auto-bump deps using dependabot

This commit is contained in:
hackerESQ
2025-09-05 18:24:15 -05:00
committed by GitHub
parent 8e625107c1
commit 3d944afeb4
+22
View File
@@ -0,0 +1,22 @@
# To get started with Dependabot version updates, you'll need to specify which
# package ecosystems to update and where the package manifests are located.
# Please see the documentation for all configuration options:
# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file
version: 2
updates:
- package-ecosystem: "composer"
directory: "/"
schedule:
interval: "monthly"
commit-message:
prefix: "composer-dependencies"
open-pull-requests-limit: 5
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "monthly"
commit-message:
prefix: "npm-dependencies"
open-pull-requests-limit: 5