mirror of
https://github.com/VictoriaMetrics/VictoriaMetrics.git
synced 2026-05-17 00:26:36 +03:00
Recent supply chain attacks on GitHub Actions and npm packages show the risk of pulling dependency updates too quickly: - https://socket.dev/blog/trivy-under-attack-again-github-actions-compromise - https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan
35 lines
816 B
YAML
35 lines
816 B
YAML
version: 2
|
|
updates:
|
|
- package-ecosystem: "github-actions"
|
|
directory: "/"
|
|
schedule:
|
|
interval: "daily"
|
|
cooldown:
|
|
default-days: 21
|
|
- package-ecosystem: "gomod"
|
|
directory: "/"
|
|
schedule:
|
|
interval: "weekly"
|
|
open-pull-requests-limit: 0
|
|
- package-ecosystem: "bundler"
|
|
directory: "/docs"
|
|
schedule:
|
|
interval: "weekly"
|
|
open-pull-requests-limit: 0
|
|
- package-ecosystem: "gomod"
|
|
directory: "/app/vmui/packages/vmui/web"
|
|
schedule:
|
|
interval: "weekly"
|
|
open-pull-requests-limit: 0
|
|
- package-ecosystem: "docker"
|
|
directory: "/"
|
|
schedule:
|
|
interval: "daily"
|
|
cooldown:
|
|
default-days: 21
|
|
- package-ecosystem: "npm"
|
|
directory: "/app/vmui/packages/vmui"
|
|
schedule:
|
|
interval: "weekly"
|
|
open-pull-requests-limit: 0
|