Skip to content

Commit

Permalink
Remove allow list from Dependabot config
Browse files Browse the repository at this point in the history
In [RFC-153](alphagov/govuk-rfcs#153), we proposed and agreed to remove 'allow lists' from all [GOV.UK](http://gov.uk/) Dependabot configs, in order to re-enable security updates.

Trello card: https://trello.com/c/DuA0q9Ck/2966-remove-allow-lists-from-dependabot-configs-2
  • Loading branch information
sihugh committed Jan 31, 2023
1 parent d4c9c61 commit 1dec4b7
Showing 1 changed file with 1 addition and 24 deletions.
25 changes: 1 addition & 24 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,30 +4,7 @@ updates:
directory: /
schedule:
interval: daily
allow:
# Security updates
- dependency-name: brakeman
dependency-type: direct
# Internal gems
- dependency-name: "govuk*"
dependency-type: direct
- dependency-name: "rubocop-govuk"
dependency-type: direct
- dependency-name: gds-api-adapters
dependency-type: direct
- dependency-name: gds-sso
dependency-type: direct
- dependency-name: plek
dependency-type: direct
# Framework gems
- dependency-name: mongo
dependency-type: direct
- dependency-name: factory_bot_rails
dependency-type: direct
- dependency-name: rails
dependency-type: direct
- dependency-name: rspec-rails
dependency-type: direct

- package-ecosystem: docker
directory: /
schedule:
Expand Down

0 comments on commit 1dec4b7

Please sign in to comment.