Merge pull request #776 from overleaf/jpa-dependabot-config

[misc] add the dependabot config of the buildscripts
This commit is contained in:
Jakob Ackermann 2020-09-04 10:47:31 +02:00 committed by GitHub
commit 28f326fd98
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

17
.github/dependabot.yml vendored Normal file
View file

@ -0,0 +1,17 @@
version: 2
updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "daily"
pull-request-branch-name:
# Separate sections of the branch name with a hyphen
# Docker images use the branch name and do not support slashes in tags
# https://github.com/overleaf/google-ops/issues/822
# https://docs.github.com/en/github/administering-a-repository/configuration-options-for-dependency-updates#pull-request-branch-nameseparator
separator: "-"
# Block informal upgrades -- security upgrades use a separate queue.
# https://docs.github.com/en/github/administering-a-repository/configuration-options-for-dependency-updates#open-pull-requests-limit
open-pull-requests-limit: 0