Skip to content

Create dependabot.yml #741

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Dec 28, 2024
Merged

Create dependabot.yml #741

merged 1 commit into from
Dec 28, 2024

Conversation

taku333
Copy link
Contributor

@taku333 taku333 commented Dec 28, 2024

Summary

A mechanism has been added to automatically suggest upgrades to Official Actions and Generic Actions.

@spier spier added the Type - Maintenance / Cleanup Maintaining / cleaning the repo is the main focus of this issue / PR label Dec 28, 2024
@spier
Copy link
Member

spier commented Dec 28, 2024

Thanks @taku333!

I have used dependabot before but I don't know what the effect of activating package-ecosystem: "github-actions" would be.

Will this create automatic Pull Requests, once a new version of the GitHub Actions is available, or how will this work?

@spier
Copy link
Member

spier commented Dec 28, 2024

I found the info that I was looking for here:
https://docs.github.com/en/code-security/dependabot/working-with-dependabot/keeping-your-actions-up-to-date-with-dependabot

So I have a rough idea of how this will work.

I say let's just try it out. :)

Thank you for your contribution @taku333!

@spier spier merged commit 59b3a1e into InnerSourceCommons:main Dec 28, 2024
7 checks passed
@spier
Copy link
Member

spier commented Dec 28, 2024

This has certainly worked, as some PRs were created immediately :)

Screenshot 2024-12-28 at 09 18 08

@spier spier added the dependencies Pull requests that update a dependency file label Dec 29, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file Type - Maintenance / Cleanup Maintaining / cleaning the repo is the main focus of this issue / PR
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants