diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 00000000..514b41f1 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,14 @@ +# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file +version: 2 +updates: + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "quarterly" # We do not need *immediate* bumps, only frequent enough to avoid falling out of support range. + cooldown: # Avoid bumping deps immediately, to give time for security audits to be conducted + default-days: 15 + include: [ * ] + groups: + actions: + labels: [ builds ] # Since those are CI-related updates... +