Skip to content

Commit

Permalink
.github: Add dependabot.yml file
Browse files Browse the repository at this point in the history
Enables dependabot tool and checks for any version updates to
all the github actions weekly on Mondays.
Dependabot.yml file needs to be in .github folder as
opposed to .github/workflows like all other workflow yml files
since .github folder is checked by github actions and also by
OSSF scorecard.

Signed-off-by: Juee Himalbhai Desai <[email protected]>
  • Loading branch information
Juee14Desai authored and j-xiong committed Mar 22, 2024
1 parent fb314c6 commit 3b54007
Showing 1 changed file with 15 additions and 0 deletions.
15 changes: 15 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# To get started with Dependabot version updates, you'll need to specify which
# package ecosystems to update and where the package manifests are located.
# Please see the documentation for all configuration options:
# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file

version: 2
updates:
- package-ecosystem: "github-actions"
directory: "/" # Location of package manifests
schedule:
# Check for updates to GitHub Actions weekly on Monday
interval: "weekly"
time: "09:00"
timezone: "America/Los_Angeles"

0 comments on commit 3b54007

Please sign in to comment.