Skip to content
This repository is currently being migrated. It's locked while the migration is in progress.

Commit b46cd37

Browse files
committed
impr: SEC-1370 Update dependabot config
1 parent b02198c commit b46cd37

1 file changed

Lines changed: 40 additions & 0 deletions

File tree

.github/dependabot.yml

Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
# Author: daniel_moore@trendmicro.com
2+
# Purpose: Enables dependabot to raise pull requests to update
3+
# out of date dependencies.
4+
#
5+
# A maximum of 5 pull requests will be raised for a given repository
6+
# at any one time.
7+
version: 2
8+
registries:
9+
# Allows dependabot to access @conformity/* private npm
10+
# packages.
11+
npm-github:
12+
type: npm-registry
13+
url: https://jfrog.trendmicro.com/artifactory/api/npm/conformity-npm_virtual/
14+
# The workflow token is configured at the org level as was created under
15+
# service-cloudconformity account. The token is stored in 1password.
16+
token: ${{secrets.ARTIFACTORY_TOKEN_PREPARED}}
17+
updates:
18+
- package-ecosystem: "npm"
19+
# Assign to anyone in dev team. Someone responsible for the repo should check
20+
# and merge the pull request.
21+
reviewers:
22+
- cloudconformity/developers
23+
# Ignore all semver major updates as these need special consideration
24+
# when performing updates due to breaking changes.
25+
ignore:
26+
- dependency-name: "*"
27+
update-types:
28+
- version-update:semver-major
29+
registries:
30+
- npm-github
31+
directory: "/"
32+
open-pull-requests-limit: 0
33+
schedule:
34+
interval: "daily"
35+
# prefix commits and PR titles with dependabot so they're easily identifiable and
36+
# so commitlint can ignore the misssing ticket.
37+
commit-message:
38+
include: scope
39+
prefix: "dependabot"
40+
prefix-development: "dependabot"

0 commit comments

Comments
 (0)