diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 5990d9c..0b225c5 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,11 +1,20 @@ -# To get started with Dependabot version updates, you'll need to specify which -# package ecosystems to update and where the package manifests are located. -# Please see the documentation for all configuration options: -# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file +# The ecosystem was left as the template's empty string, which makes the whole +# file inert - Dependabot parses it, matches nothing, and reports nothing. This +# repo is TypeScript with a package.json at the root, and it also pins GitHub +# Actions across five workflows. version: 2 updates: - - package-ecosystem: "" # See documentation for possible values - directory: "/" # Location of package manifests + - package-ecosystem: "npm" + directory: "/" + schedule: + interval: "weekly" + groups: + # One PR a week for the routine bumps rather than one per package. + npm-minor-and-patch: + update-types: ["minor", "patch"] + + - package-ecosystem: "github-actions" + directory: "/" schedule: interval: "weekly"