Skip to content

Commit 730fc98

Browse files
authored
Merge pull request #4396 from github/nickrolfe/cooldown
Add 3-day cooldown for Dependabot and npm
2 parents 5c4618e + 721fe80 commit 730fc98

2 files changed

Lines changed: 8 additions & 0 deletions

File tree

.github/dependabot.yml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,8 @@ version: 2
22
updates:
33
- package-ecosystem: "npm"
44
directory: "extensions/ql-vscode"
5+
cooldown:
6+
default-days: 3
57
schedule:
68
interval: "weekly"
79
day: "thursday" # Thursday is arbitrary
@@ -32,13 +34,17 @@ updates:
3234
- "@typescript-eslint/*"
3335
- package-ecosystem: "github-actions"
3436
directory: "/"
37+
cooldown:
38+
default-days: 3
3539
schedule:
3640
interval: "weekly"
3741
day: "thursday" # Thursday is arbitrary
3842
labels:
3943
- "Update dependencies"
4044
- package-ecosystem: docker
4145
directory: "extensions/ql-vscode/test/e2e/docker"
46+
cooldown:
47+
default-days: 3
4248
schedule:
4349
interval: "weekly"
4450
day: "thursday" # Thursday is arbitrary

extensions/ql-vscode/.npmrc

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,2 +1,4 @@
11
# Storybook requires this option to be set. See https://github.com/storybookjs/storybook/issues/18298
22
legacy-peer-deps=true
3+
# Supply chain security: require packages to be at least 3 days old before install
4+
min-release-age=3

0 commit comments

Comments
 (0)