From f70fcd9aefc3d6972d9898ae59b9a74eeb2cabd3 Mon Sep 17 00:00:00 2001 From: Violeta Georgieva Date: Tue, 19 Mar 2024 12:11:19 +0200 Subject: [PATCH] Update dependabot configuration --- .github/dependabot.yml | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 7852b92..995ab34 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -14,6 +14,8 @@ updates: # Don't update Reactor projects - dependency-name: io.projectreactor:* - dependency-name: io.projectreactor.addons:* + # JSR305 backport is fixed to last version with annotations (3.0.1) + - dependency-name: "com.google.code.findbugs:jsr305" # Versions > 6.13 require JDK11+ - dependency-name: com.diffplug.spotless versions: @@ -29,6 +31,13 @@ updates: - dependency-name: org.slf4j:* versions: - "[2.a, 3]" + - dependency-name: ch.qos.logback:logback-classic + versions: + - "[1.3.a, 1.6]" + # artifactory: don't upgrade to v5 + - dependency-name: "com.jfrog.artifactory" + versions: + - ">= 5.0.a" rebase-strategy: disabled - package-ecosystem: github-actions directory: "/"