veza/.github/dependabot.yml
senke ff5d6736f8 ci: add Dependabot configuration for automated dependency updates
Configure weekly automated dependency update PRs for all ecosystems:

- gomod: /veza-backend-api (Go modules)
- cargo: /veza-chat-server, /veza-stream-server (Rust crates)
- npm: /apps/web (frontend packages)
- github-actions: / (CI action versions)

Each ecosystem gets appropriate labels for easy triage.

Addresses audit finding A06: no automated dependency update mechanism.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-02-11 23:26:18 +01:00

31 lines
719 B
YAML

version: 2
updates:
- package-ecosystem: "gomod"
directory: "/veza-backend-api"
schedule:
interval: "weekly"
labels: ["dependencies", "go"]
- package-ecosystem: "cargo"
directory: "/veza-chat-server"
schedule:
interval: "weekly"
labels: ["dependencies", "rust"]
- package-ecosystem: "cargo"
directory: "/veza-stream-server"
schedule:
interval: "weekly"
labels: ["dependencies", "rust"]
- package-ecosystem: "npm"
directory: "/apps/web"
schedule:
interval: "weekly"
labels: ["dependencies", "frontend"]
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
labels: ["dependencies", "ci"]