Keep GitHub Actions up to date with Dependabot

Reference major versions of versioned actions, as suggested in:
https://docs.github.com/en/actions/creating-actions/about-custom-actions#good-practices-for-release-management
This commit is contained in:
Dimitri Papadopoulos
2022-11-02 14:11:39 +01:00
parent 833c32a4f1
commit 26276fe89c
2 changed files with 12 additions and 2 deletions
+10
View File
@@ -0,0 +1,10 @@
# See: https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#about-the-dependabotyml-file
version: 2
updates:
# Configure check for outdated GitHub Actions actions in workflows.
# See: https://docs.github.com/code-security/dependabot/working-with-dependabot/keeping-your-actions-up-to-date-with-dependabot
- package-ecosystem: github-actions
directory: / # Check the repository's workflows under /.github/workflows/
schedule:
interval: daily
+2 -2
View File
@@ -10,7 +10,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@master
uses: actions/checkout@v3
- uses: actions/setup-python@v1
- run: pip install codespell
- uses: ./
@@ -24,7 +24,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@master
uses: actions/checkout@v3
- uses: actions/setup-python@v1
- run: pip install git+https://github.com/codespell-project/codespell.git
- uses: ./