chore: configure dependabot for monthly npm/composer update PRs #93
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
This sets up dependabot to create update PRs for npm/composer dependencies on a monthly schedule. To make the process of validating updates simple without risking unexpected breaking changes, the updates are grouped by minor/patch version vs. major version updates, by development vs. production dependencies, and by composer vs. npm dependencies.
Here's a PR for another project for adding a very similar config, and here's an example dependabot PR that updated all dev dependencies. The open question about this PR's config is whether Composer behaves the same way as npm.
Closes #92
To Validate
main
, but you can check the configuration options to make sure our usage is valid