Skip to content

Commit 532cd92

Browse files
authored
Merge pull request #406 from laurazard/disable-dependabot-versions
dependabot: disable version bump checks/only keep security updates
2 parents 02dae79 + 7d8722b commit 532cd92

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

.github/dependabot.yml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,10 @@ updates:
44
directory: "/"
55
schedule:
66
interval: weekly
7-
open-pull-requests-limit: 10
7+
# compose-go is a library, so to maximize compatibility for downstream
8+
# users with go's minimal version selection for dependencies we should
9+
# ignore version bumps and only update when there are security updates
10+
open-pull-requests-limit: 0
811
ignore:
912
- dependency-name: github.com/sirupsen/logrus
1013
versions:

0 commit comments

Comments
 (0)