Skip to content

Commit c5b7a13

Browse files
authored
security: Delay dependabot updates (#125)
7 days should be enough when most malicious packages are patched within 24 hours.
1 parent 859742d commit c5b7a13

1 file changed

Lines changed: 20 additions & 18 deletions

File tree

.github/dependabot.yml

Lines changed: 20 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -1,20 +1,22 @@
11
version: 2
22
updates:
3-
- package-ecosystem: nuget
4-
directory: "/"
5-
schedule:
6-
interval: daily
7-
timezone: Europe/Lisbon
8-
open-pull-requests-limit: 10
9-
ignore:
10-
- dependency-name: SonarAnalyzer.VisualBasic
11-
versions:
12-
- 8.17.0.26580
13-
- 8.18.0.27296
14-
- 8.19.0.28253
15-
- 8.20.0.28934
16-
- 8.21.0.30542
17-
- dependency-name: ReverseMarkdown
18-
versions:
19-
- 3.15.0
20-
- 3.18.0
3+
- package-ecosystem: nuget
4+
directory: "/"
5+
schedule:
6+
interval: daily
7+
timezone: Europe/Lisbon
8+
open-pull-requests-limit: 10
9+
ignore:
10+
- dependency-name: SonarAnalyzer.VisualBasic
11+
versions:
12+
- 8.17.0.26580
13+
- 8.18.0.27296
14+
- 8.19.0.28253
15+
- 8.20.0.28934
16+
- 8.21.0.30542
17+
- dependency-name: ReverseMarkdown
18+
versions:
19+
- 3.15.0
20+
- 3.18.0
21+
cooldown:
22+
default-days: 7

0 commit comments

Comments
 (0)