version: 2 updates: # Enable version updates for npm - package-ecosystem: "npm" directory: "/" schedule: interval: "weekly" day: "monday" time: "09:00" open-pull-requests-limit: 10 reviewers: - "barsa" labels: - "dependencies" - "security" # Group updates together to reduce PR noise groups: # Group all non-security updates development-dependencies: dependency-type: "development" update-types: - "minor" - "patch" production-dependencies: dependency-type: "production" update-types: - "minor" - "patch" # Auto-merge patch updates for dev dependencies allow: - dependency-type: "development" update-types: ["patch"] # Ignore specific packages if needed ignore: # Example: ignore major version updates for specific packages # - dependency-name: "next" # update-types: ["version-update:semver-major"] versioning-strategy: increase commit-message: prefix: "chore(deps)" prefix-development: "chore(deps-dev)" include: "scope" # Monitor GitHub Actions - package-ecosystem: "github-actions" directory: "/" schedule: interval: "weekly" day: "monday" time: "09:00" labels: - "github-actions" - "security" commit-message: prefix: "ci" # Monitor Docker dependencies if you're using Docker - package-ecosystem: "docker" directory: "/docker" schedule: interval: "weekly" day: "monday" time: "09:00" labels: - "docker" - "security" commit-message: prefix: "chore(docker)"