Skip to content

Conversation

@SuperQ
Copy link

@SuperQ SuperQ commented Nov 17, 2025

Use the correct path and tag for the github.com/pborman/getopt/v2 requirement.

  • Update and pin GitHub actions for supply chain security.
  • Enable dependabot.

@peterbourgon
Copy link
Member

peterbourgon commented Nov 17, 2025

Happy to update the dependency, but no thanks on Dependabot, and can you explain the SHA versions for the tooling? At first glance it seems strange...

@SuperQ
Copy link
Author

SuperQ commented Nov 17, 2025

The SHA thing is a recommended mitigation against GitHub Action supply chain attacks.

This is why I enabled dependabot, it makes it easier to review the changes for actions by showing the git changes between versions.

Use the correct path and tag for the `github.com/pborman/getopt/v2`
requirement.
* Update and pin GitHub actions for supply chain security.
* Enable dependabot.

Signed-off-by: SuperQ <[email protected]>
@SuperQ
Copy link
Author

SuperQ commented Nov 17, 2025

I removed the dependabot config.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants