.github/dependabot.yml
# https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file
version: 2
updates:
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
day: monday
time: "10:00"
commit-message:
prefix: ci
prefix-development: ci
include: scope
labels:
- pinned
- dependencies
- gha
- package-ecosystem: maven
directory: /
schedule:
interval: weekly
day: monday
time: "10:00"
commit-message:
prefix: fix
prefix-development: build
include: scope
labels:
- pinned
- dependencies
- mvn
ignore:
- dependency-name: "org.springframework:*"
update-types: ["version-update:semver-major"]
# these dependencies are only used by TypesTest and need to have stable versions
- dependency-name: "jdom:jdom"
- dependency-name: "org.eclipse.platform:org.eclipse.urischeme"
- dependency-name: "org.netbeans.external:*"
- dependency-name: "jakarta.*"