diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..1251dfa --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,26 @@ +# Monthly, grouped. The dependency that matters is @cap2ui5/cds-plugin: while +# the plugin is 0.x a minor may change how apps are written and break the +# samples here, and this repository has no lockfile - an install gets the +# newest plugin the range allows. A bump has to show up here as a pull request +# that runs the tests, so a plugin release that breaks a sample is a red pull +# request, not a broken `npm install` for somebody trying the samples. +version: 2 +updates: + - package-ecosystem: npm + directory: / + schedule: + interval: monthly + open-pull-requests-limit: 5 + groups: + cap2ui5: + patterns: ["@cap2ui5/*"] + dependencies: + patterns: ["*"] + exclude-patterns: ["@cap2ui5/*"] + - package-ecosystem: github-actions + directory: / + schedule: + interval: monthly + groups: + actions: + patterns: ["*"] diff --git a/package.json b/package.json index ceb4465..356abc2 100644 --- a/package.json +++ b/package.json @@ -30,12 +30,12 @@ }, "dependencies": { "@cap-js/sqlite": "^3", - "@cap2ui5/cds-plugin": "^0.3.1", + "@cap2ui5/cds-plugin": "^0.4.0", "@sap/cds": "^10", "@sap/cds-rfc": "^2.2.1" }, "devDependencies": { - "@abap2ui5/linter": "^0.8.3", + "@abap2ui5/linter": "^0.8.5", "@cap-js/cds-test": "^1.0.2", "eslint": "^10", "fast-xml-parser": "^5.11.1"