From c7541cb51687d10f784cb93f482edfe56700c4dc Mon Sep 17 00:00:00 2001
From: Johann Bauer <bauerj@bauerj.eu>
Date: Fri, 18 Feb 2022 16:06:56 +0100
Subject: [PATCH] Enable dependabot for repository (#86)

---
 .github/dependabot.yml | 22 ++++++++++++++++++++++
 1 file changed, 22 insertions(+)
 create mode 100644 .github/dependabot.yml

diff --git a/.github/dependabot.yml b/.github/dependabot.yml
new file mode 100644
index 000000000..0d64b9a15
--- /dev/null
+++ b/.github/dependabot.yml
@@ -0,0 +1,22 @@
+# https://docs.github.com/en/code-security/supply-chain-security/keeping-your-dependencies-updated-automatically/configuration-options-for-dependency-updates#package-ecosystem
+
+version: 2
+updates:
+
+  # Enable version updates for npm
+  - package-ecosystem: "npm"
+    target-branch: "dev"
+    # Look for `package.json` and `lock` files in the `root` directory
+    directory: "/src-ui"
+    # Check the npm registry for updates every week
+    schedule:
+      interval: "weekly"
+
+  # Enable version updates for Python
+  - package-ecosystem: "pip"
+    target-branch: "dev"
+    # Look for a `Pipfile` in the `root` directory
+    directory: "/"
+    # Check for updates once a week
+    schedule:
+      interval: "weekly"