Skip to content

Commit 24651cd

Browse files
committed
Enable Dependabot updates for transitive dependencies
Configure Dependabot's `allow` key with `dependency-type: all` so it also updates transitive dependencies (those only in the lockfile), not just direct dependencies. This removes the need to manually refresh lockfiles. https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#allow-- GUS-W-24099599.
1 parent c860df6 commit 24651cd

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

‎.github/dependabot.yml‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,4 +4,7 @@ updates:
44
directory: "/"
55
schedule:
66
interval: "monthly"
7+
allow:
8+
# Update transitive dependencies too.
9+
- dependency-type: "all"
710
versioning-strategy: increase-if-necessary

0 commit comments

Comments
 (0)