version: 2 updates: # Security updates reuse this entry only when its directory matches the # manifest's own; they scan requirement/ as "/requirement", so both are listed. - package-ecosystem: "pip" directories: - "/" - "/requirement" schedule: interval: "daily" # Odoo versions kept only as migration sources: their pins stay frozen. # Globs cover requirements, ignore_requirements, pyproject and poetry.lock. exclude-paths: - "**/*odoo12.0_*" - "**/*odoo13.0_*" - "**/*odoo14.0_*" - "**/*odoo15.0_*" - "**/*odoo16.0_*" - "**/*odoo17.0_*" ignore: # meteostat 2.x caps pytz below 2024, which would freeze the timezone # data of every Odoo instance; 1.x leaves pytz free. - dependency-name: "meteostat" update-types: ["version-update:semver-major"]