The same rules the hooks enforce locally, run where they cannot be skipped with --no-verify: lint, typecheck, tests, commit messages and the branch policy. typecheck and test are scoped with `turbo --affected` against the PR base, which is the one deliberate difference from `make preflight` — locally there is no base to diff against, so it runs repo-wide.
40 lines
937 B
YAML
40 lines
937 B
YAML
version: 2
|
|
|
|
# dependabot/* is on branch-policy.yml's allowlist precisely so these PRs can
|
|
# target main without a release branch.
|
|
updates:
|
|
- package-ecosystem: npm
|
|
directory: /
|
|
schedule:
|
|
interval: weekly
|
|
day: monday
|
|
open-pull-requests-limit: 10
|
|
labels:
|
|
- dependencies
|
|
commit-message:
|
|
prefix: "chore(deps)"
|
|
prefix-development: "chore(deps-dev)"
|
|
groups:
|
|
# Minor and patch bumps land as one PR; majors stay individual so a
|
|
# breaking change is never buried in a batch of twelve.
|
|
npm-minor-patch:
|
|
update-types:
|
|
- minor
|
|
- patch
|
|
|
|
- package-ecosystem: github-actions
|
|
directory: /
|
|
schedule:
|
|
interval: weekly
|
|
day: monday
|
|
open-pull-requests-limit: 5
|
|
labels:
|
|
- dependencies
|
|
- github-actions
|
|
commit-message:
|
|
prefix: "ci(deps)"
|
|
groups:
|
|
github-actions:
|
|
patterns:
|
|
- "*"
|