Skip to content

Commit 985f9da

Browse files
authored
Merge pull request #3887 from plotly/fix/depbot-again
fix dependabot
2 parents 0c6b5a0 + be23759 commit 985f9da

1 file changed

Lines changed: 16 additions & 10 deletions

File tree

‎.github/dependabot.yml‎

Lines changed: 16 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,17 @@
11
version: 2
22
updates:
33
# Root package dependencies.
4-
# NOTE: listing more than one entry under `directories` makes Dependabot treat
5-
# "/" as a recursive glob, so it scans every nested package.json. The negated
6-
# globs below keep it out of directories that have their own update entry — the
7-
# components and the renderer carry narrow allow/ignore lists (e.g. react-docgen
8-
# is pinned) that the root entry would otherwise bypass. @plotly/* is internal.
4+
# NOTE: Dependabot's npm updater recurses from "/" into every nested
5+
# package.json, and neither the singular `directory` nor plural `directories`
6+
# with `!` exclusion globs stops that recursion. So the ONLY reliable way to
7+
# keep this entry from bumping the components/renderer (which carry their own
8+
# narrow allow/ignore lists, e.g. react-docgen is pinned) is the `allow` list
9+
# below: it names only packages that exist SOLELY in the root package.json, so
10+
# even while recursing, Dependabot opens root-only PRs. npm-run-all, rimraf and
11+
# @types/jest are intentionally omitted — they also live in the components and
12+
# would produce duplicate PRs.
913
- package-ecosystem: "npm"
10-
directories:
11-
- "/"
12-
- "!/@plotly/*"
13-
- "!/components/*"
14-
- "!/dash/dash-renderer"
14+
directory: "/"
1515
schedule:
1616
interval: "weekly"
1717
day: "monday"
@@ -26,6 +26,12 @@ updates:
2626
applies-to: security-updates
2727
patterns:
2828
- "*"
29+
allow:
30+
- dependency-name: "@lerna/*"
31+
- dependency-name: "@percy/cli"
32+
- dependency-name: "husky"
33+
- dependency-name: "lerna"
34+
- dependency-name: "lint-staged"
2935

3036
# Dash renderer
3137
- package-ecosystem: "npm"

0 commit comments

Comments
 (0)