Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enable Dependabot for Workflow updates #68

Merged

Conversation

Weltraumschaf
Copy link
Member

We want to be notified if

  • used GitHub actions and
  • used baes images in the workflow

are outdated.

We are not sure if it will work. This is a first try.

The docker ecosystem is configured globaly because we may use containers outside workflows and we hope that Dependabot searches recursive. We are also not sure if Dependabot recognizes the image tag in the workflow YAML as Docker dependency.

@Weltraumschaf Weltraumschaf self-assigned this Jul 28, 2023
@Weltraumschaf Weltraumschaf added the dependencies Pull requests that update a dependency file label Jul 28, 2023
We want to be notified if

- used GitHub actions and
- used baes images in the workflow

are outdated.

We are not sure if it will work. This is a first try.

The docker ecosystem is configured globaly because we may use
containers outside workflows and we hope that Dependabot searches
recursive. We are also not sure if Dependabot recognizes the image
tag in the workflow YAML as Docker dependency.

Signed-off-by: Sven Strittmatter <sven.strittmatter@iteratec.com>
@Weltraumschaf Weltraumschaf force-pushed the dependabot_image_updates branch from eebfc55 to 671b0b7 Compare July 28, 2023 10:35
@Ilyesbdlala
Copy link
Member

Why has the CI not ran on this PR? Any idea @Zero3141 ?

@Zero3141 Zero3141 changed the title Enable Dependabot for Wwrokflow updates Enable Dependabot for Workflow updates Jul 28, 2023
@Zero3141
Copy link
Contributor

Why has the CI not ran on this PR? Any idea @Zero3141 ?

See my comment in PR67, which should fix this issue

@Weltraumschaf Weltraumschaf merged commit fc0a37f into secureCodeBox:main Jul 28, 2023
@Weltraumschaf Weltraumschaf deleted the dependabot_image_updates branch July 28, 2023 14:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
Archived in project
Development

Successfully merging this pull request may close these issues.

3 participants