diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 000000000..94da15da2 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,24 @@ +# To get started with Dependabot version updates, you'll need to specify which +# package ecosystems to update and where the package manifests are located. +# Please see the documentation for all configuration options: +# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file + +version: 2 +updates: + # Keep npm dependencies up to date + - package-ecosystem: 'npm' + directory: '/' # root package.json + schedule: + interval: 'weekly' + + # Keep GitHub Actions up to date + - package-ecosystem: 'github-actions' + directory: '/' + schedule: + interval: 'weekly' + + # Keep Docker images up to date + - package-ecosystem: 'docker' + directory: '/docker' + schedule: + interval: 'weekly' diff --git a/CHANGELOG.md b/CHANGELOG.md index aa78ea5c0..6b87f45a5 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,8 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## Unreleased +- Added dependabot for version update + ### Changed - Eliminated `uuid` in favor of using `randomUUID` from `node:crypto`