Skip to content

Commit 01434fe

Browse files
authored
Distinguish prod and dev dependentbot update (#39)
* Distinguish prod and dev dependentbot update * Including scope make it explicit enough * Upgrade only lockfile
1 parent 2fc7f78 commit 01434fe

File tree

1 file changed

+20
-0
lines changed

1 file changed

+20
-0
lines changed

.github/dependabot.yml

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
# To get started with Dependabot version updates, you'll need to specify which
2+
# package ecosystems to update and where the package manifests are located.
3+
# Please see the documentation for all configuration options:
4+
# https://help.github.com/github/administering-a-repository/configuration-options-for-dependency-updates
5+
6+
version: 2
7+
updates:
8+
- package-ecosystem: "npm" # See documentation for possible values
9+
directory: "/" # Location of package manifests
10+
schedule:
11+
interval: "daily"
12+
versioning-strategy: lockfile-only
13+
commit-message:
14+
prefix: "npm"
15+
include: "scope"
16+
allow: # Only consider run time dependencies:
17+
- dependency-type: "production"
18+
ignore: # Don't update major and minor to keep compatibility with older jupyterlab
19+
- dependency-name: '*'
20+
update-types: ["version-update:semver-major", "version-update:semver-minor"]

0 commit comments

Comments
 (0)