diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 5d1023a..631d972 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,24 +1,46 @@ # Dependabot configuration for MyBudget-bot. # Keeps NuGet, GitHub Actions and the Docker base image up to date and surfaces # known vulnerabilities as security alerts/PRs. +# +# Tuned to stay quiet and safe: +# - monthly schedule and rebase-strategy: disabled → no weekly PR/rebase churn. +# - explicit open-pull-requests-limit for every ecosystem. +# - major version updates are ignored on purpose: majors are planned manual +# upgrades (framework migrations, base image jumps), not bot PRs. Minor and +# patch updates keep flowing, grouped into one PR per ecosystem. +# - Dependabot security alerts are not affected by these settings. version: 2 updates: - package-ecosystem: "nuget" directory: "/" schedule: - interval: "weekly" + interval: "monthly" open-pull-requests-limit: 5 + rebase-strategy: disabled groups: nuget-minor-patch: patterns: ["*"] update-types: ["minor", "patch"] + ignore: + - dependency-name: "*" + update-types: ["version-update:semver-major"] - package-ecosystem: "github-actions" directory: "/" schedule: - interval: "weekly" + interval: "monthly" + open-pull-requests-limit: 5 + rebase-strategy: disabled + ignore: + - dependency-name: "*" + update-types: ["version-update:semver-major"] - package-ecosystem: "docker" directory: "/docker/app" schedule: - interval: "weekly" + interval: "monthly" + open-pull-requests-limit: 5 + rebase-strategy: disabled + ignore: + - dependency-name: "*" + update-types: ["version-update:semver-major"]