YAML examples in this folder illustrate optional pieces of a Dependabot version updates configuration. Place a real config at .github/dependabot.yml in your repository.
Every dependabot.yml uses syntax version 2 and declares one or more package managers under updates. Each entry must include:
From GitHub’s documentation, a minimal shape looks like this:
version: 2
updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "daily"- Overview: Configuring Dependabot version updates
- Required and optional keys: Configuration options for the dependabot.yml file
Optional top-level sections (for example registries for private packages) are documented in the same options reference.
Each .yml file starts with a harmonized comment header:
- One-line summary (first comment line).
- Description (blank line, then what the snippet covers and which options matter).
Documentation:(blank line, then bullet links to official GitHub docs).
Copy the relevant keys into your own updates entries, or combine several patterns into one file, keeping a single version: 2 and merging lists under updates as needed.
Dependabot currently does not support include / extends for sharing one dependabot.yml across many repositories: each repository keeps its own .github/dependabot.yml on the default branch. This has been discussed in the community for a long time (for example dependabot-core #2015 and dependabot-core #1065), so teams usually standardize with templates/automation that copy or generate per-repo files.