Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create dependabot.yml #348

Closed
wants to merge 1 commit into from
Closed

Create dependabot.yml #348

wants to merge 1 commit into from

Conversation

joycebrum
Copy link

Closes #347

Here is a dependabot configuration that enables version updates for github workflows and groups them in a single PR to avoid multiple PRs

It is schedule to run monthly to allow a delay after new version bumps to allow vulnerabilities to be discovered and fixed before affecting go-cmp. Because of that, it is important to enable the "security updates" on the config, mentioned in the issue, because it enables dependabot to send out of schedule PRs in case of a security patch being released.

@neild
Copy link
Collaborator

neild commented Jan 5, 2024

Thanks, but no thanks. go-cmp (quite intentionally) has no dependencies, so this isn't going to do anything useful.

@neild neild closed this Jan 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Enable a dependency update tool
2 participants