version: 2 updates: - package-ecosystem: "github-actions" directory: "/" schedule: interval: "monthly" labels: - "skip issue" - "skip news" ignore: - dependency-name: "*" update-types: - "version-update:semver-minor" - "version-update:semver-patch" groups: actions: patterns: - "*" cooldown: # https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns # Cooldowns protect against supply chain attacks by avoiding the # highest-risk window immediately after new releases. default-days: 14 - package-ecosystem: "pip" directory: "/Tools/" schedule: interval: "monthly" labels: - "skip issue" - "skip news" cooldown: default-days: 14