Feat: Add dependabot configuration for NPM/Docker 17/138317/2
authorMatthew Watkins <mwatkins@linuxfoundation.org>
Tue, 25 Jun 2024 08:41:12 +0000 (09:41 +0100)
committerMatthew Watkins <mwatkins@linuxfoundation.org>
Tue, 25 Jun 2024 08:42:25 +0000 (09:42 +0100)
Issue-ID: IT-26882

Change-Id: I2a83b0a9b60b36d6a2ed61dd102ff7b88389c1c6
Signed-off-by: Matthew Watkins <mwatkins@linuxfoundation.org>
.github/dependabot.yml [new file with mode: 0644]

diff --git a/.github/dependabot.yml b/.github/dependabot.yml
new file mode 100644 (file)
index 0000000..8979dd8
--- /dev/null
@@ -0,0 +1,20 @@
+---
+# Dependabot configured for weekly NPM and Docker scans
+
+version: 2
+updates:
+  # Enable version updates for npm
+  - package-ecosystem: "npm"
+    # Look for `package.json` and `lock` files in the `root` directory
+    directory: "/"
+    # Check the npm registry for updates every day (weekdays)
+    schedule:
+      interval: "weekly"
+
+  # Enable version updates for Docker
+  - package-ecosystem: "docker"
+    # Look for a `Dockerfile` in the `root` directory
+    directory: "/"
+    # Check for updates once a week
+    schedule:
+      interval: "weekly"