11version : 2
22updates :
33 # Root package dependencies.
4- # NOTE: listing more than one entry under `directories` makes Dependabot treat
5- # "/" as a recursive glob, so it scans every nested package.json. The negated
6- # globs below keep it out of directories that have their own update entry — the
7- # components and the renderer carry narrow allow/ignore lists (e.g. react-docgen
8- # is pinned) that the root entry would otherwise bypass. @plotly/* is internal.
4+ # NOTE: Dependabot's npm updater recurses from "/" into every nested
5+ # package.json, and neither the singular `directory` nor plural `directories`
6+ # with `!` exclusion globs stops that recursion. So the ONLY reliable way to
7+ # keep this entry from bumping the components/renderer (which carry their own
8+ # narrow allow/ignore lists, e.g. react-docgen is pinned) is the `allow` list
9+ # below: it names only packages that exist SOLELY in the root package.json, so
10+ # even while recursing, Dependabot opens root-only PRs. npm-run-all, rimraf and
11+ # @types/jest are intentionally omitted — they also live in the components and
12+ # would produce duplicate PRs.
913 - package-ecosystem : " npm"
10- directories :
11- - " /"
12- - " !/@plotly/*"
13- - " !/components/*"
14- - " !/dash/dash-renderer"
14+ directory : " /"
1515 schedule :
1616 interval : " weekly"
1717 day : " monday"
@@ -26,6 +26,12 @@ updates:
2626 applies-to : security-updates
2727 patterns :
2828 - " *"
29+ allow :
30+ - dependency-name : " @lerna/*"
31+ - dependency-name : " @percy/cli"
32+ - dependency-name : " husky"
33+ - dependency-name : " lerna"
34+ - dependency-name : " lint-staged"
2935
3036 # Dash renderer
3137 - package-ecosystem : " npm"
0 commit comments