Skip to content
compiler.dev

Dependabot config generator

Choose your ecosystems and update schedule and get a ready-to-commit .github/dependabot.yml, with grouped minor and patch updates so you get fewer pull requests.

Supported: bundler, cargo, composer, devcontainers, docker, docker-compose, dotnet-sdk, elm, github-actions, gitsubmodule, gomod, gradle, helm, maven, mix, npm, nuget, pip, pub, swift, terraform, uv

.github/dependabot.yml

version: 2
updates:
  - package-ecosystem: "github-actions"
    directory: "/"
    schedule:
      interval: "weekly"
      day: "monday"
      time: "06:00"
      timezone: "Etc/UTC"
    open-pull-requests-limit: 5
    groups:
      minor-and-patch:
        update-types:
          - "minor"
          - "patch"
    labels:
      - "dependencies"
    commit-message:
      prefix: "ci"
  - package-ecosystem: "npm"
    directory: "/"
    schedule:
      interval: "weekly"
      day: "monday"
      time: "06:00"
      timezone: "Etc/UTC"
    open-pull-requests-limit: 5
    groups:
      minor-and-patch:
        update-types:
          - "minor"
          - "patch"
    labels:
      - "dependencies"
    commit-message:
      prefix: "deps"
  - package-ecosystem: "docker"
    directory: "/"
    schedule:
      interval: "weekly"
      day: "monday"
      time: "06:00"
      timezone: "Etc/UTC"
    open-pull-requests-limit: 5
    groups:
      minor-and-patch:
        update-types:
          - "minor"
          - "patch"
    labels:
      - "dependencies"
    commit-message:
      prefix: "deps"

Everything runs in your browser; nothing you type is sent anywhere.

How to use it

  1. List one ecosystem per line with its directory, such as npm / or pip /backend.
  2. Choose how often Dependabot runs, whether to group minor and patch updates, and optional labels and reviewers.
  3. Copy the YAML into .github/dependabot.yml and commit it to your default branch.

Frequently asked questions

Where does dependabot.yml go?

In .github/dependabot.yml on the default branch. Dependabot reads it from there only.

Should I update GitHub Actions too?

Yes. Add the github-actions ecosystem at / so pinned actions get updated. It keeps SHA-pinned actions fresh and safe.

How do I reduce Dependabot noise?

Group minor and patch updates into one pull request, lower open-pull-requests-limit, and use a weekly schedule rather than daily.

Why is my directory not detected?

Each entry's directory must contain the manifest (package.json, requirements.txt, go.mod). For monorepos, add one entry per package directory.

Made by compiler.dev, faster GitHub Actions runners. More free tools.