11version : 2
22updates :
3- # Enable version updates for Python dependencies
3+ # GitHub Actions – weekly để giảm nhiễu
4+ - package-ecosystem : " github-actions"
5+ directory : " /"
6+ schedule :
7+ interval : " weekly"
8+ day : " monday"
9+ time : " 06:00"
10+ open-pull-requests-limit : 2
11+ commit-message :
12+ prefix : " deps(actions)"
13+ include : " scope"
14+ groups :
15+ gha-minors :
16+ patterns : ["*"]
17+ update-types : ["minor", "patch"]
18+
19+ # Python (nếu có pyproject/requirements)
420 - package-ecosystem : " pip"
521 directory : " /"
622 schedule :
723 interval : " weekly"
824 day : " monday"
9- time : " 09:00"
10- open-pull-requests-limit : 10
11- reviewers :
12- - " stillme-ai/security-team"
13- assignees :
14- - " stillme-ai/maintainers"
25+ time : " 06:30"
26+ open-pull-requests-limit : 2
1527 commit-message :
16- prefix : " chore( deps)"
28+ prefix : " deps(pip )"
1729 include : " scope"
18- labels :
19- - " dependencies"
20- - " python"
30+ insecure-external-code-execution : " deny"
2131 ignore :
2232 # Ignore major version updates for critical dependencies
2333 - dependency-name : " fastapi"
@@ -27,40 +37,14 @@ updates:
2737 - dependency-name : " pydantic"
2838 update-types : ["version-update:semver-major"]
2939
30- # Enable version updates for GitHub Actions
31- - package-ecosystem : " github-actions"
32- directory : " /"
33- schedule :
34- interval : " weekly"
35- day : " monday"
36- time : " 09:00"
37- open-pull-requests-limit : 5
38- reviewers :
39- - " stillme-ai/security-team"
40- assignees :
41- - " stillme-ai/maintainers"
42- commit-message :
43- prefix : " chore(ci)"
44- include : " scope"
45- labels :
46- - " dependencies"
47- - " github-actions"
48-
49- # Enable version updates for Docker dependencies
40+ # Docker dependencies
5041 - package-ecosystem : " docker"
5142 directory : " /"
5243 schedule :
5344 interval : " weekly"
5445 day : " monday"
55- time : " 09:00"
56- open-pull-requests-limit : 5
57- reviewers :
58- - " stillme-ai/security-team"
59- assignees :
60- - " stillme-ai/maintainers"
46+ time : " 07:00"
47+ open-pull-requests-limit : 2
6148 commit-message :
62- prefix : " chore (docker)"
49+ prefix : " deps (docker)"
6350 include : " scope"
64- labels :
65- - " dependencies"
66- - " docker"
0 commit comments