Skip to content

Extend Dependabot coverage to all package manifests #817

Description

@collinsadi

.github/dependabot.yml covers root cargo, root npm, /frontend npm, and GitHub Actions — but not /sdk, /asp, /publisher, /relayer, /circuits (and its v2/v3 packages), the SDK example app, or the scanner's separate cargo workspace, each of which has its own lockfile.

Add ecosystem entries for every manifest.

Acceptance criteria:

  • Every directory with a lockfile has a Dependabot entry.
  • Grouping and cadence follow the existing frontend configuration.
  • The supply-chain policy doc lists the covered manifests.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    infraInfrastructure, CI, hosting, and indexersp3Hardening, polish, and operational maturitytype:opsOperational work or release process

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions