Skip to content

Commit

Permalink
ci: add dependabot security updates
Browse files Browse the repository at this point in the history
  • Loading branch information
MegaRedHand committed Jan 15, 2025
1 parent f0de05d commit e1e6adf
Showing 1 changed file with 36 additions and 8 deletions.
44 changes: 36 additions & 8 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,39 @@
# To get started with Dependabot version updates, you'll need to specify which
# package ecosystems to update and where the package manifests are located.
# Please see the documentation for all configuration options:
# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file

version: 2

updates:
- package-ecosystem: "gomod" # See documentation for possible values
directory: "/" # Location of package manifests
# Group Security Updates
- package-ecosystem: "gomod"
directory: "/"
schedule:
interval: "daily"
time: "08:00"
timezone: "America/Los_Angeles"
target-branch: "main"
commit-message:
prefix: "[golang-security]"
include: "scope"
pull-request-branch-name:
separator: "-"
open-pull-requests-limit: 0
reviewers:
- "Layr-Labs/avs-devnet"
labels:
- "security"
- "golang"
allow:
- dependency-type: "direct"
groups:
security-updates:
applies-to: security-updates
patterns:
- "*"
update-types:
- "minor"
- "patch"
- "major"

# Version updates
- package-ecosystem: "gomod"
directory: "/"
schedule:
interval: "weekly"
interval: "daily"

0 comments on commit e1e6adf

Please sign in to comment.