Skip to content

Commit 228035a

Browse files
Throttle Dependabot: monthly cadence + 1 open PR per ecosystem (cut CI spend)
1 parent 6cffa13 commit 228035a

1 file changed

Lines changed: 12 additions & 6 deletions

File tree

.github/dependabot.yml

Lines changed: 12 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,45 +1,51 @@
11
# Keeps SHA-pinned GitHub Actions and every language dependency fresh.
22
# Implements [SWR-SEC-ACTION-PINNING]: each ecosystem groups ALL updates into ONE
33
# combined PR per run (patterns: ["*"]) so pinned action SHAs get bumped together
4-
# instead of one PR per package.
4+
# instead of one PR per package. Monthly cadence + one-open-PR-per-ecosystem caps
5+
# CI spend (security updates are exempt from `schedule` and still arrive promptly).
56
version: 2
67
updates:
78
- package-ecosystem: github-actions
89
directory: /
910
schedule:
10-
interval: weekly
11+
interval: monthly
12+
open-pull-requests-limit: 1
1113
groups:
1214
actions:
1315
patterns: ["*"]
1416

1517
- package-ecosystem: npm
1618
directory: /src/Napper.VsCode
1719
schedule:
18-
interval: weekly
20+
interval: monthly
21+
open-pull-requests-limit: 1
1922
groups:
2023
vscode-extension:
2124
patterns: ["*"]
2225

2326
- package-ecosystem: npm
2427
directory: /website
2528
schedule:
26-
interval: weekly
29+
interval: monthly
30+
open-pull-requests-limit: 1
2731
groups:
2832
website:
2933
patterns: ["*"]
3034

3135
- package-ecosystem: nuget
3236
directory: /
3337
schedule:
34-
interval: weekly
38+
interval: monthly
39+
open-pull-requests-limit: 1
3540
groups:
3641
dotnet:
3742
patterns: ["*"]
3843

3944
- package-ecosystem: cargo
4045
directory: /src/Napper.Zed
4146
schedule:
42-
interval: weekly
47+
interval: monthly
48+
open-pull-requests-limit: 1
4349
groups:
4450
zed-extension:
4551
patterns: ["*"]

0 commit comments

Comments
 (0)