From 1d4088fefc2f6d7578e86032b7954b1ed467e92e Mon Sep 17 00:00:00 2001 From: "Yuan (Terry) Tang" Date: Mon, 12 Feb 2024 12:15:39 -0500 Subject: [PATCH 1/2] ci: Add dependabot configuration for security updates Signed-off-by: Yuan (Terry) Tang --- .github/dependabot.yml | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 00000000..80b17e9d --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,17 @@ +version: 2 +updates: + - package-ecosystem: "gomod" + directory: "/" + schedule: + interval: "weekly" + day: "saturday" + # ignore all non-security updates: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#open-pull-requests-limit + open-pull-requests-limit: 0 + + - package-ecosystem: "pip" + directory: "/" + schedule: + interval: "weekly" + day: "saturday" + # ignore all non-security updates: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#open-pull-requests-limit + open-pull-requests-limit: 0 From 31f6e30ccc0d78f4e63a21053f5ae6619691ae7b Mon Sep 17 00:00:00 2001 From: "Yuan (Terry) Tang" Date: Mon, 12 Feb 2024 12:17:05 -0500 Subject: [PATCH 2/2] Update dependabot.yml Signed-off-by: Yuan (Terry) Tang --- .github/dependabot.yml | 8 -------- 1 file changed, 8 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 80b17e9d..aac171b7 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -7,11 +7,3 @@ updates: day: "saturday" # ignore all non-security updates: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#open-pull-requests-limit open-pull-requests-limit: 0 - - - package-ecosystem: "pip" - directory: "/" - schedule: - interval: "weekly" - day: "saturday" - # ignore all non-security updates: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#open-pull-requests-limit - open-pull-requests-limit: 0