Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add dependabot config for github actions #643

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

RincewindsHat
Copy link
Member

No description provided.

@cla-bot cla-bot bot added the cla/signed label Aug 10, 2023
@julianbrost
Copy link
Contributor

Interesting idea but I'm not entirely sure if this will help us. I mean we reference other actions using something like @v3, which means if compatible changes are done to the action, we'll receive them automatically. So feels like the resulting PRs are less "you should update this" but more "there's a new version that's probably incompatible, maybe you want to use it".

No description provided.

What exactly was your motivation for creating this PR?

@RincewindsHat
Copy link
Member Author

In other projects we got deprecation warnings for the pipelines after some time.
The specific versions seem to be nailed to a specific node version which does not get updated within the version of the action. Therefore those actions will have to be updated eventually (if Github continues this practice) and IMHO it is better to get receive a PR for that beforehand instead of getting a deprecation notice unexpectedly.

Copy link
Member

@Al2Klimov Al2Klimov left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I, in contrast, don't even want a reason for applying updates – GHA or not.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants