Dependabot config generator
Choose your ecosystems and update schedule and get a ready-to-commit .github/dependabot.yml, with grouped minor and patch updates so you get fewer pull requests.
.github/dependabot.yml
version: 2
updates:
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
day: "monday"
time: "06:00"
timezone: "Etc/UTC"
open-pull-requests-limit: 5
groups:
minor-and-patch:
update-types:
- "minor"
- "patch"
labels:
- "dependencies"
commit-message:
prefix: "ci"
- package-ecosystem: "npm"
directory: "/"
schedule:
interval: "weekly"
day: "monday"
time: "06:00"
timezone: "Etc/UTC"
open-pull-requests-limit: 5
groups:
minor-and-patch:
update-types:
- "minor"
- "patch"
labels:
- "dependencies"
commit-message:
prefix: "deps"
- package-ecosystem: "docker"
directory: "/"
schedule:
interval: "weekly"
day: "monday"
time: "06:00"
timezone: "Etc/UTC"
open-pull-requests-limit: 5
groups:
minor-and-patch:
update-types:
- "minor"
- "patch"
labels:
- "dependencies"
commit-message:
prefix: "deps"
Everything runs in your browser; nothing you type is sent anywhere.
How to use it
- List one ecosystem per line with its directory, such as npm / or pip /backend.
- Choose how often Dependabot runs, whether to group minor and patch updates, and optional labels and reviewers.
- Copy the YAML into .github/dependabot.yml and commit it to your default branch.
Frequently asked questions
Where does dependabot.yml go?
In .github/dependabot.yml on the default branch. Dependabot reads it from there only.
Should I update GitHub Actions too?
Yes. Add the github-actions ecosystem at / so pinned actions get updated. It keeps SHA-pinned actions fresh and safe.
How do I reduce Dependabot noise?
Group minor and patch updates into one pull request, lower open-pull-requests-limit, and use a weekly schedule rather than daily.
Why is my directory not detected?
Each entry's directory must contain the manifest (package.json, requirements.txt, go.mod). For monorepos, add one entry per package directory.
Made by compiler.dev, faster GitHub Actions runners. More free tools.
Related tools
- GitHub Actions workflow YAML checkerPaste a GitHub Actions workflow and catch missing runs-on, unpinned actions, pull_request_target risks, missing permissions and bad needs.
- CODEOWNERS generator and validatorWrite and validate a GitHub CODEOWNERS file. Catch invalid owners and unsupported patterns, and test which owners a file path resolves to.
- GitHub Actions cache key builderBuild a correct actions/cache key with hashFiles patterns and restore-keys for npm, pnpm, pip, Gradle, Maven, Go, Cargo and more. Copy-ready YAML.
- Conventional commit and semver bump helperPaste commit messages to check Conventional Commits format, find the next semantic version (major, minor, patch) and generate a changelog.