Skip to content

chore: Included githubactions in the dependabot config#345

Closed
naveensrinivasan wants to merge 1 commit into
ruby:masterfrom
turrisxyz:Dependabot-GitHub-Actions
Closed

chore: Included githubactions in the dependabot config#345
naveensrinivasan wants to merge 1 commit into
ruby:masterfrom
turrisxyz:Dependabot-GitHub-Actions

Conversation

@naveensrinivasan
Copy link
Copy Markdown

This should help with keeping the GitHub actions updated on new releases. This will also help with keeping it secure.

Dependabot helps in keeping the supply chain secure https://docs.github.com/en/code-security/dependabot

GitHub actions up to date https://docs.github.com/en/code-security/dependabot/working-with-dependabot/keeping-your-actions-up-to-date-with-dependabot

https://github.com/ossf/scorecard/blob/main/docs/checks.md#dependency-update-tool
Signed-off-by: naveen 172697+naveensrinivasan@users.noreply.github.com

This should help with keeping the GitHub actions updated on new releases. This will also help with keeping it secure.

Dependabot helps in keeping the supply chain secure https://docs.github.com/en/code-security/dependabot

GitHub actions up to date https://docs.github.com/en/code-security/dependabot/working-with-dependabot/keeping-your-actions-up-to-date-with-dependabot

https://github.com/ossf/scorecard/blob/main/docs/checks.md#dependency-update-tool
Signed-off-by: naveen <172697+naveensrinivasan@users.noreply.github.com>
@eregon
Copy link
Copy Markdown
Member

eregon commented May 26, 2022

I'm unsure this is useful, very few actions are used in this repo's workflows, and they are only used for testing.
I guess it'll update actions/checkout to v3, which seems pretty much unnecessary noise, but we can do it (#302).

@eregon eregon closed this May 26, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants