From d47d85225c9a235f01eadf372fdad32286d508e3 Mon Sep 17 00:00:00 2001 From: Aston Yong Date: Tue, 6 Aug 2024 16:11:00 -0700 Subject: [PATCH] Update Dependabot to catch vulnerabilities in Dockerfile base images. --- .github/dependabot.yml | 41 ++++++++++++++++++++++++++++------------- 1 file changed, 28 insertions(+), 13 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index f2c04c71a..b5b1a4963 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -16,20 +16,35 @@ version: 2 updates: +- package-ecosystem: docker + directory: /nvidia-driver-installer/ubuntu + schedule: + interval: weekly +- package-ecosystem: docker + directory: /nvidia-driver-installer/minikube + schedule: + interval: weekly +- package-ecosystem: docker + directory: /partition_gpu + schedule: + interval: weekly +- package-ecosystem: docker + directory: /fast-socket-installer/image + schedule: + interval: weekly +- package-ecosystem: docker + directory: /demo/gpu-error/illegal-memory-access + schedule: + interval: weekly +- package-ecosystem: docker + directory: / + schedule: + interval: weekly - package-ecosystem: gomod directory: / - labels: - - dependencies - - go schedule: interval: weekly - day: monday - time: "03:00" - timezone: America/Los_Angeles - target-branch: develop - reviewers: - - grac3gao - - Jiaqicao257 - - aston-github - - elfinhe - - samuelkarp \ No newline at end of file + groups: + gomod-dependencies: + patterns: + - '*'