👷 github每日扫描依赖并创建PR

This commit is contained in:
徐晓伟 2023-05-08 08:09:00 +08:00
parent 8f026ada0f
commit 1911f1847b

30
.github/dependabot.yml vendored Normal file
View File

@ -0,0 +1,30 @@
# To get started with Dependabot version updates, you'll need to specify which
# package ecosystems to update and where the package manifests are located.
# Please see the documentation for all configuration options:
# https://docs.github.com/github/administering-a-repository/configuration-options-for-dependency-updates
# https://docs.github.com/zh/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file
version: 2
updates:
- package-ecosystem: "maven" # See documentation for possible values
directory: "/" # Location of package manifests
schedule:
interval: "daily"
# https://docs.github.com/zh/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#ignore
ignore:
- dependency-name: org.springframework.boot:spring-boot-dependencies
# spring-boot 3.0 不支持 JDK 8
versions:
- ">= 3"
- dependency-name: org.springframework.cloud:spring-cloud-dependencies
# spring-cloud 2022 不支持 JDK 8
versions:
- ">= 2022"
- dependency-name: de.codecentric:spring-boot-admin-dependencies
# spring-boot-admin 3.0 不支持 JDK 8
versions:
- ">= 3"
- dependency-name: org.springframework.security:spring-security-oauth2-authorization-server
# spring-security-oauth2-authorization-server 1.0 不支持 JDK 8
versions:
- ">= 1"