Files
backnotprop__plannotator/.github/dependabot.yml
Michael Ramos d4ce3dcb57 ci: harden releases and add security scanning (#1274)
* ci: harden release and add security scanning

* Harden release and deploy recovery paths

* Fix npm artifact pack destinations
2026-08-12 11:40:15 -07:00

24 lines
586 B
YAML

version: 2
# Dependabot owns Bun workspace updates. Renovate owns GitHub Actions.
updates:
- package-ecosystem: bun
directory: /
schedule:
interval: weekly
day: monday
time: "05:00"
timezone: America/Los_Angeles
# Delay routine releases long enough for ecosystem problems to surface.
# Dependabot security updates do not observe this cooldown.
cooldown:
default-days: 7
open-pull-requests-limit: 5
groups:
bun-minor-and-patch:
patterns:
- "*"
update-types:
- minor
- patch