From cf807c36831d4c237d8ceddf5f55d2fdc3a24dec Mon Sep 17 00:00:00 2001 From: Matthew Watkins Date: Tue, 25 Jun 2024 09:41:12 +0100 Subject: [PATCH] Feat: Add dependabot configuration for NPM/Docker Issue-ID: IT-26882 Change-Id: I2a83b0a9b60b36d6a2ed61dd102ff7b88389c1c6 Signed-off-by: Matthew Watkins --- .github/dependabot.yml | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..8979dd8 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,20 @@ +--- +# Dependabot configured for weekly NPM and Docker scans + +version: 2 +updates: + # Enable version updates for npm + - package-ecosystem: "npm" + # Look for `package.json` and `lock` files in the `root` directory + directory: "/" + # Check the npm registry for updates every day (weekdays) + schedule: + interval: "weekly" + + # Enable version updates for Docker + - package-ecosystem: "docker" + # Look for a `Dockerfile` in the `root` directory + directory: "/" + # Check for updates once a week + schedule: + interval: "weekly" -- 2.16.6