mirror of
https://github.com/twentyhq/twenty.git
synced 2026-04-22 16:01:20 -04:00
Exclude community apps from Dependabot scanning (#17345)
## Summary - Adds `exclude-paths` configuration to Dependabot to skip `packages/twenty-apps/community/**` - Community-maintained apps have their own dependency management and don't need the same security requirements as core packages ## Test plan - Verify Dependabot no longer creates alerts/PRs for dependencies in community apps
This commit is contained in:
2
.github/dependabot.yml
vendored
2
.github/dependabot.yml
vendored
@@ -2,6 +2,8 @@ version: 2
|
||||
updates:
|
||||
- package-ecosystem: "npm"
|
||||
directory: "/"
|
||||
exclude-paths:
|
||||
- "packages/twenty-apps/community/**"
|
||||
schedule:
|
||||
interval: "weekly"
|
||||
open-pull-requests-limit: 3
|
||||
|
||||
Reference in New Issue
Block a user