Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
48 changes: 46 additions & 2 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,52 @@ updates:
- package-ecosystem: bundler
directory: /
schedule:
interval: daily
interval: weekly
day: tuesday
time: "07:00"
allow:
- dependency-type: direct
cooldown:
default-days: 3
open-pull-requests-limit: 25
groups:
test:
patterns:
- "benchmark"
- "database_cleaner"
- "pry"
- "rack-test"
- "rspec"
- "rspec-*"
- "simplecov"
lint:
patterns:
- "rubocop"
- "rubocop-*"

- package-ecosystem: github-actions
directory: /
schedule:
interval: daily
interval: weekly
day: tuesday
time: "07:00"
cooldown:
default-days: 3
open-pull-requests-limit: 25

# Ruby needs to be upgraded manually in multiple places, so cannot
# be upgraded by Dependabot. That effectively makes the below
# config redundant, as ruby is the only updatable thing in the
# Dockerfile, although this may change in the future. We hope this
# config will save a dev from trying to upgrade ruby via Dependabot.
- package-ecosystem: docker
directory: /
ignore:
- dependency-name: ruby
schedule:
interval: weekly
day: tuesday
time: "07:00"
cooldown:
default-days: 7
open-pull-requests-limit: 25
Loading