Skip to content

Commit 6074c02

Browse files
committed
Adjust dependabot cadence
We want non-security dependabots to be released on a monthly basis as opposed to a weekly basis. This allows us to avoid drift from what has been released while balancing the amount of overhead involved with review and integration. We are also adding a "cooldown" of 7 days, which means a dependency won't be incorporated immediately, but only 7 days after its release date. This makes it more likely that any community issues with the dependency are resolved (whether that be catching a security issue or simply updating peer dependencies).
1 parent 9975586 commit 6074c02

File tree

1 file changed

+10
-2
lines changed

1 file changed

+10
-2
lines changed

.github/dependabot.yml

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,11 @@ updates:
33
- package-ecosystem: 'npm'
44
directory: '/'
55
schedule:
6-
interval: 'daily'
6+
interval: 'monthly'
7+
time: '00:00'
8+
timezone: 'Etc/UTC'
9+
cooldown:
10+
default-days: 7
711
groups:
812
storybook:
913
patterns:
@@ -35,4 +39,8 @@ updates:
3539
- package-ecosystem: 'github-actions'
3640
directory: '.github/workflows'
3741
schedule:
38-
interval: 'weekly'
42+
interval: 'monthly'
43+
time: '00:00'
44+
timezone: 'Etc/UTC'
45+
cooldown:
46+
default-days: 7

0 commit comments

Comments
 (0)