Compare commits

...

1 Commits

Author SHA1 Message Date
hainenber
2b0805e55f feat(sec): delays version-bumping PR to avoid prematurely usage of compromised packages
Co-authored-by: Copilot <copilot@github.com>
Signed-off-by: hainenber <dotronghai96@gmail.com>
2026-04-30 20:51:54 +07:00

View File

@@ -1,7 +1,6 @@
version: 2 version: 2
enable-beta-ecosystems: true enable-beta-ecosystems: true
updates: updates:
- package-ecosystem: "github-actions" - package-ecosystem: "github-actions"
directory: "/" directory: "/"
ignore: ignore:
@@ -10,6 +9,8 @@ updates:
- dependency-name: anthropics/claude-code-action - dependency-name: anthropics/claude-code-action
schedule: schedule:
interval: "daily" interval: "daily"
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
ignore: ignore:
@@ -57,6 +58,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 30 open-pull-requests-limit: 30
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "pip" - package-ecosystem: "pip"
@@ -67,6 +70,8 @@ updates:
labels: labels:
- pip - pip
- dependabot - dependabot
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: ".github/actions" directory: ".github/actions"
@@ -74,6 +79,8 @@ updates:
interval: "daily" interval: "daily"
open-pull-requests-limit: 10 open-pull-requests-limit: 10
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/docs/" directory: "/docs/"
@@ -97,6 +104,8 @@ updates:
interval: "daily" interval: "daily"
open-pull-requests-limit: 10 open-pull-requests-limit: 10
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-websocket/" directory: "/superset-websocket/"
@@ -106,6 +115,8 @@ updates:
- npm - npm
- dependabot - dependabot
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-websocket/utils/client-ws-app/" directory: "/superset-websocket/utils/client-ws-app/"
@@ -116,6 +127,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 10 open-pull-requests-limit: 10
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
# Now for all of our plugins and packages! # Now for all of our plugins and packages!
@@ -128,6 +141,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/plugins/legacy-plugin-chart-partition/" directory: "/superset-frontend/plugins/legacy-plugin-chart-partition/"
@@ -138,6 +153,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/plugins/legacy-plugin-chart-world-map/" directory: "/superset-frontend/plugins/legacy-plugin-chart-world-map/"
@@ -148,6 +165,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/plugins/plugin-chart-pivot-table/" directory: "/superset-frontend/plugins/plugin-chart-pivot-table/"
@@ -161,6 +180,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/plugins/legacy-plugin-chart-chord/" directory: "/superset-frontend/plugins/legacy-plugin-chart-chord/"
@@ -171,6 +192,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/plugins/legacy-plugin-chart-horizon/" directory: "/superset-frontend/plugins/legacy-plugin-chart-horizon/"
@@ -181,6 +204,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/plugins/legacy-plugin-chart-rose/" directory: "/superset-frontend/plugins/legacy-plugin-chart-rose/"
@@ -191,6 +216,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/plugins/legacy-preset-chart-deckgl/" directory: "/superset-frontend/plugins/legacy-preset-chart-deckgl/"
@@ -201,6 +228,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/plugins/plugin-chart-table/" directory: "/superset-frontend/plugins/plugin-chart-table/"
@@ -214,6 +243,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/plugins/legacy-plugin-chart-country-map/" directory: "/superset-frontend/plugins/legacy-plugin-chart-country-map/"
@@ -224,6 +255,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/plugins/legacy-plugin-chart-map-box/" directory: "/superset-frontend/plugins/legacy-plugin-chart-map-box/"
@@ -234,6 +267,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/plugins/legacy-preset-chart-nvd3/" directory: "/superset-frontend/plugins/legacy-preset-chart-nvd3/"
@@ -244,6 +279,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/plugins/plugin-chart-word-cloud/" directory: "/superset-frontend/plugins/plugin-chart-word-cloud/"
@@ -254,6 +291,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/plugins/legacy-plugin-chart-paired-t-test/" directory: "/superset-frontend/plugins/legacy-plugin-chart-paired-t-test/"
@@ -264,6 +303,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/plugins/plugin-chart-echarts/" directory: "/superset-frontend/plugins/plugin-chart-echarts/"
@@ -274,6 +315,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/plugins/plugin-chart-ag-grid-table/" directory: "/superset-frontend/plugins/plugin-chart-ag-grid-table/"
@@ -284,6 +327,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/plugins/plugin-chart-cartodiagram/" directory: "/superset-frontend/plugins/plugin-chart-cartodiagram/"
@@ -294,6 +339,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/plugins/legacy-plugin-chart-parallel-coordinates/" directory: "/superset-frontend/plugins/legacy-plugin-chart-parallel-coordinates/"
@@ -304,6 +351,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/plugins/plugin-chart-handlebars/" directory: "/superset-frontend/plugins/plugin-chart-handlebars/"
@@ -318,6 +367,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/packages/generator-superset/" directory: "/superset-frontend/packages/generator-superset/"
@@ -328,6 +379,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/packages/superset-ui-chart-controls/" directory: "/superset-frontend/packages/superset-ui-chart-controls/"
@@ -338,6 +391,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/packages/superset-ui-core/" directory: "/superset-frontend/packages/superset-ui-core/"
@@ -353,6 +408,8 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5
- package-ecosystem: "npm" - package-ecosystem: "npm"
directory: "/superset-frontend/packages/superset-ui-switchboard/" directory: "/superset-frontend/packages/superset-ui-switchboard/"
@@ -363,3 +420,5 @@ updates:
- dependabot - dependabot
open-pull-requests-limit: 5 open-pull-requests-limit: 5
versioning-strategy: increase versioning-strategy: increase
cooldown:
default-days: 5