From 04541ae664bf14114ee9d604d8ab86f6e21c7600 Mon Sep 17 00:00:00 2001 From: "dependabot-preview[bot]" <27856297+dependabot-preview[bot]@users.noreply.github.com> Date: Thu, 29 Apr 2021 19:40:00 +0000 Subject: [PATCH] Upgrade to GitHub-native Dependabot --- .github/dependabot.yml | 50 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 50 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..5881eed --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,50 @@ +version: 2 +updates: +- package-ecosystem: pip + directory: "/api" + schedule: + interval: daily + time: "08:00" + timezone: Europe/London + open-pull-requests-limit: 10 + allow: + - dependency-type: direct + - dependency-type: indirect + ignore: + - dependency-name: amqp + versions: + - 5.0.5 + - dependency-name: django + versions: + - 2.2.13 + - dependency-name: billiard + versions: + - 3.6.3.0 +- package-ecosystem: npm + directory: "/webapp" + schedule: + interval: daily + time: "08:00" + timezone: Europe/London + open-pull-requests-limit: 10 + ignore: + - dependency-name: eslint + versions: + - 7.18.0 + - 7.19.0 + - 7.20.0 + - 7.21.0 + - 7.22.0 + - 7.23.0 + - 7.24.0 + - dependency-name: react-tabs + versions: + - 3.2.0 + - 3.2.1 + - dependency-name: react + versions: + - 16.14.0 + - 17.0.1 + - dependency-name: gulp-strip-debug + versions: + - 3.0.0