From 50c7c4474002aadb5a1b1542df18306d858306f4 Mon Sep 17 00:00:00 2001 From: Matthias Linhuber Date: Thu, 27 Aug 2026 00:06:47 +0200 Subject: [PATCH] chore: activate dependabot package-ecosystem was left as the template's empty string, so the file parsed, matched nothing, and reported nothing - this repo has never had a dependency update raised. It is TypeScript with a package.json at the root and pins GitHub Actions across five workflows, so both ecosystems are configured. Minor and patch npm bumps are grouped into one weekly PR rather than one per package. --- .github/dependabot.yml | 21 +++++++++++++++------ 1 file changed, 15 insertions(+), 6 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 5990d9c..0b225c5 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,11 +1,20 @@ -# To get started with Dependabot version updates, you'll need to specify which -# package ecosystems to update and where the package manifests are located. -# Please see the documentation for all configuration options: -# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file +# The ecosystem was left as the template's empty string, which makes the whole +# file inert - Dependabot parses it, matches nothing, and reports nothing. This +# repo is TypeScript with a package.json at the root, and it also pins GitHub +# Actions across five workflows. version: 2 updates: - - package-ecosystem: "" # See documentation for possible values - directory: "/" # Location of package manifests + - package-ecosystem: "npm" + directory: "/" + schedule: + interval: "weekly" + groups: + # One PR a week for the routine bumps rather than one per package. + npm-minor-and-patch: + update-types: ["minor", "patch"] + + - package-ecosystem: "github-actions" + directory: "/" schedule: interval: "weekly"