Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add dependabot to repository #7

Merged
merged 1 commit into from
Nov 13, 2024
Merged

Add dependabot to repository #7

merged 1 commit into from
Nov 13, 2024

Conversation

jpthiele
Copy link
Contributor

This bot checks daily whether or not there are new versions of individual GitHub actions available and drafts pull requests to bump the version.

This bot checks daily whether or not there are new versions of individual GitHub actions available and drafts pull requests to bump the version.
@jpthiele jpthiele requested a review from pjaap November 12, 2024 16:11
Copy link
Member

@pjaap pjaap left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@pjaap
Copy link
Member

pjaap commented Nov 13, 2024

Hmm. "The base branch does not allow updates" restricts the merge. I understood that "restrict updates" disables direct pushes, but it seems that it does not allow any updates of master at all? Is then the option "require pull request" sufficient? Can someone second that?

@pjaap
Copy link
Member

pjaap commented Nov 13, 2024

"restrict updates" is also not listed at https://best.openssf.org/SCM-BestPractices/ ... therefore, I think that rule is a bit too much :) I'll remove it from @chmerdon's repos

@pjaap
Copy link
Member

pjaap commented Nov 13, 2024

looks good now. But I think the final merge should be done by @chmerdon

@pjaap pjaap merged commit b96a3d7 into master Nov 13, 2024
9 checks passed
@pjaap
Copy link
Member

pjaap commented Nov 13, 2024

merged as requested by @chmerdon and @jpthiele

@pjaap pjaap deleted the jpthiele-dependabot branch November 13, 2024 18:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants