ceph-csi/.github/dependabot.yml
Niels de Vos f7a024cf7b ci: disable dependabot PR creation
Dependabot does not need to report available updates for vendored
dependencies in the downstream repository. Updates to dependencies are
synced from the upstream repository when needed. There is also the
"Upstream First" requirement, which we follow closely.

See-also: https://docs.github.com/en/code-security/supply-chain-security/keeping-your-dependencies-updated-automatically/configuration-options-for-dependency-updates#open-pull-requests-limit
Signed-off-by: Niels de Vos <ndevos@redhat.com>
2021-09-01 08:46:09 +02:00

41 lines
1.5 KiB
YAML

---
version: 2
updates:
- package-ecosystem: "gomod"
# ODF only: disable PR creation, synced from upstream
open-pull-requests-limit: 0
directory: "/"
schedule:
interval: "weekly"
labels:
- rebase
commit-message:
prefix: "rebase"
ignore:
# k8s.io/kubernetes prevents auto-updating these
- dependency-name: "k8s.io/api"
- dependency-name: "k8s.io/apiextensions-apiserver"
- dependency-name: "k8s.io/apimachinery"
- dependency-name: "k8s.io/apiserver"
- dependency-name: "k8s.io/cli-runtime"
- dependency-name: "k8s.io/client-go"
- dependency-name: "k8s.io/cloud-provider"
- dependency-name: "k8s.io/cluster-bootstrap"
- dependency-name: "k8s.io/code-generator"
- dependency-name: "k8s.io/component-base"
- dependency-name: "k8s.io/component-helpers"
- dependency-name: "k8s.io/controller-manager"
- dependency-name: "k8s.io/cri-api"
- dependency-name: "k8s.io/csi-translation-lib"
- dependency-name: "k8s.io/kube-aggregator"
- dependency-name: "k8s.io/kube-controller-manager"
- dependency-name: "k8s.io/kube-proxy"
- dependency-name: "k8s.io/kube-scheduler"
- dependency-name: "k8s.io/kubectl"
- dependency-name: "k8s.io/kubelet"
- dependency-name: "k8s.io/legacy-cloud-providers"
- dependency-name: "k8s.io/metrics"
- dependency-name: "k8s.io/mount-utils"
- dependency-name: "k8s.io/pod-security-admission"
- dependency-name: "k8s.io/sample-apiserver"