|
interval: daily
|
|
target-branch: "v0.37.x"
|
|
# Only allow automated security-related dependency updates on release
|
|
# branches.
|
|
open-pull-requests-limit: 0
|
|
labels:
|
|
- T:dependencies
|
|
- S:automerge
|
|
|
|
- package-ecosystem: gomod
|
|
directory: "/"
|
|
schedule:
|
|
interval: daily
|
|
target-branch: "v0.34.x"
|
|
# Only allow automated security-related dependency updates on release
|
|
# branches.
|
|
open-pull-requests-limit: 0
|
|
labels:
|
|
- T:dependencies
|
|
- S:automerge
|