Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Dependabot config for updating GH Actions #10917

Closed
wants to merge 1 commit into from

Conversation

bencomp
Copy link
Contributor

@bencomp bencomp commented Oct 9, 2024

What this PR does / why we need it:
Configure @dependabot to check for outdated GitHub Actions in workflows

Which issue(s) this PR closes:

Special notes for your reviewer:
I followed https://docs.github.com/en/code-security/dependabot/working-with-dependabot/keeping-your-actions-up-to-date-with-dependabot to create the file.
Nothing will probably happen before this is merged.

I only included the github-actions ecosystem. Dependabot should not start creating PRs for Maven updates.

Suggestions on how to test this:
Watch out for pull requests created by Dependabot.

Does this PR introduce a user interface change? If mockups are available, please link/include them here:
No.

Is there a release notes update needed for this change?:
No.

Additional documentation:
https://docs.github.com/en/code-security/dependabot/ecosystems-supported-by-dependabot/supported-ecosystems-and-repositories#github-actions lists some caveats. Importantly, locally referenced and Docker-style actions are not checked for available updates.

@pdurbin
Copy link
Member

pdurbin commented Oct 10, 2024

This is the same as #9251 except for the check interval.

@pdurbin pdurbin added Type: Feature a feature request Component: Code Infrastructure formerly "Feature: Code Infrastructure" Size: 3 A percentage of a sprint. 2.1 hours. labels Oct 10, 2024
@bencomp bencomp closed this Oct 10, 2024
@bencomp
Copy link
Contributor Author

bencomp commented Oct 10, 2024

Oops, I should have checked before opening! Thanks, @pdurbin !

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Component: Code Infrastructure formerly "Feature: Code Infrastructure" Size: 3 A percentage of a sprint. 2.1 hours. Type: Feature a feature request
Projects
Status: No status
Development

Successfully merging this pull request may close these issues.

Several in-use GitHub Actions use outdated NodeJS versions
2 participants