From 5d3a55a72cddbd25ca62adf0b8fa3ad1f6571e2d Mon Sep 17 00:00:00 2001 From: Pol Date: Fri, 15 May 2026 20:20:38 +0200 Subject: [PATCH] ci(deps): add Dependabot config for pip + npm + github-actions Weekly scans against main covering pip (web), npm (web/frontend), and github-actions. Existing test.yml CI gates each PR. Co-Authored-By: Claude Opus 4.7 --- .github/dependabot.yml | 49 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 49 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..d713084 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,49 @@ +# Weekly Dependabot scans against main. Existing test.yml CI gates each +# PR. Major-version bumps ignored — those need focused review. + +version: 2 +updates: + - package-ecosystem: pip + directory: /web + schedule: + interval: weekly + day: monday + open-pull-requests-limit: 3 + ignore: + - dependency-name: '*' + update-types: + - version-update:semver-major + commit-message: + prefix: chore(deps) + include: scope + labels: + - dependencies + + - package-ecosystem: npm + directory: /web/frontend + schedule: + interval: weekly + day: monday + open-pull-requests-limit: 3 + ignore: + - dependency-name: '*' + update-types: + - version-update:semver-major + commit-message: + prefix: chore(deps) + include: scope + labels: + - dependencies + + - package-ecosystem: github-actions + directory: / + schedule: + interval: weekly + day: monday + open-pull-requests-limit: 3 + commit-message: + prefix: chore(ci) + include: scope + labels: + - dependencies + - ci