Skip to content

Commit ee437c0

Browse files
authored
Chore: [AEA-0000] - stagger dependabot (#88)
## Summary - Routine Change ### Details - stagger dependabot
1 parent dac60c1 commit ee437c0

File tree

3 files changed

+10
-6
lines changed

3 files changed

+10
-6
lines changed

.gitallowed

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,3 +7,4 @@ self\.token = token
77
token = os\.environ\.get\(\"GH_TOKEN\"\)
88
poetry\.lock
99
\-Dsonar\.token=\"\$SONAR_TOKEN\"
10+
token: "\${{ steps\.generate-token\.outputs\.token }}"

.github/dependabot.yaml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -14,28 +14,28 @@ updates:
1414
prefix: "Upgrade: [dependabot] - "
1515

1616
###################################
17-
# NPM workspace ##################
17+
# Poetry #########################
1818
###################################
19-
- package-ecosystem: "npm"
19+
- package-ecosystem: "pip"
2020
directory: "/"
2121
schedule:
2222
interval: "weekly"
2323
day: "thursday"
24-
time: "18:00" # UTC
24+
time: "20:00" # UTC
2525
open-pull-requests-limit: 20
2626
versioning-strategy: increase
2727
commit-message:
2828
prefix: "Upgrade: [dependabot] - "
2929

3030
###################################
31-
# Poetry #########################
31+
# NPM workspace ##################
3232
###################################
33-
- package-ecosystem: "pip"
33+
- package-ecosystem: "npm"
3434
directory: "/"
3535
schedule:
3636
interval: "weekly"
3737
day: "thursday"
38-
time: "18:00" # UTC
38+
time: "22:00" # UTC
3939
open-pull-requests-limit: 20
4040
versioning-strategy: increase
4141
commit-message:

.trivyignore.yaml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,3 +22,6 @@ vulnerabilities:
2222
- id: CVE-2026-29786
2323
statement: tar vulnerability accepted as risk - dependency of npm (multiple)
2424
expired_at: 2026-06-01
25+
- id: CVE-2026-31802
26+
statement: tar vulnerability accepted as risk - dependency of npm (multiple)
27+
expired_at: 2026-06-01

0 commit comments

Comments
 (0)