diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..63d7063 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,25 @@ +version: 2 +updates: + - package-ecosystem: npm + versioning-strategy: lockfile-only + directory: / + schedule: + interval: daily + labels: + - auto-approve + - automerge + - dependencies + - security + # Disable version updates for npm dependencies, only use Dependabot for security updates + open-pull-requests-limit: 0 + - package-ecosystem: github-actions + directory: / + schedule: + interval: daily + labels: + - auto-approve + - automerge + - dependencies + # only update hashicorp actions, external actions managed by tsccr + allow: + - dependency-name: hashicorp/*