# See: https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#about-the-dependabotyml-file version: 2 updates: # Configure check for outdated GitHub Actions actions in workflows. # See: https://docs.github.com/code-security/dependabot/working-with-dependabot/keeping-your-actions-up-to-date-with-dependabot - package-ecosystem: github-actions directory: / # Check the repository's workflows under /.github/workflows/ schedule: interval: daily # Configure check for outdated base image digest in the Dockerfile. # See: https://docs.docker.com/build/building/best-practices/#pin-base-image-versions - package-ecosystem: docker directory: / # Check the repository's Dockerfile at /Dockerfile schedule: interval: weekly # Configure check for outdated codespell version in requirements.txt. - package-ecosystem: pip directory: / # Check the repository's Python dependencies at /requirements.txt schedule: interval: daily