58 lines
1.9 KiB
YAML
58 lines
1.9 KiB
YAML
version: 2
|
|
updates:
|
|
- package-ecosystem: "pip"
|
|
directory: "/"
|
|
schedule:
|
|
interval: "weekly"
|
|
labels:
|
|
- "dependencies"
|
|
open-pull-requests-limit: 5
|
|
commit-message:
|
|
prefix: "deps"
|
|
prefix-development: "deps"
|
|
include: "scope"
|
|
|
|
# Hash-pinned CI tool installs (ruff/build/pytest/pip-audit/pip). Pinning is
|
|
# what Scorecard's Pinned-Dependencies wants, but a frozen pin rots: these
|
|
# locks are what security.yml's pip-audit scans, so a new advisory against a
|
|
# pinned dep reds the job until the pin moves. This entry is what keeps that
|
|
# window short. Dependabot reads the `pip-compile ...` command out of each
|
|
# .txt header and regenerates the lock (hashes included) from the .in.
|
|
# Separate from the "/" pip entry above, which tracks pyproject.toml.
|
|
- package-ecosystem: "pip"
|
|
directory: "/.github/requirements"
|
|
schedule:
|
|
interval: "weekly"
|
|
labels:
|
|
- "ci"
|
|
open-pull-requests-limit: 5
|
|
commit-message:
|
|
prefix: "ci"
|
|
include: "scope"
|
|
# packaging/pygments are shared across build.txt, e2e.txt and audit.txt.
|
|
# Ungrouped, one bump fans out into several PRs that each rewrite a subset
|
|
# of the locks and conflict with each other. One PR per week moves them all.
|
|
groups:
|
|
ci-tooling:
|
|
patterns:
|
|
- "*"
|
|
|
|
- package-ecosystem: "github-actions"
|
|
directory: "/"
|
|
schedule:
|
|
interval: "weekly"
|
|
labels:
|
|
- "ci"
|
|
open-pull-requests-limit: 5
|
|
commit-message:
|
|
prefix: "ci"
|
|
include: "scope"
|
|
# codeql-action is a monorepo (init/analyze/upload-sarif share one release).
|
|
# Bumping them in separate PRs leaves mismatched versions in security.yml and
|
|
# CodeQL hard-fails "init and analyze must be the same version". Group them so
|
|
# every codeql-action bump lands as a single PR that moves all paths together.
|
|
groups:
|
|
codeql-action:
|
|
patterns:
|
|
- "github/codeql-action*"
|