File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 11# Keeps SHA-pinned GitHub Actions and every language dependency fresh.
22# Implements [SWR-SEC-ACTION-PINNING]: each ecosystem groups ALL updates into ONE
33# combined PR per run (patterns: ["*"]) so pinned action SHAs get bumped together
4- # instead of one PR per package.
4+ # instead of one PR per package. Monthly cadence + one-open-PR-per-ecosystem caps
5+ # CI spend (security updates are exempt from `schedule` and still arrive promptly).
56version : 2
67updates :
78 - package-ecosystem : github-actions
89 directory : /
910 schedule :
10- interval : weekly
11+ interval : monthly
12+ open-pull-requests-limit : 1
1113 groups :
1214 actions :
1315 patterns : ["*"]
1416
1517 - package-ecosystem : npm
1618 directory : /src/Napper.VsCode
1719 schedule :
18- interval : weekly
20+ interval : monthly
21+ open-pull-requests-limit : 1
1922 groups :
2023 vscode-extension :
2124 patterns : ["*"]
2225
2326 - package-ecosystem : npm
2427 directory : /website
2528 schedule :
26- interval : weekly
29+ interval : monthly
30+ open-pull-requests-limit : 1
2731 groups :
2832 website :
2933 patterns : ["*"]
3034
3135 - package-ecosystem : nuget
3236 directory : /
3337 schedule :
34- interval : weekly
38+ interval : monthly
39+ open-pull-requests-limit : 1
3540 groups :
3641 dotnet :
3742 patterns : ["*"]
3843
3944 - package-ecosystem : cargo
4045 directory : /src/Napper.Zed
4146 schedule :
42- interval : weekly
47+ interval : monthly
48+ open-pull-requests-limit : 1
4349 groups :
4450 zed-extension :
4551 patterns : ["*"]
You can’t perform that action at this time.
0 commit comments