Skip to content

Commit 5cf294b

Browse files
committed
ci: harden dependabot review workflow
Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
1 parent d103fc9 commit 5cf294b

1 file changed

Lines changed: 21 additions & 0 deletions

File tree

.github/dependabot.yml

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,12 @@ updates:
99
directory: "/"
1010
schedule:
1111
interval: "weekly"
12+
open-pull-requests-limit: 5
13+
allow:
14+
- dependency-name: "python"
15+
- dependency-name: "ghcr.io/astral-sh/uv"
16+
- dependency-name: "trufflesecurity/trufflehog"
17+
- dependency-name: "aquasec/trivy"
1218
labels:
1319
- "dependencies"
1420
- "docker"
@@ -23,6 +29,13 @@ updates:
2329
directory: "/app_tests"
2430
schedule:
2531
interval: "weekly"
32+
open-pull-requests-limit: 2
33+
allow:
34+
- dependency-name: "python"
35+
- dependency-name: "golang"
36+
- dependency-name: "securego/gosec"
37+
- dependency-name: "trufflesecurity/trufflehog"
38+
- dependency-name: "aquasec/trivy"
2639
labels:
2740
- "dependencies"
2841
- "docker"
@@ -37,6 +50,14 @@ updates:
3750
directory: "/"
3851
schedule:
3952
interval: "weekly"
53+
open-pull-requests-limit: 4
54+
groups:
55+
github-actions-minor-patch:
56+
patterns:
57+
- "*"
58+
update-types:
59+
- "minor"
60+
- "patch"
4061
labels:
4162
- "dependencies"
4263
- "github-actions"

0 commit comments

Comments
 (0)