# To get started with Dependabot version updates, you'll need to specify which
# package ecosystems to update and where the package manifests are located.
# Please see the documentation for all configuration options:
# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file

version: 2
updates:
  # Enable version updates for npm
  - package-ecosystem: "npm"
    # Look for `package.json` and `lock` files in the `root` directory
    directory: "/"
    # Check the npm registry for updates once every week on a weekday
    schedule:
      interval: "weekly"
    ignore:
      # TypeScript 7 (the native port) is not yet supported by typescript-eslint,
      # so major bumps break the lint job (and dependency resolution in CI).
      # See https://github.com/typescript-eslint/typescript-eslint/issues/10940
      # Re-enable once typescript-eslint ships TS >=7 support.
      - dependency-name: "typescript"
        update-types: ["version-update:semver-major"]
    versioning-strategy: "increase"
    labels:
      - dependabot
      - dependencies
      - javascript
      - semver-patch
    groups:
      patch-updates:
        update-types:
          - "patch"
      minor-updates:
        update-types:
          - "minor"
