Skip to content

chore(ci): added dependabot#147

Open
schronck wants to merge 1 commit into
devfrom
chore/ci/security-tooling
Open

chore(ci): added dependabot#147
schronck wants to merge 1 commit into
devfrom
chore/ci/security-tooling

Conversation

@schronck
Copy link
Copy Markdown

Summary

Adds .github/dependabot.yml matching the pattern in dec-party-manager:

  • Monthly npm updates at /, grouped minor/patch, conventional commit prefixes
  • Monthly github-actions updates if workflows exist

Part of the org-wide security tooling rollout. cargo-audit / cargo-deny don't apply (no Rust).

Test plan

  • Dependabot picks up the config (Insights → Dependency graph → Dependabot)
  • First scheduled run produces grouped PRs as expected

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant