From d822ca3d1b5a696b17b12ea4ce08479c85a0271f Mon Sep 17 00:00:00 2001 From: Paul Schneider Date: Thu, 11 Jun 2026 20:21:12 +0100 Subject: [PATCH] Update Dependabot configuration for multiple ecosystems --- .github/dependabot.yml | 191 +++++++++++++++++++++++++++++++++++++++++ 1 file changed, 191 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 00000000..c04b71cc --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,191 @@ +version: 2 +multi-ecosystem-groups: + uv-ecosystem: + schedule: + interval: "weekly" + day: "sunday" + time: "16:00" + +updates: + - package-ecosystem: "bundler" + directories: + - "/updater" + - "/" + schedule: + interval: "weekly" + day: "sunday" + time: "16:00" + groups: + sorbet: + patterns: + - "*-sorbet" + - "sorbet-*" + - "sorbet" + - "tapioca" + aws-sdk: + patterns: + - "aws-sdk-*" + prod-dependencies: + dependency-type: "production" + update-types: + - "minor" + - "patch" + dev-dependencies: + dependency-type: "development" + update-types: + - "minor" + - "patch" + + # Watch the per-ecosystem native helpers + - package-ecosystem: "composer" + directories: + - "/composer/helpers/v2" + schedule: + interval: "weekly" + day: "sunday" + time: "16:00" + groups: + prod-dependencies: + dependency-type: "production" + update-types: + - "minor" + - "patch" + dev-dependencies: + dependency-type: "development" + update-types: + - "minor" + - "patch" + - package-ecosystem: "devcontainers" + directory: "/" + schedule: + interval: "weekly" + day: "sunday" + time: "16:00" + - package-ecosystem: "docker" + directories: + - "/" + - "/go_modules" + - "/cargo" + schedule: + interval: "weekly" + day: "sunday" + time: "16:00" + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" + day: "sunday" + time: "16:00" + groups: + all-actions: + patterns: [ "*" ] + - package-ecosystem: "gomod" + directory: "/go_modules/helpers" + schedule: + interval: "weekly" + day: "sunday" + time: "16:00" + - package-ecosystem: "mix" + directory: "/hex/helpers" + schedule: + interval: "weekly" + day: "sunday" + time: "16:00" + - package-ecosystem: "npm" + directory: "/npm_and_yarn/helpers" + schedule: + interval: "weekly" + day: "sunday" + time: "16:00" + groups: + npm-dependencies: + patterns: + - "@npmcli/arborist" + - "nock" + - "npm" + - "semver" + exclude-patterns: + - "detect-indent" # temp excluded due to https://github.com/dependabot/dependabot-core/pull/5683#issuecomment-1243468605 + yarn-dependencies: + patterns: + - "@dependabot/yarn-lib" + pnpm-dependencies: + patterns: + - "@pnpm/lockfile-file" + - "@pnpm/dependency-path" + dev-dependencies: + dependency-type: "development" + update-types: + - "minor" + - "patch" + ignore: + - dependency-name: "npm" + update-types: [ "version-update:semver-major" ] + - package-ecosystem: "pip" + directory: "/python/helpers" + schedule: + interval: "weekly" + day: "sunday" + time: "16:00" + groups: + common: + patterns: + - hashin + - cython + - flake8 + # Keep the package managers themselves separate because they are higher risk + # and also higher visibility--ie, users generally want latest, so we don't + # want breakage in the `common` group to prevent updating package manager versions + - package-ecosystem: "pub" + directory: "/pub/helpers" + schedule: + interval: "weekly" + day: "sunday" + time: "16:00" + - package-ecosystem: "nuget" + directory: "/nuget/helpers/lib/NuGetUpdater" + schedule: + interval: "weekly" + day: "sunday" + time: "16:00" + - package-ecosystem: "dotnet-sdk" + directory: "/nuget/helpers/lib/NuGetUpdater" + schedule: + interval: "weekly" + day: "sunday" + time: "16:00" + - package-ecosystem: "docker" + directory: "/maven" + schedule: + interval: "weekly" + day: "sunday" + time: "16:00" + - package-ecosystem: "docker" + directory: "/uv" + multi-ecosystem-group: "uv-ecosystem" + patterns: ["*"] + - package-ecosystem: "pip" + directory: "/uv/helpers" + multi-ecosystem-group: "uv-ecosystem" + patterns: ["*"] + ignore: + # Ignore major updates as most major updates will need manual intervention + - dependency-name: "*" + update-types: [ "version-update:semver-major" ] + - package-ecosystem: "docker" + directory: "/docker" + schedule: + interval: "weekly" + day: "sunday" + time: "16:00" + groups: + regclient: + patterns: + - "regclient/regctl*" + - "sigstore/cosign/cosign*" + - package-ecosystem: "docker" + directory: "/gradle" + schedule: + interval: "weekly" + day: "sunday" + time: "16:00"