From 855f730841780d0f5d65f3cce24b31719834cec5 Mon Sep 17 00:00:00 2001 From: "dependabot-preview[bot]" <27856297+dependabot-preview[bot]@users.noreply.github.com> Date: Thu, 29 Apr 2021 16:06:36 +0000 Subject: [PATCH] Upgrade to GitHub-native Dependabot --- .github/dependabot.yml | 41 +++++++++++++++++++++++++++++++++++++++++ 1 file changed, 41 insertions(+) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 000000000..1f7c2c5b3 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,41 @@ +version: 2 +updates: +- package-ecosystem: maven + directory: "/" + schedule: + interval: daily + time: "03:00" + open-pull-requests-limit: 10 + target-branch: develop + ignore: + - dependency-name: org.owasp:dependency-check-maven + versions: + - 6.1.0 + - 6.1.1 + - 6.1.2 + - 6.1.3 + - 6.1.4 + - dependency-name: com.fasterxml.jackson.core:jackson-core + versions: + - 2.12.1 + - 2.12.2 + - dependency-name: com.fasterxml.jackson.core:jackson-annotations + versions: + - 2.12.1 + - 2.12.2 + - dependency-name: org.mockito:mockito-core + versions: + - 3.7.7 + - 3.8.0 + - dependency-name: com.sun.xml.bind:jaxb-core + versions: + - 3.0.0 + - dependency-name: org.json:json + versions: + - "20201115" + - dependency-name: org.glassfish.jaxb:jaxb-runtime + versions: + - 3.0.0 + - dependency-name: com.fasterxml.jackson.core:jackson-databind + versions: + - 2.12.1