Skip to content

Commit

Permalink
Merge pull request #659 from eclipse-tractusx/docs/publish_dependabot…
Browse files Browse the repository at this point in the history
…_trg

docs: publish Dependabot TRG
  • Loading branch information
tomaszbarwicki authored Mar 1, 2024
2 parents a73fa43 + 666c60c commit 8443ef4
Showing 1 changed file with 3 additions and 1 deletion.
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ title: TRG 2.06 - Dependabot

| Status | Created | Post-History |
|--------|--------------|-----------------|
| Active | 12-Feb-2024 | Publish TRG |
| Draft | 4-Jan-2024 | Initial release |

## Why
Expand Down Expand Up @@ -36,7 +37,8 @@ To enable Dependabot for version updates, create a dependabot.yml file in .githu

### Example

This configuration checks for Maven, GitHub Action and Docker updates on a weekly basis and creates pull requests for up to 5 updates at a time.
A basic example of a dependabot.yml file, demonstrating configurations for for Maven, GitHub Action and Docker ([all options](https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#package-ecosystem)), is shown below:
Please note the interval, open pull requests limits as well as other parameters can be customized according to preferences.

:::caution
Be careful, Dependabot PR merge can lead to out of date DEPENDENCIES file.
Expand Down

0 comments on commit 8443ef4

Please sign in to comment.