Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Before replacing dependabot with a custom action, we were manually approving PRs. I don't believe the change to a custom action was intended to change that behaviour. There are additional security concerns that we should consider before moving to automerge any updates. Given that we review dependabot PRs once a week, I've also changed the workflow to run weekly rather than daily (as dependabot was doing previously).
- Loading branch information