Skip to content

chore: update dependabot config to group security updates - #1158

Open
ReneSchroederLJ wants to merge 1 commit into
eclipse-tractusx:mainfrom
achtzig20:chore/update-dependabot-config
Open

chore: update dependabot config to group security updates#1158
ReneSchroederLJ wants to merge 1 commit into
eclipse-tractusx:mainfrom
achtzig20:chore/update-dependabot-config

Conversation

@ReneSchroederLJ

Copy link
Copy Markdown
Member

Description

  • added rule for "pip" package ecosystem
  • included "/local/" in npm rule
  • added security update groups per package ecosystem

Pre-review checks

Please ensure to do as many of the following checks as possible, before asking for committer review:

  • DEPENDENCIES are up-to-date. Dash license tool. Committers can open IP issues for restricted libs.
  • Copyright and license header are present on all affected files (TRG 7.02)
  • Documentation Notice are present on all affected files (TRG 7.07)
  • If helm chart has been changed, the chart version has been bumped to either next major, minor or patch level (compared to released chart).
  • Changelog updated (changelog.md) with PR reference and brief summary.
  • Frontend version bumped, if needed (frontend/package.json, frontend/package-lock.json)
  • Backend version bumped, if needed (backend/pom.xml)
  • Open API specification updated, if controllers have been changed (use python script scripts/generate_openapi_yaml.py with running customer backend)

@tom-rm-meyer-ISST tom-rm-meyer-ISST left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks a lot!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants