Skip to content

Dependabot should ignore npm packages, and only update ruby gems#175

Merged
bshand merged 1 commit intodevelopfrom
feature/dependabot_ignore_npm
Feb 23, 2026
Merged

Dependabot should ignore npm packages, and only update ruby gems#175
bshand merged 1 commit intodevelopfrom
feature/dependabot_ignore_npm

Conversation

@bshand
Copy link
Contributor

@bshand bshand commented Feb 20, 2026

Restrict Dependabot to ruby gem updates only, so that we can enable it.

This PR updates Dependabot rules to ignore all npm updates, because we have our own GitHub Actions solution using yarn audit, and because Dependabot cannot populate vendor/npm-packages-offline-cache/

@bshand bshand merged commit dc3c542 into develop Feb 23, 2026
10 of 15 checks passed
@bshand bshand deleted the feature/dependabot_ignore_npm branch February 23, 2026 23:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant