Commit 40cd33d
committed
Restrict Dependabot updates to direct dependencies
Configure Dependabot to only open pull requests for direct dependencies,
reducing noise from transitive updates and keeping changes more relevant and
easier to review.
Approach recommended in GOV.UK Developer Docs.
https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#dependency-type-allow1 parent 3b078aa commit 40cd33d
1 file changed
+2
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| 9 | + | |
| 10 | + | |
9 | 11 | | |
10 | 12 | | |
11 | 13 | | |
| |||
0 commit comments