Files
editor/.github/dependabot.yml
T
John Carmack 01bd751d5f ci: keep the CodeQL actions on one version (#2133)
CodeQL has been failing on main since #2105: `init` is on v4.37.9 while
`autobuild` and `analyze` are on v4.37.8, and the action rejects a
config written by a newer version ("Loaded a configuration file for
version '4.37.9', but running version '4.37.8'"). Dependabot bumps the
three steps in separate pull requests, so #2119 and #2120 each still
fail on their own and main has gone red at every partial bump (08-19,
08-28, today).

This moves the two steps to v4.37.9, the same commit dependabot picked
in #2119 and #2120, and groups `github/codeql-action*` in dependabot so
the three bump together from now on. Supersedes #2119 and #2120.

## Launch Checklist

 - [x] Briefly describe the changes in this PR.
- [ ] Add an entry to `CHANGELOG.md` under the `## main` section (not
applicable, CI only).
2026-09-04 23:55:48 +03:00

44 lines
1.2 KiB
YAML

# To get started with Dependabot version updates, you'll need to specify which
# package ecosystems to update and where the package manifests are located.
# Please see the documentation for all configuration options:
# https://help.github.com/github/administering-a-repository/configuration-options-for-dependency-updates
version: 2
updates:
- package-ecosystem: "npm" # See documentation for possible values
directory: "/" # Location of package manifests
schedule:
interval: "daily"
open-pull-requests-limit: 20
versioning-strategy: increase
groups:
vitest:
patterns:
- "*vitest*"
react:
patterns:
- "*react*"
cooldown:
default-days: 5
semver-major-days: 5
semver-minor-days: 3
semver-patch-days: 3
include:
- "*"
exclude:
- "@maplibre/*"
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "daily"
groups:
codeql-action:
patterns:
- "github/codeql-action*"
cooldown:
default-days: 3
# no semver support for github-actions
# => no specific configuration for this
include:
- "*"