Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Included githubactions in the dependabot config #8104

Merged
merged 1 commit into from
Apr 3, 2022

Conversation

nathannaveen
Copy link
Contributor

This should help with keeping the GitHub actions updated on new releases. This will also help with keeping it secure.

Dependabot helps in keeping the supply chain secure https://docs.github.com/en/code-security/dependabot

GitHub actions up to date https://docs.github.com/en/code-security/dependabot/working-with-dependabot/keeping-your-actions-up-to-date-with-dependabot

https://github.com/ossf/scorecard/blob/main/docs/checks.md#dependency-update-tool

@Falke-Design Falke-Design requested a review from jonkoops April 1, 2022 19:28
Copy link
Member

@mourner mourner left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Awesome, didn't know Dependabot can do this too!

@mourner mourner merged commit 2fe5332 into Leaflet:main Apr 3, 2022
@jonkoops
Copy link
Collaborator

jonkoops commented Apr 4, 2022

Very nice, I was not aware this was a feature! Thanks @nathannaveen!

This was referenced Apr 18, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants