Skip to content

Latest commit

 

History

5 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Dependabot snippet library

YAML examples in this folder illustrate optional pieces of a Dependabot version updates configuration. Place a real config at .github/dependabot.yml in your repository.

Base skeleton

Every dependabot.yml uses syntax version 2 and declares one or more package managers under updates. Each entry must include:

From GitHub’s documentation, a minimal shape looks like this:

version: 2
updates:
  - package-ecosystem: "npm"
    directory: "/"
    schedule:
      interval: "daily"

Optional top-level sections (for example registries for private packages) are documented in the same options reference.

How the snippets are organized

Each .yml file starts with a harmonized comment header:

  1. One-line summary (first comment line).
  2. Description (blank line, then what the snippet covers and which options matter).
  3. Documentation: (blank line, then bullet links to official GitHub docs).

Copy the relevant keys into your own updates entries, or combine several patterns into one file, keeping a single version: 2 and merging lists under updates as needed.

Extra notes

Dependabot currently does not support include / extends for sharing one dependabot.yml across many repositories: each repository keeps its own .github/dependabot.yml on the default branch. This has been discussed in the community for a long time (for example dependabot-core #2015 and dependabot-core #1065), so teams usually standardize with templates/automation that copy or generate per-repo files.

About

Contains examples of Dependabot configs for Version Updates

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors