Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add dependabot config #1057

Merged
merged 2 commits into from
Dec 2, 2024
Merged

Add dependabot config #1057

merged 2 commits into from
Dec 2, 2024

Conversation

frankieroberto
Copy link
Contributor

This sets up Dependabot to monitor for both updates to GitHub Actions and NPM packages.

See Dependabot configuration for the different options.

Open to suggestions on the best update frequencies!

@paulrobertlloyd
Copy link
Contributor

I think monthly for both. Daily is too frequent and noisy, and sometimes you want to wait to make sure there are not further patches on previous patches.

@frankieroberto
Copy link
Contributor Author

@paulrobertlloyd yeah that might make sense, especially for a frontend library which is only released every few weeks anyway. I think Dependabot might still flag security updates more quickly?

@paulrobertlloyd paulrobertlloyd merged commit 272b562 into main Dec 2, 2024
5 checks passed
@paulrobertlloyd paulrobertlloyd deleted the add-dependabot-config branch December 2, 2024 12:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants