Multi Branch Setup in Dependabot¶
In the Equinor GitHub organization, Dependabot alerts and security updates are enabled by organization policy; you do not need to enable them manually. Version updates still require repository configuration.
To configure Dependabot version updates for multiple branches, use the target-branch property in .github/dependabot.yml. This controls version updates only; Dependabot security updates target the default branch.
-
Create or Edit the
dependabot.ymlFile:- On your repository's default branch, navigate to the
.githubdirectory. - Create or edit the
dependabot.ymlfile to specify configurations for each branch.
- On your repository's default branch, navigate to the
-
Define Updates for Multiple Branches:
- Use the
updateskey in thedependabot.ymlfile to define configurations for each branch. - Replace
package-ecosystem,directory,schedule, andtarget-branchwith values specific to your repository.
- Use the
Example:
version: 2
updates:
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "daily"
target-branch: "main"
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
target-branch: "development"