From af482edd57ceb8059e3b6366a8fb4c8c4836aa3e Mon Sep 17 00:00:00 2001 From: hasparus Date: Thu, 10 Jun 2021 11:30:20 +0200 Subject: [PATCH] Ignore patch updates in Dependabot We get a lot of noise from Dependabot on a weekly basis. This should help a bit. See https://github.blog/changelog/2021-05-21-dependabot-version-updates-can-now-ignore-major-minor-patch-releases/ --- dependabot.yml | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/dependabot.yml b/dependabot.yml index f38eefc05..454b4868c 100644 --- a/dependabot.yml +++ b/dependabot.yml @@ -1,9 +1,11 @@ # see https://docs.github.com/en/code-security/supply-chain-security/keeping-your-dependencies-updated-automatically version: 2 updates: - - package-ecosystem: "npm" - directory: "/" + - package-ecosystem: 'npm' + directory: '/' schedule: - interval: "monthly" + interval: 'monthly' ignore: - - dependency-name: "@codechecks/client" + - dependency-name: '@codechecks/client' + - dependency-name: '*' + update-types: ['version-update:semver-patch']