Skip to content
Merged
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
62 changes: 62 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,62 @@
version: 2
updates:
# pnpm workspace. The root entry reads pnpm-workspace.yaml, so it covers the
# root package.json, packages/core and plugins/vscode in pnpm-lock.yaml.
# Synced content stays out of scope: plugins/<ide>/skills are byte-identical
# copies of volcano-skills with no manifests, and there is deliberately no
# gitsubmodule entry, because sync-skills.yml moves sources/volcano-skills
# together with those copies (a bare gitlink bump fails check:skill-drift).
# tests/e2e-agent-eval is local test tooling with no lockfile.
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
open-pull-requests-limit: 5
# Supply-chain safeguard: skip releases until they have aged.
cooldown:
default-days: 5
semver-major-days: 14
# No dependency labels exist in this repo; [] stops Dependabot creating them.
labels: []
# release-please releases on fix/feat. These are build and test tools, so
# chore(deps) keeps them out of releases and the changelog.
commit-message:
prefix: "chore"
include: "scope"
groups:
# Minor and patch updates share one PR; each major gets its own PR.
npm-minor-patch:
patterns:
- "*"
update-types:
- "minor"
- "patch"
ignore:
# Must not exceed plugins/vscode engines.vscode, or vsce refuses to
# package; raise both together when the minimum VS Code version moves.
- dependency-name: "@types/vscode"
# Tracks the Node.js 24 engine; move it with a Node upgrade.
- dependency-name: "@types/node"
update-types:
- "version-update:semver-major"

# Keep SHA-pinned GitHub Actions (and their `# vX.Y.Z` comments) current.
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
open-pull-requests-limit: 5
# GitHub Actions supports only default-days, not per-SemVer cooldowns.
cooldown:
default-days: 5
labels: []
commit-message:
prefix: "ci"
include: "scope"
groups:
github-actions:
patterns:
- "*"
update-types:
- "minor"
- "patch"
Loading